SharePoint Graph for AI agents
SharePoint Graph uses Microsoft Graph to reach SharePoint sites, document libraries, lists, and Excel workbooks stored there. Teams use it for deeper automation across files and structured data. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in SharePoint Graph.
Update a shared Excel table
Add a row to a workbook table stored in a document library, like a shared tracking sheet.
Create a new site page
Publish a new SharePoint site page with content for a team or announcement.
Confirm before deleting a drive item
Check a file's version history and get approval before deleting it from a document library.
162 SharePoint Graph actions, graded by risk.
Every SharePoint Graph action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
75Look things up. Allowed by default.
- sharepoint_graph.get_listGet SharePoint List
- sharepoint_graph.get_siteGet SharePoint Site
- sharepoint_graph.get_driveGet SharePoint Drive
- sharepoint_graph.get_sharesGet SharePoint Shared Item
- sharepoint_graph.list_listsList SharePoint Lists
- sharepoint_graph.list_sitesList SharePoint Sites
- sharepoint_graph.get_my_siteGet Signed-In User SharePoint My Site
- sharepoint_graph.search_queryRun Microsoft Graph Search Query
- sharepoint_graph.get_all_sitesGet All SharePoint Sites
- sharepoint_graph.get_list_itemGet SharePoint List Item
- sharepoint_graph.get_root_siteGet Root SharePoint Site
- sharepoint_graph.get_site_pageGet SharePoint Site Page
- sharepoint_graph.list_subsitesList SharePoint Subsites
- sharepoint_graph.get_drive_itemGet SharePoint Drive Item
- sharepoint_graph.get_list_columnGet SharePoint List Column
- sharepoint_graph.get_site_columnGet SharePoint Site Column
write
67Create and change things. Allow, or ask the user first.
- sharepoint_graph.create_listCreate SharePoint List
- sharepoint_graph.update_listUpdate SharePoint List
- sharepoint_graph.update_siteUpdate SharePoint Site
- sharepoint_graph.create_folderCreate SharePoint Folder
- sharepoint_graph.create_list_itemCreate SharePoint List Item
- sharepoint_graph.create_site_pageCreate SharePoint Site Page
- sharepoint_graph.update_list_itemUpdate SharePoint List Item
- sharepoint_graph.update_site_pageUpdate SharePoint Site Page
- sharepoint_graph.add_workbook_nameAdd SharePoint Workbook Named Item
- sharepoint_graph.update_drive_itemUpdate SharePoint Drive Item
- sharepoint_graph.add_workbook_chartAdd SharePoint Workbook Chart
- sharepoint_graph.add_workbook_tableAdd SharePoint Workbook Table
- sharepoint_graph.create_list_columnCreate SharePoint List Column
- sharepoint_graph.create_site_columnCreate SharePoint Site Column
- sharepoint_graph.update_list_columnUpdate SharePoint List Column
- sharepoint_graph.update_site_columnUpdate SharePoint Site Column
destructive
20Delete, cancel or archive. Ask first, or deny outright.
- sharepoint_graph.delete_listDelete SharePoint List
- sharepoint_graph.delete_list_itemDelete SharePoint List Item
- sharepoint_graph.delete_site_pageDelete SharePoint Site Page
- sharepoint_graph.delete_drive_itemDelete SharePoint Drive Item
- sharepoint_graph.delete_list_columnDelete SharePoint List Column
- sharepoint_graph.delete_site_columnDelete SharePoint Site Column
- sharepoint_graph.delete_subscriptionDelete Microsoft Graph Subscription
- sharepoint_graph.delete_workbook_tableDelete SharePoint Workbook Table
- sharepoint_graph.delete_site_permissionDelete SharePoint Site Permission
- sharepoint_graph.delete_share_permissionDelete SharePoint Share Permission
- sharepoint_graph.delete_list_content_typeDelete SharePoint List Content Type
- sharepoint_graph.delete_site_content_typeDelete SharePoint Site Content Type
- sharepoint_graph.delete_drive_item_versionDelete SharePoint Drive Item Version
- sharepoint_graph.delete_workbook_worksheetDelete SharePoint Workbook Worksheet
- sharepoint_graph.delete_drive_item_permissionDelete SharePoint Drive Item Permission
- sharepoint_graph.workbook_clear_rangeClear SharePoint Workbook Range
SharePoint Graph in three steps.
- 01Your users connect SharePoint GraphThey sign in to SharePoint Graph on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create SharePoint List” can wait for the user, and “delete SharePoint List” can be denied outright.
- 03Any agent can actYour agent calls SharePoint Graph through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('sharepoint_graph', { read: 'allow', write: 'ask', // create_list destructive: 'deny', // delete_list }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How SharePoint Graph connects.
Users sign in to SharePoint Graph on Arc0 Connect and approve the scopes you request. Build with Arc0’s SharePoint Graph OAuth app, or bring your own so the SharePoint Graph consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same SharePoint Graph connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0 · OAuth 2.0 client credentials
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use SharePoint Graph from any agent.
SharePoint Graph and Arc0, answered.
Can I use SharePoint Graph with Claude, ChatGPT or Cursor?
Yes. Connect SharePoint Graph to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the SharePoint Graph actions you allow.
How do users connect SharePoint Graph?
Users sign in to SharePoint Graph on Arc0 Connect and approve the scopes you request. Build with Arc0’s SharePoint Graph OAuth app, or bring your own so the SharePoint Graph consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which SharePoint Graph actions can my agent take?
162 in total: 75 read, 67 write and 20 destructive, such as “create SharePoint List”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in SharePoint Graph?
Yes. Actions like “delete SharePoint List” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call SharePoint Graph too?
Yes. The same SharePoint Graph connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug SharePoint Graph into your agent.
Your users connect SharePoint Graph once, under your brand. Your agent gets 162 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan