What a pilot involves.
Twenty-one days of real work on the firm’s own Microsoft 365.
Signing to day twenty-two.
Signing, setup, go-live, and the twenty-one days that follow.
Signing
The Order Form is signed first, so nothing has to be agreed again at the end.
Setup
Systems connected, clients matched, the policy pack reviewed with the firm’s compliance lead.
Go-live
The first people are connected, and real work starts.
Days 1 to 21
Briefs before client meetings, chasing work stuck on a missing document, engagement records kept current.
Before day 21
One note in writing ends it. The environment is torn down and the deletion confirmed in writing.
Day 22
If it is working, there is nothing to do. The subscription simply continues.
Setup, in three steps.
None of them touch a device, and none of them change the network.
admin@contoso.com
Permissions requested
Review for your organization
This application is not published by Microsoft or your organization.
This app would like to:
- Read user mail
- Read user calendars
- Read user chat messages
- Read user channel messages
- Read all files that user can access
- Read user’s tasks and task lists
- Sign in and read user profile
- View users’ basic profile
If you accept, this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions.
Does this app look suspicious? Report it here
Microsoft’s own screen, listing eight of the ten read permissions. The other two, openid and offline_access, are part of signing in.
The approval
Approving is one click. Nothing switches on until a real person signs in and a calendar read succeeds.
The address
The firm’s connector address goes into the assistant’s admin settings, and the firm chooses who sees it.
The sign-in
Each person signs in with their own Microsoft account, MFA included, the first time they ask for firm work.
Ten permissions to read, three to act.
Delegated only. The ceiling is what each person can already open.
openidSigning people in.profileTheir name, so work is attributed correctly.offline_accessNot re-prompting on every request.User.ReadChecking the person against the firm’s directory.
Mail.ReadCorrespondence relevant to the request.
Calendars.ReadMeeting context, and the go-live check.
Chat.ReadTeams chats the person is in.
ChannelMessage.Read.AllChannels the person belongs to.
Files.Read.AllFiles the person can already open.Tasks.ReadTo Do and Planner items.
The action approval, on its own screen.

Mail.ReadWritePreparing a draft for a person to review.
Mail.SendSending a message a person approved.Tasks.ReadWriteCreating or updating a task.
Decline or withdraw it at any time. Reading keeps working.
![]()
Karbon and Salesforce, where connected, each carry their own approval in that system’s own terms.
What we never ask IT to do.
Proxara Connect is hosted, and appears in Entra like any other application.
Install anything
No agent, no package, no update channel.
Change the network
No proxy, no firewall rule, no DNS. Nothing listens on the firm’s network.
Handle credentials
The assistant registers itself. There is no secret to store or rotate.
Grant broad access
Delegated only. Nobody reaches more than they already can.
Any permission can be revoked from its row in Entra, or the application deleted, without asking us.

