Microsoft 365

Access that follows the signed-in user—not the whole tenant.

Inlyra uses delegated permissions only through Microsoft Graph. Application permissions are not part of the product model.

Permission model

Start read-only. Add scope only when a released feature needs it.

Consent is incremental and described before the user grants it.

StagePermissionsPurpose
Initial connectionopenid · profile · offline_access · Mail.Read

Sign in, maintain the delegated connection, and read the authorized mailbox for triage and analysis.

Sending & actionsMail.Send · Mail.ReadWrite

Requested through incremental consent only after reply sending or message actions are released.

Shared mailboxesMail.ReadWrite.Shared · Mail.Send.Shared

Requested only after shared mailbox features are released and only within access the signed-in user already has.

Boundary

No unrestricted tenant-wide mailbox claim.

Inlyra works within the signed-in user’s mailbox and shared mailboxes that user is already authorized to access. It does not market unlimited access to every mailbox in a customer tenant.

Connection lifecycle
Authorization
Delegated
Expansion
Incremental consent
Disconnect
New Microsoft access stops
Token data
Deleted for that connection

Microsoft Entra ID

Identity and delegated authorization.

Microsoft Graph

Mailbox access within approved scopes.

Google Cloud europe-west1

Primary application infrastructure region.

Private pilot

Begin with up to three connected mailboxes.

Start private pilot