Private & Secure AI
Can private AI work with Microsoft 365, SharePoint and Outlook?
The short answer
Yes. A private AI system can index approved SharePoint libraries, OneDrive locations, Teams content and selected Outlook shared mailboxes, then answer in plain English with source citations. It should use Microsoft identity and existing permissions so users cannot retrieve documents they could not already open. Personal mailboxes, stale documents and conflicting versions need explicit governance rather than indiscriminate indexing.
Indicative price ranges
SharePoint pilot
£6,000–£12,000
One library, small user group, citations and answer-quality testing.
Microsoft 365 knowledge system
£12,000–£30,000
Several libraries, selected shared mailboxes, identity, permissions, logs and rollout.
Complex enterprise scope
£30,000–£60,000+
Several tenants or departments, legacy sources, advanced assurance and workflow actions.
These are indicative UK ranges based on projects we have actually delivered. Scope drives the number, not the sales conversation — we quote a fixed price after a scoping session, and we will tell you if an off-the-shelf tool is the cheaper answer.
Typical timescales
- 1–2 weeks
Content and permission audit
Choose authoritative locations and exclude unsuitable content.
- 2–4 weeks
Pilot indexing
Connect, retrieve, cite and test refusals.
- 2–6 weeks
Rollout
Expand sources and users with ownership and monitoring.
Who this suits
- Microsoft 365 teams with repeated policy, project or client-information questions.
- Organisations that already manage document permissions sensibly.
- Shared mailboxes with a clear business purpose and owner.
Who it does not suit
- Indexing every employee mailbox by default.
- SharePoint estates full of duplicate and obsolete documents.
- Use cases requiring the AI to make unreviewed high-impact decisions.
What actually drives the cost
Permission inheritance
Complex SharePoint structures need careful testing.
Mailbox scope
Shared operational mailboxes are easier to govern than personal inboxes.
Content freshness
Owners and review dates prevent old policy becoming a confident answer.
Citations and refusals
Useful systems show their basis and decline unsupported questions.
What a responsible Microsoft 365 connection looks like
The system signs users in through Microsoft identity, retrieves from approved sources using their access, and returns an answer with links or citations. It does not need to copy every document into an unrestricted database, and it should not flatten permissions during indexing.
Outlook needs particular care. A selected shared mailbox used for tenders or support may have a clear business purpose; personal mailboxes contain far more unrelated and sensitive material. Scope them differently.
Our fuller SharePoint and Outlook knowledge-system guide covers content ownership and adoption. Compare deployment options before choosing where retrieval and model processing run.
Common questions
Does it replace Microsoft 365 Copilot?
Not necessarily. Copilot is strong inside Microsoft apps; a bespoke layer can provide more control over authoritative sources, retrieval, refusals, presentation and logs.
Can it read personal inboxes?
Technically possible, but it should not be the default. Purpose, lawful basis, permissions and employee expectations need review first.
Will it respect SharePoint permissions?
It should. Permission-aware retrieval is a core acceptance test, not an optional enhancement.