Microsoft SharePoint & OneDrive
The SharePoint & OneDrive integration lets an agent find and read content across your SharePoint sites and each person’s OneDrive during a conversation — search sites and files, read pages and list items, and pull a file’s contents to answer from. When you enable it, the agent can also upload and share files, create a OneDrive folder, and add a SharePoint list item. It always acts as the asking user and sees only what that person can already see.This is the SharePoint/OneDrive integration — a tool the agent uses inside a
conversation (on the web widget, Slack, Teams, voice, and so on). It is not
the same as putting your agent on a SharePoint intranet page — that’s the
SharePoint Online channel, a separate setup. You can use
either or both.
Modules
Reads in each enabled module are on by default. Write tools are off until you turn them on, one at a time.
Everything runs as the asking user, bounded by what that person can already
access in Microsoft 365. There are no deletes in this version, and no
organization-wide admin tools — every action is a per-user action.
Set it up
1
Add the integration
From your agent, open Integrations, choose Microsoft SharePoint &
OneDrive, and pick the modules you want — SharePoint, OneDrive, or
both.
2
Restrict the SharePoint reach (optional)
Add a SharePoint site allowlist (one site URL per line, e.g.
https://acme.sharepoint.com/sites/it) to limit which sites the agent can
search and read. Leave it empty to cover every site the asking person is a
member of. (The allowlist applies to SharePoint only — OneDrive is per-user by
design.)3
Turn on any write tools you want (optional)
Reads are on by default. To let the agent upload or share files, create a
folder, or add a list item, switch those tools on individually. Leaving them off
keeps the integration read-only.
4
Grant tenant admin consent for SharePoint
SharePoint’s read/write permissions (
Sites.*) are organization-wide and need a
Microsoft 365 tenant admin to grant consent once. OneDrive needs no
admin consent — its permissions are ones each user can grant for themselves. If
you enable SharePoint without admin consent, the SharePoint tools stay
unavailable until consent is granted.5
Attest and let users authorize themselves
Review the access requested (higher-impact scopes are flagged), name the
integration, and save. The first time the agent uses a tool for someone, that
person signs in with Microsoft and approves. If your tenant also uses the
Outlook or Microsoft Teams integration, this is the same Microsoft
sign-in — people see one combined prompt, not three.
How writes stay safe
Write tools run under the guardrails every Cobalt integration gets:- Writes are off by default and enabled one tool at a time.
- The agent acts as the user, so an upload or share can only reach what that person could already reach in SharePoint or OneDrive.
- It reports what actually happened, with a link to the uploaded file, the new folder, the shared link, or the created list item.
Troubleshooting
- “Please authorize Microsoft.” Each person authorizes once, and again if you later enable a tool that needs a new permission (for example turning on uploads after launching read-only). Approve the prompt and the agent continues.
- A site isn’t searchable. If you set a site allowlist, only the listed sites are in reach. Either add the site, or clear the allowlist to cover every site the person belongs to.
- “I couldn’t find any you can access.” The agent only sees what the asking person can — files in a site they don’t belong to, or someone else’s OneDrive, are intentionally out of reach.
FAQ
Do I need a Microsoft admin to set this up?
Do I need a Microsoft admin to set this up?
For OneDrive, no — each user grants their own access. For SharePoint,
yes — a tenant admin grants organization-wide consent once, because
SharePoint’s site permissions can’t be granted per user.
Whose files can the agent see?
Whose files can the agent see?
Only the asking person’s. Reads and writes run with that user’s own Microsoft
365 permissions, optionally narrowed further by your SharePoint site allowlist.
Can it delete files?
Can it delete files?
No. This version reads, uploads, shares, creates folders, and adds list items —
it doesn’t delete files, folders, or list items.
Related
- Integrations overview — how integrations work in general.
- Microsoft Outlook and Microsoft Teams — the other Microsoft 365 integrations that share the same sign-in.
- SharePoint Online channel — host the agent on a SharePoint intranet (a different feature).
- How Cobalt works — where integrations fit.
