Exact availability depends on your workspace configuration. New to Surfaice? Read What is Surfaice? first.
Principles
Nothing connects without consent
Nothing connects without consent
Administrators approve Surfaice in your Microsoft 365, Google Workspace, or other tenant. Each system of record follows the same rule: no silent tenant-wide grabs.
Email is per user
Email is per user
Mailbox access is granted by the individual user to their own mailbox. There is no tenant-wide mailbox read. A user can only reach email they could already open themselves.
Roles gate who even sees a connector
Roles gate who even sees a connector
Connector availability is governed by role inside Surfaice. Roles that should not use a connector never see the option.
Permissions are inherited, never expanded
Permissions are inherited, never expanded
A signed-in user sees exactly the data their existing role in Lucernex, SharePoint, or another system already grants. Surfaice does not grant new access.
Exclusions apply across skills
Exclusions apply across skills
Keywords, senders, domains, and folders can be excluded instance-wide (for example HR or legal topics). Those exclusions apply to every email-touching skill by default.
Typical setup sequence
1
IT approves the application
Your identity / SaaS admins consent to Surfaice in the relevant tenant.
2
Surfaice roles are assigned
Only intended roles (for example lease admin) get connector entitlements.
3
Users connect their own accounts
Users complete OAuth for personal connectors such as Outlook.
4
Rollout stays staged
Connectors go live one at a time on explicit sign-off and can be revoked in your IdP at any time.
What you should see in the app
1
Connectors settings
Each integration shows connected / not connected. OAuth connectors display the signed-in account email.
2
Consent screens
Microsoft or Google consent lists the exact permissions Surfaice requests — no broader than needed for lease and project workflows.
3
Role visibility
If you do not see Lucernex or Outlook at all, your Surfaice role may not include that connector — contact your admin.
Related
- Working with Hugo — access denied and connector troubleshooting
- Permissions
- Data handling
- Security overview