SharePoint Access
The SharePoint tools let an agent read and write documents across your Microsoft 365 SharePoint sites: browse and search libraries, read files, and (when granted) create, update, move, and delete content. Which sites an agent can reach, and whether it can write to them, is controlled per agent through the Configure SharePoint Access modal.
Overview
The nine SharePoint tools (sharepoint_list_sites, sharepoint_browse, sharepoint_search, sharepoint_read_file, sharepoint_create_file, sharepoint_update_file, sharepoint_create_folder, sharepoint_move_item, sharepoint_delete_item) share a single access grant. Rather than configuring each tool separately, you grant the agent access to specific sites once, and every SharePoint tool the agent has is scoped to that grant.
Access is fail-closed: an agent with no grant receives no SharePoint tools at all and will tell users it has no SharePoint access.
Why access is IT-Admin only
Configuring which sites an agent can write to is an IT-Admin concern. An employee must not be able to widen their own assistant's reach from the PA Hub Tools page. The gear that opens this modal is hidden for employee-facing personas, the same way the Search Mailbox configuration is hidden. Employees can still enable or disable a SharePoint tool within the access an administrator has already granted; they cannot change the sites or the read/write level.
Opening the modal
- Go to the agent's Tools tab.
- Find the SharePoint tool group and assign at least one SharePoint tool to the agent.
- Click the gear icon on the SharePoint group header to open Configure SharePoint Access.
Access modes
The modal offers two modes:
- Full Access -- the agent can read and write any SharePoint site in the organization, including sites created after today. Choosing Full Access collapses the site picker and shows an amber warning. Full access includes write, so avoid it unless the agent genuinely needs tenant-wide reach.
- Scoped Access -- grant Read or Read + Write on specific sites. This is the recommended default.
Granting scoped access
Under Scoped Access you see the tenant's SharePoint sites:
- Site collection -- when your tenant has more than one SharePoint hostname, a dropdown lets you switch between them, each labeled with its site count. When there is only one hostname (the common case) the dropdown is hidden and the filter box takes the full width.
- Filter -- free-text match against a site's display name and path within the selected hostname.
- Site table -- each site has three options: None, Read, or Read + Write. The pinned first row sets every site shown at once.
Selections persist as you switch hostnames, change the filter, or toggle between Full and Scoped access within a session. Nothing is committed until you click Save, which replaces the agent's grant set atomically: a site you set back to None is genuinely revoked.
What Read + Write permits
When any site is set to Read + Write, the modal shows an amber warning. Read + Write lets the agent create, overwrite, move, and delete content on those sites without a human approving each change. Grant it deliberately.
Unavailable sites
If a site was granted and later removed from SharePoint, it appears in the table as a disabled unavailable row showing its stored display name. This lets you see and clear a stale grant rather than wondering where a site went. You cannot grant new access to an unavailable site, but you can set it back to None to remove the leftover grant.
Site inventory freshness
The site list is served from a cached inventory that refreshes in the background roughly every 24 hours, so the modal never blocks on a full enumeration of a large tenant. The modal shows how long ago the inventory was updated and a Refresh control to force an immediate re-sweep.
Validation
In Scoped mode, Save is disabled until at least one site is granted. The modal explains inline that an agent with no grants receives no SharePoint tools and will report that it has no SharePoint access. Add at least one Read or Read + Write grant, or switch to Full Access, to save.