Connect Outlook & Microsoft 365 to Agee
Connecting an Outlook or Microsoft 365 mailbox lets Agee act as a full email client inside your case files — reading, sending, and organizing email, keeping your calendar in sync, capturing billable time, and keeping each matter’s email in one place. This page explains, in plain English, what Agee accesses, how that data is used and protected, and what disconnecting or deleting does.
For authenticated users of the Agee legal platform · Last updated June 28, 2026
What connecting does
A connected Microsoft 365 mailbox turns Agee into an email client for that account, tied to your matters:
- A full email experience in Agee. Read your mail and compose, reply, reply-all, forward, and organize it (mark read/unread, move or file, move to Deleted Items or Junk) from within Agee.
- Calendar in sync. Your Outlook calendar and your matter calendar stay aligned — Agee reads your events and, when you ask, creates or updates them.
- Email on the right case. Messages are associated with the correct matter so your firm can review a matter’s full email record and search it in one place.
- Billable time, captured. Agee can capture billable activity from email so it can be recorded against the correct matter.
This is your firm’s connected mailbox, used for your firm’s own work on its own matters.
How to connect
- In Agee, open Settings → Connected accounts and choose Connect Outlook / Microsoft 365.
- You are redirected to Microsoft’s own secure sign-in page (
login.microsoftonline.com). You sign in directly with your firm’s Microsoft 365 (work or school) account and approve access on Microsoft’s consent screen. Agee never sees, receives, or stores your Microsoft password.
- Microsoft issues Agee a secure, revocable access token. You can disconnect at any time in Agee, and you can review or revoke Agee’s access from your Microsoft account at myaccount.microsoft.com (your IT administrator can also manage it in Microsoft Entra ID).
In many organizations a Microsoft 365 administrator controls whether third-party apps may connect. If your organization requires it, an administrator may need to approve the connection.
What Agee accesses (the permissions you grant)
On Microsoft’s consent screen you grant Agee these Microsoft Graph permissions. Because Agee is a full email client — not a read-only viewer — these include read/write access to your mail and calendar:
| Permission | Why Agee asks for it |
Your Microsoft identity (User.Read) | Identify which Microsoft account is connected (email address, basic profile). |
Read and write your mail, and send on your behalf (Mail.ReadWrite + Mail.Send) | Sync and read your messages into Agee; send and reply from your mailbox; and organize messages (mark read/unread, move or file, move to Deleted Items or Junk) when you ask. |
Read and write your calendar (Calendars.ReadWrite) | Keep your Outlook calendar and your matter calendar in sync — read events and, when you ask, create or update them. |
| Maintain access while you are offline, and receive change notifications | Keep your mailbox in sync in near-real-time without asking you to sign in repeatedly. |
Agee requests only the access needed to run these features. The integration does not request access to your Microsoft passwords or payment instruments.
What Agee stores, and where
When connected, Agee syncs from your Microsoft 365 mailbox into your firm’s Agee workspace, along with records Agee derives from it (for example, extracted billing time entries, case-match and follow-up suggestions, and AI-generated draft text).
- What gets synced. Message headers and metadata and a preview of each message; the full message content and attachments are stored for email linked to a matter. Calendar events you sync are stored as well.
- Near-real-time sync. Agee uses Microsoft Graph change-notification subscriptions so new mail syncs in promptly; these subscriptions are torn down when you disconnect.
- Where it lives. Agee’s infrastructure runs on Amazon Web Services in the United States.
- Encryption. Email content and attachments are encrypted at rest at the storage layer and in transit (TLS), and are isolated by row-level security. The OAuth tokens that authorize the connection additionally receive per-connection AWS KMS envelope encryption.
- Firm isolation. Your firm’s data is isolated by database row-level security tied to your firm’s tenant. Only your firm can reach it.
How Agee uses your email — and what it never does
Agee accesses your connected Microsoft 365 data solely to provide and improve a small set of user-facing features for your firm’s own work on its own matters:
- Work your email inside each case. Read, send, reply, and organize messages, and link and search a matter’s email so your firm can review its full email record in one place.
- Capture billable activity from email so it can be recorded against the correct matter.
- Assist your drafting — for example, suggesting a reply that you review and send from your own mailbox.
Just as important, here is what Agee does not do with your email:
- Your email is never used to train AI models. When a feature uses AI, your message content is processed by large language models (through AWS Bedrock / Anthropic Claude) only to produce that one result, for your firm, per request. It is not used to train, fine-tune, or improve any generalized or cross-customer AI model.
- No sale, no transfer. Agee never sells, rents, or transfers your email — content or metadata — to any third party for that party’s own purposes. The data belongs to your firm; Agee processes it on your firm’s behalf.
- No advertising. Agee runs no advertising and does not use your email to target or measure ads.
- Limited human access. Agee personnel do not read your email in the ordinary course of running the service. People access mailbox content only with your firm’s consent, as necessary for security, abuse-prevention, or support, to comply with law, or in aggregated or anonymized form for internal operations.
To deliver these features Agee relies on a limited set of service providers, including Amazon Web Services (hosting, in the United States) and AWS Bedrock / Anthropic (the AI models behind AI-assisted features); see our Privacy Policy for details. Agee’s access to your Microsoft 365 mailbox is governed by the Microsoft APIs Terms of Use and by your organization’s Microsoft 365 administrator policies.
If you connect your own AI assistant
Separately from this email connection, your firm can connect an AI assistant such as Claude or ChatGPT to Agee through the AI-assistant connector. If you do, and you ask that assistant to work with your Microsoft 365 email, the data responsive to your request is sent to that AI provider under your own account and that provider’s terms. By connecting it you consent to share that data with the provider, and Agee does not control how that provider uses, stores, or retains it. The “never used to train AI models” commitment above covers Agee’s own processing; a third-party assistant you connect is governed by your agreement with that provider.
Security
- No password sharing. The connection uses Microsoft’s OAuth sign-in; Agee never receives your Microsoft password.
- Encryption. Your email and attachments are encrypted at rest at the storage layer and in transit (TLS), and are isolated by row-level security. The OAuth tokens that authorize the connection additionally receive per-connection AWS KMS envelope encryption (access and refresh tokens encrypted separately), stored apart from your mail.
- Firm-level isolation. Database row-level security keeps your firm’s data reachable only by your firm.
- See our Security page for Agee’s full security posture.
Your responsibilities before you connect
- Connect a firm email account, not a personal one. Agee is for your firm’s business email. Connect a firm or organization mailbox — not a personal Gmail or personal Microsoft account.
- Connect only a mailbox you are authorized to use. Connect only if your organization permits it; firm or IT administrators should connect shared or firm mailboxes only where they have authority to do so.
- You control what comes in. Connecting a mailbox brings its email — which may include privileged, confidential, or otherwise sensitive client information — into your firm’s Agee workspace. You and your firm are responsible for ensuring that doing so is permitted for your matters and consistent with your professional, ethical, and client-confidentiality obligations.
- Your firm decides. Whether to enable email connections, and which mailboxes to connect, is your firm’s decision.
How long Agee keeps your email
Agee retains the email it has synced for the lifetime of the mailbox connection, so your firm can keep using the features above, and deletes it on request. Agee does not run a fixed-period auto-expiry on this data.
Disconnecting and deleting
- Disconnecting is not deleting. Disconnecting in Agee stops future syncing and erases the access Agee has stored for that mailbox. For Microsoft 365, disconnecting also tears down Agee’s Microsoft Graph change-notification subscriptions. To fully revoke the access you granted, also remove Agee from your connected apps at Microsoft. Disconnecting does not, by itself, delete email already synced into Agee.
- Your real mailbox stays intact. Disconnecting — and any later deletion of your synced data in Agee — affects only Agee’s stored copy. It does not delete, trash, or modify any message in your actual Outlook / Microsoft 365 mailbox. (Separately, when you use Agee’s email tools to send a message, or to file or move one, that action acts on your real mailbox, the same as any email client.)
- Deleting your synced data. To request deletion of the data Agee synced from your mailbox, contact support@agee.law, as described in our Privacy Policy. Some information may be retained where necessary for legal, compliance, security, or backup purposes — for example, billing time entries you have already recorded are kept as your firm’s business records, with the originating email content removed.
- Backups. Deleted data is removed from Agee’s live systems promptly. Copies may persist in encrypted, access-controlled disaster-recovery backups until those backups expire on their normal schedule (currently up to roughly 35 days for point-in-time database recovery, plus the retention window of immutable backup snapshots), after which they are no longer recoverable. Agee does not restore deleted data from backups into its live systems.
Privacy & support
For the full picture, see our Privacy Policy, Terms of Service, and Security page. Questions or issues: support@agee.law · (954) 324-3435.