AI governance

Microsoft 365 and AI: the value lies in control, not access

BuiltPublished:

Starting questionHow do we give AI assistants access to mail, calendar, and documents without granting all or nothing?

Result

Works

The access layer decides what a model may see for each tool, tenant, and type of content, and logs every access.

Through an access layer based on the Model Context Protocol that controls access rather than simply granting it: tools with a fixed scope, separated tenants, a need-to-know filter for sensitive content, and a log of every access. Sensitive content is detected before it reaches a model.

What we built

We built an access layer for Microsoft 365 based on the Model Context Protocol. It has several layers: tools with a fixed scope, tenant isolation, rate limiting, a need-to-know filter that detects personal and sensitive content, and logging of every access.

Development spans more than 200 revisions since April 2026.

What it means for business architecture

Sooner or later the platform vendor will offer mailbox access itself. What remains is the question of who may pass which content to which model, and how to prove it. That question belongs in the architecture of AI use.

Lessons learned

  1. With access layers, what counts is how they control, not how much they can do.
  2. Sensitive content has to be detected before it reaches a model. After that, it is too late.
  3. Open protocols let you switch models later instead of tying yourself to one vendor.
  • Microsoft 365
  • Model Context Protocol
  • need-to-know
  • logging

More reports on AI governance

Consulting by SIMO GmbH

From the Lab to consulting.

This report shows what works technically. Whether it works in your company is a question of architecture. SIMO GmbH answers it with you, independent of vendors.

Decision Readiness Check: 12 questions, about 3 minutes, result at once. Initial call: 45 minutes, free of charge, by video. Entry with BISA 1 or BEIA. All on simo-online.com.