Skip to main content

Microsoft SharePoint & OneDrive

The SharePoint & OneDrive integration lets an agent find and read content across your SharePoint sites and each person’s OneDrive during a conversation — search sites and files, read pages and list items, and pull a file’s contents to answer from. When you enable it, the agent can also upload and share files, create a OneDrive folder, and add a SharePoint list item. It always acts as the asking user and sees only what that person can already see.
This is the SharePoint/OneDrive integration — a tool the agent uses inside a conversation (on the web widget, Slack, Teams, voice, and so on). It is not the same as putting your agent on a SharePoint intranet page — that’s the SharePoint Online channel, a separate setup. You can use either or both.

Modules

Reads in each enabled module are on by default. Write tools are off until you turn them on, one at a time. Everything runs as the asking user, bounded by what that person can already access in Microsoft 365. There are no deletes in this version, and no organization-wide admin tools — every action is a per-user action.

Set it up

1

Add the integration

From your agent, open Integrations, choose Microsoft SharePoint & OneDrive, and pick the modules you want — SharePoint, OneDrive, or both.
2

Restrict the SharePoint reach (optional)

Add a SharePoint site allowlist (one site URL per line, e.g. https://acme.sharepoint.com/sites/it) to limit which sites the agent can search and read. Leave it empty to cover every site the asking person is a member of. (The allowlist applies to SharePoint only — OneDrive is per-user by design.)
3

Turn on any write tools you want (optional)

Reads are on by default. To let the agent upload or share files, create a folder, or add a list item, switch those tools on individually. Leaving them off keeps the integration read-only.
4

Grant tenant admin consent for SharePoint

SharePoint’s read/write permissions (Sites.*) are organization-wide and need a Microsoft 365 tenant admin to grant consent once. OneDrive needs no admin consent — its permissions are ones each user can grant for themselves. If you enable SharePoint without admin consent, the SharePoint tools stay unavailable until consent is granted.
5

Attest and let users authorize themselves

Review the access requested (higher-impact scopes are flagged), name the integration, and save. The first time the agent uses a tool for someone, that person signs in with Microsoft and approves. If your tenant also uses the Outlook or Microsoft Teams integration, this is the same Microsoft sign-in — people see one combined prompt, not three.

How writes stay safe

Write tools run under the guardrails every Cobalt integration gets:
  • Writes are off by default and enabled one tool at a time.
  • The agent acts as the user, so an upload or share can only reach what that person could already reach in SharePoint or OneDrive.
  • It reports what actually happened, with a link to the uploaded file, the new folder, the shared link, or the created list item.

Troubleshooting

SharePoint tools say they’re unavailable. The most common cause is missing tenant admin consent — SharePoint’s Sites.* permissions can’t be granted by an individual user. Have a Microsoft 365 admin grant consent once. OneDrive is unaffected.
  • “Please authorize Microsoft.” Each person authorizes once, and again if you later enable a tool that needs a new permission (for example turning on uploads after launching read-only). Approve the prompt and the agent continues.
  • A site isn’t searchable. If you set a site allowlist, only the listed sites are in reach. Either add the site, or clear the allowlist to cover every site the person belongs to.
  • “I couldn’t find any you can access.” The agent only sees what the asking person can — files in a site they don’t belong to, or someone else’s OneDrive, are intentionally out of reach.

FAQ

This integration is a set of tools an agent uses inside a conversation happening on another channel. The SharePoint Online channel is about hosting the agent on a SharePoint intranet page. They’re independent and can both be on.
For OneDrive, no — each user grants their own access. For SharePoint, yes — a tenant admin grants organization-wide consent once, because SharePoint’s site permissions can’t be granted per user.
Only the asking person’s. Reads and writes run with that user’s own Microsoft 365 permissions, optionally narrowed further by your SharePoint site allowlist.
No. This version reads, uploads, shares, creates folders, and adds list items — it doesn’t delete files, folders, or list items.
Yes. SharePoint/OneDrive, Outlook, and Microsoft Teams all use one Microsoft 365 sign-in, so people approve a single combined prompt rather than one per integration.