Answer
What access do I have to grant an AI IT support service?
You grant delegated permissions to your Microsoft 365 or Google Workspace tenant scoped to the actions you want automated — typically user, licence, mailbox and device management. No standing admin account is created, permissions are exercised through short-lived tokens, and you can revoke everything from your own admin console at any time.
You are in control of the grant, and of removing it
Access is granted through your own identity provider's standard consent flow, by an admin in your organisation, and appears in your admin console as an application with a visible permission list. Revoking it is one action on your side and takes effect immediately. Nothing about the arrangement depends on us behaving well after you want out.
Least privilege in practice
Grant only the scopes matching what you want automated. If you never want mailbox content read, do not grant it — the agent will then tell you when a request needs a permission it does not hold rather than working around it. Most customers start narrow, with password and MFA management plus licence assignment, and widen once they have seen the audit log for a month.
No standing administrator account
We do not ask you to create a named admin user for us, and we do not hold a permanent privileged session. Each action requests a short-lived token scoped to that single task and discards it afterwards. This is the difference between giving someone a key to the building and buzzing them in for a specific visit that is logged.
What you can see afterwards
Every use of every permission is written to an append-only audit record on our side, exportable at any time, and it also appears in your own tenant's audit log. You can reconcile the two independently. If a change appears that you did not expect, you have both the record and the ability to revoke access before asking us about it.
Related
Follow-on questions
How long does onboarding take?
Under ten minutes for a typical cloud-first business: create the account, consent to the permission scopes you are comfortable with, invite your users. There is no onboarding call, no discovery project and no professional services fee, and you can start raising tickets straight away.
What happens to our access grant if we cancel?
Revoke consent in your admin console and the permissions end immediately, regardless of billing state. Support conversations and audit records are deleted within 30 days of account closure, and you can export them beforehand from your account page.
Get started
Open a chat. The AI picks up before the second ring — every time.
No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.