SharePoint for AI agents

SharePoint is Microsoft's platform for document management and team intranets, storing files and lists that teams collaborate on. Organizations use it to organize and secure shared content. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

DocumentsOAuth 2.0MCP + RESTsharepoint.com
AUDIT LOG · SHAREPOINTPOLICY: acme-support
09:41:07 · claude · u_8f2read
sharepoint.list_sites
List SharePoint Sites✓ allowed · 212ms
09:41:08 · claude · u_8f2read
sharepoint.get_changes
Get SharePoint List Changes✓ allowed · 164ms
09:41:09 · claude · u_8f2write
sharepoint.create_web
Create SharePoint Subsite✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
sharepoint.delete_list
Delete SharePoint List✕ blocked · policy: deny
EVERY SHAREPOINT CALL, ON THE RECORD
01 · USE CASES

What agents do in SharePoint.

01

Create a sharing link for a file

Generate a sharing link for a document so a colleague or partner can access it directly.

02

Add an item to a list

Create a new list item, such as a task or record, inside a SharePoint list.

03

Confirm before deleting a file

Check a file or folder's contents and get approval before permanently deleting it from the library.

02 · ACTIONS

105 SharePoint actions, graded by risk.

Every SharePoint action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

57

Look things up. Allowed by default.

  • sharepoint.list_sites
    List SharePoint Sites
  • sharepoint.get_changes
    Get SharePoint List Changes
  • sharepoint.get_web_info
    Get SharePoint Web Info
  • sharepoint.search_files
    Search Files Across All Sites
  • sharepoint.search_query
    Search SharePoint Site
  • sharepoint.get_site_root
    Get SharePoint Root Site
  • sharepoint.get_list_items
    Get SharePoint List Items
  • sharepoint.get_site_by_id
    Get SharePoint Site by ID
  • sharepoint.list_all_lists
    List SharePoint Lists
  • sharepoint.search_suggest
    Search Suggest
  • sharepoint.get_all_folders
    Get All SharePoint Folders
  • sharepoint.get_drive_by_id
    Get Drive by ID
  • sharepoint.get_group_users
    Get Group Users
  • sharepoint.get_my_followed
    Get Followed Entities
  • sharepoint.list_site_users
    List Site Users
  • sharepoint.get_content_type
    Get Content Type
+ 41 MORE

write

39

Create and change things. Allow, or ask the user first.

  • sharepoint.create_web
    Create SharePoint Subsite
  • sharepoint.update_list
    Update SharePoint List
  • sharepoint.update_site
    Update SharePoint Site
  • sharepoint.update_file_item
    Update File Item Metadata
  • sharepoint.update_list_item
    Update SharePoint List Item
  • sharepoint.create_list_field
    Create SharePoint List Field
  • sharepoint.update_drive_item
    Update Drive Item
  • sharepoint.update_list_field
    Update SharePoint List Field
  • sharepoint.create_content_type
    Create Content Type
  • sharepoint.update_content_type
    Update SharePoint Content Type
  • sharepoint.create_list_item_by_id
    Create SharePoint List Item by GUID
  • sharepoint.create_list_item_in_folder
    Create List Item in Folder
  • sharepoint.add_attachment_to_list_item
    Add Attachment to List Item
  • sharepoint.add_role_assignment_to_item
    Add Role Assignment to List Item
  • sharepoint.add_role_assignment_to_list
    Add Role Assignment to SharePoint List
  • sharepoint.add_field_link_to_content_type
    Add Field Link to Content Type
+ 23 MORE

destructive

9

Delete, cancel or archive. Ask first, or deny outright.

  • sharepoint.delete_list
    Delete SharePoint List
  • sharepoint.delete_folder
    Delete SharePoint Folder
  • sharepoint.delete_file_item
    Delete SharePoint File
  • sharepoint.delete_list_item
    Delete SharePoint List Item
  • sharepoint.delete_list_items
    Delete Multiple SharePoint List Items
  • sharepoint.delete_list_by_title
    Delete SharePoint List By Title
  • sharepoint.delete_drive_item_version_content
    Delete Drive Item Version Content
  • sharepoint.delete_recycle_bin_item_permanent
    Delete Recycle Bin Item Permanently
  • sharepoint.sharepoint_remove_user
    Remove SharePoint User
03 · HOW IT WORKS

SharePoint in three steps.

  1. 01Your users connect SharePointThey sign in to SharePoint on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create SharePoint Subsite” can wait for the user, and “delete SharePoint List” can be denied outright.
  3. 03Any agent can actYour agent calls SharePoint through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('sharepoint', {
  read: 'allow',
  write: 'ask',        // create_web
  destructive: 'deny',  // delete_list
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How SharePoint connects.

Users sign in to SharePoint on Arc0 Connect and approve the scopes you request. Build with Arc0’s SharePoint OAuth app, or bring your own so the SharePoint consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same SharePoint connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0 · OAuth 2.0 client credentials
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use SharePoint from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

SharePoint and Arc0, answered.

Q01

Can I use SharePoint with Claude, ChatGPT or Cursor?

Yes. Connect SharePoint to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the SharePoint actions you allow.

Q02

How do users connect SharePoint?

Users sign in to SharePoint on Arc0 Connect and approve the scopes you request. Build with Arc0’s SharePoint OAuth app, or bring your own so the SharePoint consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which SharePoint actions can my agent take?

105 in total: 57 read, 39 write and 9 destructive, such as “create SharePoint Subsite”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in SharePoint?

Yes. Actions like “delete SharePoint List” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call SharePoint too?

Yes. The same SharePoint connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug SharePoint into your agent.

Your users connect SharePoint once, under your brand. Your agent gets 105 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan