SIGBOT
For IT admins

Approving Sigbot in Microsoft 365

One-page brief · Last updated: 1 October 2026

Someone at your company wants to connect their Outlook to Sigbot, which builds a contact list from the email signatures in their mailbox. Microsoft has asked for an admin to approve it. This page covers what Sigbot reads, what it keeps and where, and how to approve or revoke it for the whole company.

Publisher
Sigbot Ltd, England and Wales (16997653). ICO registration ZC202535.
Permissions
Delegated only: Mail.Read, User.Read, offline_access
Application (client) ID
4cf71eb1-6fb9-4e5d-ae33-83dc7aad081b
Data location
Stored in the EU (Google Cloud), processed in London

1. What Sigbot asks Microsoft for

PermissionWhy
Mail.ReadTo read the signature at the bottom of each email. Read-only: Sigbot can't send, move or delete mail.
User.ReadTo know who connected: their name and email address.
offline_accessTo keep reading new mail without asking the person to sign in again each time.

All three are delegated: Sigbot acts only for a person who signs in and connects their own mailbox. Approving Sigbot for the company does not let it read anyone else's mail.

Why not Mail.ReadBasic? It leaves out the message body, and the signature is in the body.

For each message Sigbot reads the body, sender, recipients, subject and date, to find the signature and to tell a real correspondent from a newsletter. It also checks who the person has recently written to (up to 200 sent messages). Attachments are never downloaded.

2. What it keeps, and where

  • Kept: the contact details found in signatures (name, job title, company, email, phone, address, website). Senders it isn't sure about go to a review queue.
  • Not kept: email bodies, subjects, recipients and headers. Only a SHA-256 hash of each message ID is kept, for 180 days, so a message isn't scanned twice.
  • Where: Google Cloud Firestore in the EU, processed in London. Account sign-in data sits with Firebase Authentication, which runs in the US (DPA §6).
  • Encryption: TLS in transit and encrypted at rest. Mailbox tokens are also encrypted with AES-256-GCM (Security §2).
  • AI: when AI parsing is on, only the signature block (at most 4,000 characters) may be sent to Anthropic to read it. It can be switched off per account and per team (subprocessors).
  • Retention: automatic, on the schedule in Security §9. Disconnecting a mailbox deletes its tokens at once.

3. Why Microsoft asked for an admin

Microsoft's default consent setting (Let Microsoft manage your consent settings) stops ordinary users from giving an outside app access to their mail. So in most companies an admin approves Sigbot once, for everyone. Microsoft's screen shows Sigbot as a verified publisher (SIGBOT LTD), with Microsoft's blue badge.

4. Approve it once for the company

You need to be a Global Administrator, Privileged Role Administrator, Cloud Application Administrator or Application Administrator.

  1. Open Microsoft's approval page and sign in with your admin account.
  2. Check it lists only: Read user mail, Sign in and read user profile, and Maintain access to data you have given it access to.
  3. Click Accept. Microsoft sends you to a Sigbot page that confirms it, and your colleague can connect Outlook.
Open Microsoft's approval page https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=4cf71eb1-6fb9-4e5d-ae33-83dc7aad081b&redirect_uri=https%3A%2F%2Fsigbot.app%2Fauth%2Fcallback%2Foutlook&scope=https%3A%2F%2Fgraph.microsoft.com%2FMail.Read+https%3A%2F%2Fgraph.microsoft.com%2FUser.Read+offline_access&state=admin-consent

Admin for more than one Microsoft 365 organisation? Replace organizations in the link with your company's domain or tenant ID.

Or review requests as they come

Turn on Microsoft's admin consent workflow: Entra admin centre → Enterprise applications → Consent and permissions → Admin consent settings → Users can request admin consent to apps they are unable to consent to → Yes, and choose reviewers. Your colleague then sees Request approval on Microsoft's screen, and a reviewer approves or denies it.

To limit Sigbot to certain people: Enterprise applications → Sigbot → Properties → Assignment required → Yes, then add them under Users and groups.

5. Revoke it

  • For the whole company: Entra admin centre → Enterprise applications → All applications → Sigbot (Application ID 4cf71eb1-…) → Properties. Set Enabled for users to sign in? to No to stop it at once, or Delete to remove the app and every permission granted to it.
  • For one person: they can disconnect Outlook in Sigbot (Import Emails → Disconnect). That deletes Sigbot's tokens for their mailbox at once.

6. Audit log and Enterprise

Every team plan keeps a year of audit log, which owners and admins can export as CSV. Enterprise adds single sign-on (Entra ID, Okta or SAML), SCIM, audit log streaming and a read-only API, set up with you on a call: book one here.

7. Questions

Security questions: security@sigbot.co. Anything else: support@sigbot.co, or book a 20-minute call. We reply within one working day.