A company running on Microsoft 365 keeps its knowledge in two places at once
In a company equipped with Microsoft 365, what was decided sits in Outlook mail, and what was produced sits in SharePoint and in everybody's OneDrive. Both live under the same identity, and an AI plugged into one without the other answers halfway.
Those two halves are not governed the same way, though. A mailbox belongs to a person and holds their private life. A document belongs to a share, and that share names people. The connector handles both on the same pass while applying two different rules to them, and this page says which rule applies where.
No key opens every mailbox in your organisation
Microsoft can grant an application a permission that reads every mailbox in an organisation at once. The connector does not use it. Each mailbox is connected by the person it belongs to, through their own Microsoft sign-in, and the key that is kept is good for that one mailbox only.
The connection also checks that the Microsoft account which just signed in really is the person being targeted, and it refuses before anything has been kept when the two do not match. Disconnecting a mailbox removes its access key and leaves in place what has already been read, because withdrawing an access and erasing a content are two separate decisions.
The permission that would let something send a message from your address is never requested. The connector refuses to start at all if a permission whose name looks like a write is added to its configuration.
Two surfaces, two rules
The connector covers two surfaces of Microsoft 365, mail and documents. The rest of the suite is of no interest to it.
The excluded folders are excluded for a reason that fits in one sentence. A draft is a thought nobody has sent, and the bin holds what somebody already wanted out. Sorting private mail comes second, and the first move is to stay out of the folders where private content concentrates.
What comes in, object by object
Every row is checkable at your end, by looking at which folder a message sits in or how a document is shared.
| In Microsoft 365 | What comes into your Kastel |
|---|---|
| A message in the inbox or in sent items | Its text, when it is judged to be business |
| A draft nobody has sent | Nothing. The drafts folder is not read |
| A message in junk mail or in deleted items | Nothing. Those folders are not read |
| A file attached to an Outlook message | Nothing. Attachments are not opened |
| A document on a SharePoint site shared with people from one department | Its text, filed in that department |
| The same document shared with a group, through a link, or across departments | Nothing, until an administrator decides where it belongs |
| A video, a compressed archive, a binary file | Nothing. Those formats carry no text to read |
Five rows out of seven end in a refusal, and that is the intended behaviour. The fourth deserves a word, because it surprises people. An attachment does not come in through the mail, whereas the same file dropped into SharePoint comes in through the documents, with the sharing of its own. Sharing that names nobody known says nothing about a document's internal audience, so it is not used to file it. Governing your knowledge starts with those cases, the ones nobody has decided.
After the first pass, the connector only rereads what Microsoft flags
The first pass over a folder reaches back a few months, ninety days by default, and your deployer can widen it. Later passes list nothing again. They follow the trail of changes Microsoft keeps for each mail folder and for each document space.
When Microsoft no longer recognises the marker of the last pass, the connector rereads the whole window rather than assuming nothing has moved. That reread creates no duplicate, because content already written identically is recognised and left alone.
A document edited in SharePoint replaces its earlier version the moment the new one is written, and the old copy is retired. An answer therefore never leans on a stale version left lying around. As for a document's download link, it points at Microsoft's storage servers, and the connector follows it only when it really does name a Microsoft host, even though Microsoft is what handed it over a second earlier.
The Microsoft application registered for this connector also serves the Teams channels, which therefore need no second authorisation. And the sorting of private mail is exactly the one used by the Gmail connector, the same machinery applied to another mail system.
What this connector does not do
Documents do not go through the sorting of private mail. That sorting exists for communication between people, and an office file is not one. A personal document dropped into a connected OneDrive therefore comes in as a document, according to its sharing rather than according to what it says.
A document is filed on its sharing, and sharing is often wider than people think. A file nobody but you can see in your OneDrive still carries your own access, and that access is what names somebody. It is therefore filed in your department, where your colleagues can reach it through an AI even though they cannot see it in OneDrive.
The mail perimeter remains a default setting rather than a lock. The folders read are the inbox and sent items, and a deployer can add more, which would bring back into scope the folders where private content concentrates. The other way round, a person attached to two departments makes their mail wait, because your Kastel refuses to pick one of the two on their behalf. That is slower than approximate filing, and we own it.
A message deleted in Outlook, or a document taken off a SharePoint site, is not erased from your Kastel. Microsoft flags a disappearance exactly once, so the connector records it on the very pass that sees it, and the content stays there marked as gone at the source. It remains readable by those who were already entitled to it until an administrator decides to erase it, because an answer already given has to stay checkable.
See where the paid plans start before you connect your organisation.
Every connector is in the free core, installable at your end and with no size limit. The pricing page says what the plans add, and what they have no need to add.
See pricing