> ## Documentation Index
> Fetch the complete documentation index at: https://docs.velatir.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What Velatir Collects

> What the Microsoft 365 connector reads from your tenant, what Velatir keeps, and what it leaves out.

## Overview

The Microsoft 365 connector brings in three kinds of data from Microsoft. It reads them only from the tenant you connected, and only with the [permissions](/connectors/microsoft-365/permissions) you approved.

| Data | Read from | Shown in Velatir as |
| - | - | - |
| **Copilot conversations** | Microsoft Graph | Sessions, with **Origin** set to **Connector** |
| **Copilot audit records** (optional) | The Microsoft Purview audit log | Sessions, merged with the conversations |
| **Licences and seats** | Microsoft Graph | Plans and seats on the **Microsoft** card |

## Copilot Conversations

Velatir reads the Copilot conversations of every user who holds a Microsoft 365 Copilot licence. It asks Microsoft for that list of users each time it reads, so someone who gets a licence is included from the next read, and someone who loses one is no longer read.

Each prompt and its response become traces in a session, one session per Copilot conversation. They cover every Copilot surface and are named after it: **Copilot Chat**, **Copilot in Word**, **Copilot in Teams**, and so on. Each one is dated when it happened, not when Velatir read it, and is attributed to the user whose conversation it is.

### What is read from each message

**Only the text.** Velatir reads the words of the prompt and the response. It does not read:

* Links, mentions, or attachments in the message
* The files, sites, or emails Copilot used to answer

A response can still quote content Copilot read for the user, such as a passage from a document. That text is part of the response.

### What is kept

Conversation text follows **Store trace data in sessions**, exactly as for every other session. The default is **Never**: your agents review the text, and Velatir keeps a generalised description instead of the words. See [Data privacy](/security/data-privacy).

Your agents review every conversation after it arrives. The interaction has already happened, so an Enforcer's block is recorded but not enforced, and connector activity does not notify your escalation channels.

### Who it is attributed to

Each conversation is attributed to the person whose conversation it is. It lands in the same [workspace](/platform/organizations-and-workspaces) as their other activity, such as their activity from Velatir for Desktop.

## Copilot Audit Records

This part needs the optional `AuditLogsQuery.Read.All` permission. Without it, the connector works on conversations alone.

The Purview audit log records Copilot activity for everyone in the tenant, **including people who use Copilot Chat without a Microsoft 365 Copilot licence**. Velatir reads only Copilot interaction records from it.

Audit records contain no message text. When an audit record and a conversation describe the same message, Velatir merges them into one trace. When there is no conversation, for someone without a licence, the trace has no text. Your agents then have nothing to review, and the trace has no description.

<Note>
  Microsoft publishes audit records late, often an hour or more after the activity. Audit activity therefore reaches Velatir later than conversations do.
</Note>

## Licences and Seats

For each Copilot product your tenant holds, the **Microsoft** card shows how many seats you have bought and how many are assigned. It does not show who holds which licence.

See [Seats and plans](/connectors/microsoft-365#seats-and-plans) for how the products are shown.

## History From Before You Connected

When you connect, Velatir imports conversations from the **30 days** before the connection, and, with the audit permission, audit records from the same 30 days. The import runs in the background, one day at a time from the most recent, and has no progress indicator. Nothing older than 30 days is imported.

## What the Connector Does Not Collect

* **Conversation text of people without a Microsoft 365 Copilot licence.** Microsoft only offers conversations for licensed users. With the audit permission, Velatir sees that the activity happened, but not what was said.
* **Copilot Studio agents outside Microsoft 365 Copilot.** Velatir reads only Microsoft 365 Copilot records.
* **GitHub Copilot** and other Copilot products that are not part of Microsoft 365.
* **Mail, files, Teams chats, and calendars.** The permissions do not cover them.
* **Billing details.** Microsoft does not report whether a licence is billed monthly or yearly.
* **Token counts.** Microsoft does not report them for Copilot.

## When the Browser Extension Sees It Too

Velatir for Desktop and the browser extension also record Microsoft 365 Copilot when it is used in a browser. If both they and the connector see the same conversation, Velatir reconciles the two so it is not counted twice.

## Where the Data Goes

Velatir reads from Microsoft over Microsoft Graph and stores what it keeps on its own EU-based infrastructure, like the rest of your data. See [Data storage & encryption](/security/data-storage-and-encryption).

Disconnecting, or revoking the app in Entra, stops new reads. It does not delete what was already imported, which follows your organisation's **Data retention period**.

***

<CardGroup cols={2}>
  <Card title="Permissions" icon="key-round" href="/connectors/microsoft-365/permissions">
    Every permission on the consent screen, and why Velatir asks for it.
  </Card>

  <Card title="Data privacy" icon="lock" href="/security/data-privacy">
    Storage modes, generalised descriptions, and retention.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.