LexHouse for IT
What LexHouse reads in your Microsoft 365, what it can't, and who grants each part.
Signing in
Sign-in asks only who the person is: their name and email (openid, profile, email). The Word add-in signs in the same way, through LexHouse's own scope, which reads nothing from Microsoft: access_as_user.
Your IT approves this once for your organisation, on Microsoft's own consent page. The link is made for your organisation, so it isn't on this public page.
Ask for your organisation's linkWhat it reads, and who grants it
Sites.Selected
SharePoint: only the sites your IT grants it, one by one
Who grants it: Your IT, in the approval
Mail.Read
Mail: only the mailboxes the firm's Exchange admin scopes it to
Who grants it: Your Exchange admin, for the mailboxes you name
User.Read.All
The directory's people
Who grants it: Your IT, in the approval
GroupMember.Read.All
The directory's groups and their members
Who grants it: Your IT, in the approval
Mail.Read, offline_access
The person's own mail
Who grants it: The person, for themselves, one purpose at a time
Files.Read, offline_access
The person's own files
Who grants it: The person, for themselves, one purpose at a time
Chat.Read, Team.ReadBasic.All, Channel.ReadBasic.All, ChannelMessage.Read.All, offline_access
The person's own Teams chats and channels
Who grants it: The person, for themselves, one purpose at a time
Mail.Send, offline_access
Sending an email as the person, when they send it
Who grants it: The person, for themselves, one purpose at a time
Team.ReadBasic.All, Channel.ReadBasic.All, offline_access
The names of the person's own teams and channels, for the channels they pick (no messages, no files)
Who grants it: The person, for themselves, one purpose at a time
What it can't
- It writes nothing in your Microsoft 365 but the email a person sends from their own mailbox, which they alone grant (Mail.Send can neither read nor change their mailbox).
- Mail.Read is never in the approval: your Exchange admin limits it to the mailboxes you name (RBAC for Applications).
Where the steps are
- 1Approve sign-in: open your organisation's link on Microsoft's consent page (ask for it above).
- 2A law firm: your Exchange admin limits mail to the mailboxes you name, and your IT grants SharePoint sites one by one. Your LexHouse contact walks you through both.
- 3A company: create LexHouse's mailbox in your tenant and limit LexHouse to it. The person setting LexHouse up sends you a script from their Setup page, and you send back the one line it prints. They then forward or copy to it what LexHouse needs.
- 4For the Teams channels they pick, a second script lets LexHouse read those channels' files, one site at a time.
What we keep
- Our AI provider is Anthropic (Claude), through its commercial API. Under Anthropic's commercial terms, what we send through the API isn't used to train its models.
- Access codes are stored only as a hash: we can't read a code back, only check the one typed.
- Walls per client: a lawyer sees only the clients they work for.
- Your workspace is deleted on your written request.
- What LexHouse records about use