AI governance
Microsoft 365 and AI: the value lies in control, not access
Starting questionHow do we give AI assistants access to mail, calendar, and documents without granting all or nothing?
Result
Works
The access layer decides what a model may see for each tool, tenant, and type of content, and logs every access.
Through an access layer based on the Model Context Protocol that controls access rather than simply granting it: tools with a fixed scope, separated tenants, a need-to-know filter for sensitive content, and a log of every access. Sensitive content is detected before it reaches a model.
What we built
We built an access layer for Microsoft 365 based on the Model Context Protocol. It has several layers: tools with a fixed scope, tenant isolation, rate limiting, a need-to-know filter that detects personal and sensitive content, and logging of every access.
Development spans more than 200 revisions since April 2026.
What it means for business architecture
Sooner or later the platform vendor will offer mailbox access itself. What remains is the question of who may pass which content to which model, and how to prove it. That question belongs in the architecture of AI use.
Lessons learned
- With access layers, what counts is how they control, not how much they can do.
- Sensitive content has to be detected before it reaches a model. After that, it is too late.
- Open protocols let you switch models later instead of tying yourself to one vendor.
- Microsoft 365
- Model Context Protocol
- need-to-know
- logging