Field report 5 · AI governance
Microsoft 365 and AI: the value lies in control, not in access
How AI assistants get access to mail, calendar and documents without an all-or-nothing permission.
- Status
- Built Built and proven in our own use.
- Published
- Publisher
- SIMO GmbH, Aschaffenburg, Germany
Starting questionHow do we give AI assistants access to mail, calendar and documents without granting all or nothing?
What we built
We built an access layer for Microsoft 365 based on the Model Context Protocol. It has several layers: tools with a fixed scope, tenant isolation, rate limiting, a need-to-know filter that detects personal and sensitive content, and logging of every access.
Development spans more than 200 revisions since April 2026.
What it means for business architecture
Sooner or later the platform vendor will offer mailbox access itself. What remains is the question of who may pass which content to which model, and how to prove it. That question belongs in the architecture of AI use.
Learnings
- With access layers, what counts is how they control, not how much they can do.
- Sensitive content has to be detected before it reaches a model. Afterwards it is too late.
- Open protocols let you switch models later instead of tying yourself to one vendor.
- Microsoft 365
- Model Context Protocol
- need-to-know
- logging