# Answer from corporate docs, safely

> Ground answers on sensitive company knowledge without handing your documents to a model.

Teams want AI answers grounded in their own knowledge, the documents, mail, and shared drives that hold what the organisation actually knows. Feeding that content to a model usually means copying sensitive material out of its access-controlled home, past the very permissions meant to protect it. That is a trade most organisations cannot make.

## What you can do

- Ground answers on a user’s own OneDrive, SharePoint, mail, and calendar so that responses reflect internal knowledge, not just the model’s training data.

- Enforce the user’s existing Entra access control lists so that each person only gets answers drawn from content they are already permitted to see.

- Return only the synthesised answer so that the raw documents never leave the Microsoft 365 boundary or reach the agent, the editor, or the appliance.

- Meter and policy-gate every request so that document-grounded chat is governed, budgeted, and audited exactly like any other call.

## How it works

Microsoft 365 Copilot is a specialised provider adapter, m365_copilot, configured on an LLM Surface. Agent Stream translates an incoming OpenAI chat call into a Microsoft 365 Copilot Chat API call made as the signed-in user, forwarding a delegated Entra token through identity pass-through. Copilot then grounds its response on that user’s OneDrive, SharePoint, mail, and calendar content while respecting their Entra access control lists, and returns only the synthesised answer, so the agent, the editor, and the appliance never receive the raw documents. Because the call runs on an ordinary surface, the same OPA policy and per-stage metering apply, making document-grounded chat governed and attributable like any other request.

Access is bounded by the user’s own permissions: Copilot never surfaces content the user cannot already see under their Entra ACLs, and a policy denial on the surface returns a 403 before the request is dispatched.

## Related

- [Providers and Models](/products/affinidi-trust-fabric/agent-stream/concepts/providers-and-models.md#how-microsoft-365-copilot-grounds-answers-without-exposing-raw-documents): How the m365_copilot adapter grounds answers without exposing raw documents.

- [Surfaces](/products/affinidi-trust-fabric/agent-stream/concepts/surfaces.md): The LLM Surface that carries the provider connection and its governance pipeline.

- [Policies](/products/affinidi-trust-fabric/agent-stream/concepts/opa-policies.md): How a surface-level policy gates who can dispatch a grounded request.

- [Governed models in every editor](/products/affinidi-trust-fabric/agent-stream/use-cases/governed-models-in-every-editor.md): Fronting Copilot from the editor alongside your other approved models.
