Northstar EV Infrastructure
EV Infrastructure Workspace
Sarah Miller
Owner
Microsoft 365 Readiness
Syntra DemoPrepare tenant permissions, SharePoint folders, approval roles, and Copilot action boundaries before production connection.
0
Live Tenant Connections
Demo mode only
6
Readiness Checks
Pre-connection verification items
5
Proposed Graph Scopes
Delegated least-privilege only
4
Approval Gates
Before production writes
0
External Writes Enabled
All blocked in demo mode
Connection Mode
Current connection status across the Microsoft 365 surface area
Demo Mode
ActiveFictional demo data — no Microsoft services called
Microsoft 365 Readiness
ConfiguringPlanning and approval layer — no live connections
Microsoft Graph Connected
Not ConnectedRequires tenant admin consent and delegated scopes
SharePoint Folder Mapping
PlaceholderMapped to demo paths only; production requires tenant confirmation
Copilot Action Bridge
Demo OnlyActions are simulated; no Copilot endpoints are called
Demo mode does not call Microsoft services. Production connection requires customer tenant approval, least-privilege delegated scopes, and human approval gates.
Tenant Readiness Checklist
Items to verify before enabling production Microsoft 365 connection
Confirm tenant admin sponsor
Ready to VerifyConfirm Microsoft 365 licensing
PlannedConfirm Microsoft 365 Copilot licensing path
PlannedConfirm approved SharePoint document library
Needs Customer AdminConfirm allowed user groups
Needs Customer AdminConfirm delegated Graph scopes
PlannedConfirm audit/logging requirements
Ready to VerifyConfirm external AI policy
Ready to VerifyConfirm approval roles
Ready to VerifyProposed Graph Scope Plan
Delegated least-privilege scopes planned for production — no live OAuth used
User Profile
Low RiskDelegatedExample: Identify signed-in user and workspace role
Rule: Read signed-in user only
SharePoint / OneDrive Files
Medium RiskDelegatedExample: Read approved brand folders; save approved proposal packages
Rule: Selected folders only; no broad tenant crawling
Outlook Drafts
Medium RiskDelegatedExample: Prepare client follow-up drafts
Rule: Draft only; human approval before send
Calendar Drafts
Medium RiskDelegatedExample: Prepare proposal review meeting invite
Rule: Draft/preview only until approved
Teams / Notifications
Medium RiskDelegatedExample: Notify internal approver or project coordinator
Rule: Internal-only notification after approval
SharePoint Folder Mapping
Planned folder structure — not connected until tenant is approved
/Syntra EV Workspace/Brand Kit/
Approved brand assets, logos, color palettes
Rule: Read approved folder only; no tenant-wide access
/Syntra EV Workspace/Templates/
PowerPoint templates, proposal layouts
Rule: Read approved templates; no modification without approval
/Syntra EV Workspace/Proposal Packages/
Generated proposal decks and executive summaries
Rule: Save only after human approval of final package
/Syntra EV Workspace/Daily Reports/
Ingested daily report source files
Rule: Read-only intake; no automatic processing
/Syntra EV Workspace/Approval Evidence/
Audit trail exports, approval logs
Rule: Write audit evidence only; no client data in exports
/Syntra EV Workspace/Exports/
Client-ready PowerPoint, Word, PDF deliverables
Rule: Save only after all approval gates are satisfied
All folders are placeholder paths. Production mapping requires confirming the customer's actual SharePoint document library structure and access controls.
Copilot Action Boundary
Defining safe Copilot interaction boundaries for the EV Infrastructure workspace
- Copilot is the approved AI assistant/agent layer inside the customer environment.
- Syntra actions should only use approved context.
- Copilot actions should call safe Syntra endpoints only after user approval.
- Sensitive data should be redacted or scoped before drafting.
- External LLMs remain disabled unless explicitly approved.
Summarize approved daily report
Demo OnlyDraft proposal executive summary
Demo OnlyPrepare missing-info follow-up
Demo OnlyRoute approval request
Demo OnlySave approved package to SharePoint
Blocked until connected and approvedUser Role Mapping Placeholder
Planned role-to-group mapping — not connected to a real Azure AD tenant
Owner / Executive Approver
Final approval for all external actionsProject Coordinator
Manage workflow gates and missing infoProposal Reviewer
Review proposal content before client deliveryBrand Reviewer
Approve brand asset usage in client materialsIncentive Reviewer
Verify incentive values before client presentationRead-only Viewer
View proposals and dashboards; no write or approveDemo users are fictional. In production, roles map to Microsoft 365 groups via delegated Graph. All approvals remain human-gated regardless of group membership.
Production Connection Steps
Required steps before enabling live Microsoft 365 connectivity
Tenant admin review
Register app / approve integration
Configure least-privilege delegated scopes
Map SharePoint folders
Map approval roles
Run test in demo/sandbox
Enable production writes only after approval
Safety Guardrails
Enforced in demo mode; configurable per customer in production
No external writes in demo mode
No broad tenant crawling
No automatic email sending
No automatic calendar scheduling
No automatic SharePoint final save
No client logo usage without approval
No external LLM use unless approved
Demo Safety
This is a readiness planning tool. No real Microsoft Graph, SharePoint, OneDrive, Outlook, Teams, Calendar, Copilot, Copilot Studio, or Microsoft 365 services are connected. No OAuth tokens are requested. No tenant IDs, client IDs, or secrets are stored. All scope plans, folder paths, and role mappings are fictional placeholders for planning purposes only.