Northstar EV Infrastructure

EV Infrastructure Workspace

Microsoft 365 Readiness

Syntra Demo

Prepare tenant permissions, SharePoint folders, approval roles, and Copilot action boundaries before production connection.

BK

0

Live Tenant Connections

Demo mode only

TC

6

Readiness Checks

Pre-connection verification items

RC

5

Proposed Graph Scopes

Delegated least-privilege only

AG

4

Approval Gates

Before production writes

EW

0

External Writes Enabled

All blocked in demo mode

Connection Mode

Current connection status across the Microsoft 365 surface area

Demo Mode

Active

Fictional demo data — no Microsoft services called

Microsoft 365 Readiness

Configuring

Planning and approval layer — no live connections

Microsoft Graph Connected

Not Connected

Requires tenant admin consent and delegated scopes

SharePoint Folder Mapping

Placeholder

Mapped to demo paths only; production requires tenant confirmation

Copilot Action Bridge

Demo Only

Actions are simulated; no Copilot endpoints are called

Demo mode does not call Microsoft services. Production connection requires customer tenant approval, least-privilege delegated scopes, and human approval gates.

Tenant Readiness Checklist

Items to verify before enabling production Microsoft 365 connection

Confirm tenant admin sponsor

Ready to Verify

Confirm Microsoft 365 licensing

Planned

Confirm Microsoft 365 Copilot licensing path

Planned

Confirm approved SharePoint document library

Needs Customer Admin

Confirm allowed user groups

Needs Customer Admin

Confirm delegated Graph scopes

Planned

Confirm audit/logging requirements

Ready to Verify

Confirm external AI policy

Ready to Verify

Confirm approval roles

Ready to Verify

Proposed Graph Scope Plan

Delegated least-privilege scopes planned for production — no live OAuth used

User Profile

Low RiskDelegated

Example: Identify signed-in user and workspace role

Rule: Read signed-in user only

SharePoint / OneDrive Files

Medium RiskDelegated

Example: Read approved brand folders; save approved proposal packages

Rule: Selected folders only; no broad tenant crawling

Outlook Drafts

Medium RiskDelegated

Example: Prepare client follow-up drafts

Rule: Draft only; human approval before send

Calendar Drafts

Medium RiskDelegated

Example: Prepare proposal review meeting invite

Rule: Draft/preview only until approved

Teams / Notifications

Medium RiskDelegated

Example: Notify internal approver or project coordinator

Rule: Internal-only notification after approval

SharePoint Folder Mapping

Planned folder structure — not connected until tenant is approved

/Syntra EV Workspace/Brand Kit/

Approved brand assets, logos, color palettes

Rule: Read approved folder only; no tenant-wide access

Not Connected

/Syntra EV Workspace/Templates/

PowerPoint templates, proposal layouts

Rule: Read approved templates; no modification without approval

Not Connected

/Syntra EV Workspace/Proposal Packages/

Generated proposal decks and executive summaries

Rule: Save only after human approval of final package

Not Connected

/Syntra EV Workspace/Daily Reports/

Ingested daily report source files

Rule: Read-only intake; no automatic processing

Not Connected

/Syntra EV Workspace/Approval Evidence/

Audit trail exports, approval logs

Rule: Write audit evidence only; no client data in exports

Not Connected

/Syntra EV Workspace/Exports/

Client-ready PowerPoint, Word, PDF deliverables

Rule: Save only after all approval gates are satisfied

Not Connected

All folders are placeholder paths. Production mapping requires confirming the customer's actual SharePoint document library structure and access controls.

Copilot Action Boundary

Defining safe Copilot interaction boundaries for the EV Infrastructure workspace

  • Copilot is the approved AI assistant/agent layer inside the customer environment.
  • Syntra actions should only use approved context.
  • Copilot actions should call safe Syntra endpoints only after user approval.
  • Sensitive data should be redacted or scoped before drafting.
  • External LLMs remain disabled unless explicitly approved.

Summarize approved daily report

Demo Only

Draft proposal executive summary

Demo Only

Prepare missing-info follow-up

Demo Only

Route approval request

Demo Only

Save approved package to SharePoint

Blocked until connected and approved

User Role Mapping Placeholder

Planned role-to-group mapping — not connected to a real Azure AD tenant

Owner / Executive Approver

Final approval for all external actions
Demo User: Sarah MillerGroup: Service Business Owners

Project Coordinator

Manage workflow gates and missing info
Demo User: Sarah MillerGroup: EV Project Coordinators

Proposal Reviewer

Review proposal content before client delivery
Demo User: Lisa ChenGroup: EV Proposal Reviewers

Brand Reviewer

Approve brand asset usage in client materials
Demo User: Lisa ChenGroup: Brand Approvers

Incentive Reviewer

Verify incentive values before client presentation
Demo User: Marcus RiveraGroup: EV Incentive Analysts

Read-only Viewer

View proposals and dashboards; no write or approve
Demo User: Demo UserGroup: EV Viewers

Demo users are fictional. In production, roles map to Microsoft 365 groups via delegated Graph. All approvals remain human-gated regardless of group membership.

Production Connection Steps

Required steps before enabling live Microsoft 365 connectivity

1

Tenant admin review

2

Register app / approve integration

3

Configure least-privilege delegated scopes

4

Map SharePoint folders

5

Map approval roles

6

Run test in demo/sandbox

7

Enable production writes only after approval

Safety Guardrails

Enforced in demo mode; configurable per customer in production

No external writes in demo mode

No broad tenant crawling

No automatic email sending

No automatic calendar scheduling

No automatic SharePoint final save

No client logo usage without approval

No external LLM use unless approved

Demo Safety

This is a readiness planning tool. No real Microsoft Graph, SharePoint, OneDrive, Outlook, Teams, Calendar, Copilot, Copilot Studio, or Microsoft 365 services are connected. No OAuth tokens are requested. No tenant IDs, client IDs, or secrets are stored. All scope plans, folder paths, and role mappings are fictional placeholders for planning purposes only.

Delegated permissions onlyNo application-level tenant-wide permissions are requested or planned.
Human approval gatesAll writes, sends, and saves require explicit human approval.
Production-ready designAll readiness checks, scope plans, and role mappings follow enterprise best practices.