> ## Documentation Index
> Fetch the complete documentation index at: https://docs.velatir.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions

> Who can approve the Microsoft 365 connector, every permission on the consent screen, and what Velatir uses each one for.

## Overview

Connecting Microsoft 365 means approving the **Velatir Connector** app in your Microsoft Entra tenant. This page lists every permission that app asks for, what Velatir uses it for, and what happens if it is missing, so you can review the request before you accept it.

**Every permission is read-only.** Velatir cannot change, send, or delete anything in your tenant.

## Who Can Approve

The Velatir Connector app asks for Microsoft Graph **application permissions**. Microsoft lets only two roles approve those for a whole organisation:

* **Global Administrator**
* **Privileged Role Administrator**

Application Administrator and Cloud Application Administrator cannot approve application permissions for Microsoft Graph. If someone with one of those roles signs in, Microsoft asks for an administrator's approval instead.

On the Velatir side, the person who starts the connection needs the organisation **Administrator** role.

## The App You Approve

**Velatir Connector** is a multi-tenant app that Velatir registers and maintains. It is not the app behind **Sign in with Microsoft** and [Entra member sync](/platform/microsoft-entra). The two are approved separately, so:

* Organisations that already use Entra sign-in do not get the connector's permissions until an admin approves the connector.
* Approving, revoking, or deleting the connector does not affect how anyone signs in to Velatir.

### How Velatir Uses the Approval

<Steps>
  <Step title="An admin signs in" icon="log-in">
    The first Microsoft screen is a sign-in that asks only for `openid`. It tells Velatir which directory the admin belongs to. Velatir connects that directory and refuses an approval for any other.
  </Step>

  <Step title="The admin approves for the organisation" icon="badge-check">
    Microsoft's consent screen lists the permissions below. Accepting it grants them to Velatir Connector in your tenant only.
  </Step>

  <Step title="Velatir checks the approval" icon="search-check">
    Before it saves anything, Velatir asks Microsoft for an access token for your tenant, checks that the token carries the permissions it needs, and makes one test call to Microsoft Graph. If any check fails, nothing is saved.
  </Step>

  <Step title="Velatir reads on its own schedule" icon="clock">
    From then on Velatir reads as the app, not as the admin who approved it. No one needs to stay signed in, and the connection keeps working when that admin leaves.
  </Step>
</Steps>

Velatir never sees a password, and you do not create a secret or certificate for Velatir. Velatir signs in to Microsoft with the app's own credential, which Velatir manages. Microsoft then issues short-lived access tokens for your tenant, and Velatir holds them only in memory. For your organisation, Velatir stores only which tenant approved, when, and which permissions it granted.

## The Permissions

| Permission | What Velatir uses it for |
| - | - |
| `AiEnterpriseInteraction.Read.All` | Read the Copilot conversations, prompts and responses, of users with a Microsoft 365 Copilot licence. |
| `User.Read.All` | Find who holds a Copilot licence and who each conversation belongs to, and place their activity in the right workspace. |
| `LicenseAssignment.Read.All` | Read which Copilot licences the tenant has bought and how many are assigned, for the seat counts on the card. |
| `Reports.Read.All` | Read Microsoft's Microsoft 365 Copilot usage report. |
| `AuditLogsQuery.Read.All` | Query the Microsoft Purview audit log for Copilot interaction records, including Copilot Chat users without a licence. These records contain no message text. |
| `CopilotPackages.Read.All` | Read your tenant's catalogue of Copilot agents and apps. |
| `AgentIdentity.Read.All` | Read Microsoft Entra Agent ID identities, the identities AI agents act under in your tenant. |
| `AgentIdentityBlueprint.Read.All` | Read agent identity blueprints, the templates agent identities are created from. |
| `AgentIdentityBlueprintPrincipal.Read.All` | Read agent identity blueprint principals, the blueprints' service principals in your tenant. |
| `Application.Read.All` | Read the app registrations and service principals behind agents. |
| `Organization.Read.All` | Read your tenant's display name. |
| `ReportSettings.Read.All` | Read whether your usage reports show user names or hide them. |

Several of these permissions are broader than what Velatir reads with them. Microsoft does not offer narrower ones, so Velatir limits itself:

* **`User.Read.All`** covers every user's profile. Velatir looks up only people with a Copilot licence and people who appear in Copilot audit records.
* **`Reports.Read.All`** covers every Microsoft 365 usage report. Velatir reads only the Copilot report.
* **`AuditLogsQuery.Read.All`** covers the audit log of every Microsoft 365 service. Velatir queries only Copilot interaction records.

[What Velatir collects](/connectors/microsoft-365/data) says what Velatir brings in from conversations, audit records, and licences.

## What Velatir Cannot Do

None of the permissions lets Velatir write. Velatir cannot:

* Send mail, post messages, or act as a user.
* Create, change, or delete users, groups, licences, or settings.
* Read mailboxes, OneDrive or SharePoint files, Teams chats, or calendars.

A Copilot response can still quote content Copilot read for the user, such as a passage from a document or an email. That text reaches Velatir as part of the response, and your [privacy settings](/security/data-privacy) decide whether it is kept.

## If a Permission Is Missing

Velatir checks the approval with a fresh token every 15 minutes, so a change made in Entra shows on the card within that time.

If a permission Velatir needs is missing, the connection shows **Action needed** with *Permissions missing*, followed by the names of the missing permissions. Velatir stops reading until it is fixed. Select **Reconnect** and accept every permission Microsoft lists.

Some permissions only add to what Velatir brings in. Without `AuditLogsQuery.Read.All`, for example, the connection stays **Connected**, but there are no audit records and no activity from Copilot Chat users without a licence.

Microsoft can take a few minutes to apply a new approval. If you see *Permissions missing* right after accepting, wait a few minutes and select **Reconnect**.

## Review or Revoke the Approval in Entra

<Steps>
  <Step title="Open the app" icon="app-window">
    In the Microsoft Entra admin center, open **Enterprise applications** and select **Velatir Connector**.
  </Step>

  <Step title="Review its permissions" icon="list-checks">
    Open **Permissions**. The **Admin consent** tab lists every permission your organisation granted, by the same names as on this page.
  </Step>

  <Step title="Revoke, if you want to" icon="shield-off">
    Revoke individual permissions there, or delete the app to remove all of Velatir's access. Within 15 minutes the connection in Velatir shows **Action needed**. Everything Velatir already imported is kept.
  </Step>
</Steps>

***

<CardGroup cols={2}>
  <Card title="Connect Microsoft 365" icon="plug" href="/connectors/microsoft-365">
    Before you start, and the connection steps.
  </Card>

  <Card title="What Velatir collects" icon="database" href="/connectors/microsoft-365/data">
    What is read from Microsoft, what is kept, and what is left out.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.