Outlook for AI agents
Outlook is Microsoft's email and calendar platform, combining messaging, scheduling, and contacts in one workspace. Professionals use it to manage communication and meetings across an organization. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Outlook.
Create a calendar event
Schedule a meeting with attendees and a time slot directly on a connected calendar.
Draft an email for review
Create an email draft with recipients and content, held for review before sending.
Accept a meeting invite with approval
Accept a calendar event invite only after the recipient confirms they can attend.
306 Outlook actions, graded by risk.
Every Outlook action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
117Look things up. Allowed by default.
- outlook.get_eventGet calendar event
- outlook.list_chatsList Teams chats
- outlook.list_usersList users
- outlook.get_messageGet email message
- outlook.get_profileGet Outlook profile
- outlook.list_eventsList events
- outlook.list_placesList places
- outlook.get_calendarGet specific calendar
- outlook.get_scheduleGet schedule
- outlook.query_emailsQuery Emails
- outlook.get_mail_tipsGet mail tips
- outlook.list_contactsList Outlook contacts (Deprecated)
- outlook.list_messagesList Messages
- outlook.search_eventsSearch calendar events
- outlook.get_mail_deltaGet mail delta
- outlook.get_me_outlookGet user outlook
write
129Create and change things. Allow, or ask the user first.
- outlook.send_draftSend draft
- outlook.send_emailSend email
- outlook.create_taskCreate To Do task
- outlook.create_draftCreate email draft
- outlook.update_emailUpdate email message
- outlook.create_contactCreate contact
- outlook.update_contactUpdate Contact
- outlook.create_calendarCreate calendar
- outlook.create_me_eventCreate calendar event for user
- outlook.update_todo_taskUpdate To Do task
- outlook.create_email_ruleCreate Email Rule
- outlook.update_email_ruleUpdate Email Rule
- outlook.create_draft_replyCreate a draft reply
- outlook.create_mail_folderCreate mail folder
- outlook.update_mail_folderUpdate mail folder
- outlook.add_mail_attachmentAdd mail attachment
destructive
60Delete, cancel or archive. Ask first, or deny outright.
- outlook.cancel_eventCancel user calendar event
- outlook.delete_eventDelete calendar event (Deprecated)
- outlook.delete_contactDelete Contact
- outlook.delete_messageDelete Message
- outlook.delete_calendarDelete calendar
- outlook.delete_todo_taskDelete To Do task
- outlook.delete_email_ruleDelete Email Rule
- outlook.delete_mail_folderDelete mail folder
- outlook.cancel_calendar_eventCancel user's calendar event
- outlook.delete_calendar_eventDelete calendar event
- outlook.delete_calendar_groupDelete calendar group
- outlook.delete_contact_folderDelete contact folder
- outlook.delete_event_extensionDelete event extension
- outlook.delete_master_categoryDelete master category
- outlook.delete_event_attachmentDelete event attachment
- outlook.delete_event_permanentlyPermanently Delete Event
Outlook in three steps.
- 01Your users connect OutlookThey sign in to Outlook on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create To Do task” can wait for the user, and “delete calendar event (Deprecated)” can be denied outright.
- 03Any agent can actYour agent calls Outlook through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('outlook', { read: 'allow', write: 'ask', // create_task destructive: 'deny', // delete_event }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Outlook connects.
Users sign in to Outlook on Arc0 Connect and approve the scopes you request. Build with Arc0’s Outlook OAuth app, or bring your own so the Outlook consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Outlook connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0 · OAuth 2.0 client credentials
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Outlook from any agent.
Outlook and Arc0, answered.
Can I use Outlook with Claude, ChatGPT or Cursor?
Yes. Connect Outlook to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Outlook actions you allow.
How do users connect Outlook?
Users sign in to Outlook on Arc0 Connect and approve the scopes you request. Build with Arc0’s Outlook OAuth app, or bring your own so the Outlook consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Outlook actions can my agent take?
306 in total: 117 read, 129 write and 60 destructive, such as “create To Do task”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Outlook?
Yes. Actions like “delete calendar event (Deprecated)” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Outlook too?
Yes. The same Outlook connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Outlook into your agent.
Your users connect Outlook once, under your brand. Your agent gets 306 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan