Access levels
Each SharePoint account has an access level: Read-only, Read + write, and Full access. Squad refuses any agent action outside that level. You can also narrow or block single agents under Per-agent access.
Read + write is the recommended level. The connect window selects it for you, and you can choose another level.
The SharePoint sign-in page asks you to approve full access to your account. This is expected. Squad does not narrow the sign-in. It checks every agent action against the level you chose, and it refuses actions outside that level.
What agents can do at each level
Each level opens with a short summary in plain tasks, then lists every action it adds, grouped by what the action works on. You do not need to name actions. Ask in plain words, and the agent searches for the matching action. Each action shows its name, a one-line description where the SharePoint action catalog has one, and its slug. The slug is the ID that agents use when they call the action.Read-only
Read-only
Agents can use 27 of the 105 SharePoint actions at this level:
- View list items
- View content
- View files
- View and run lists
- View users
- View attachments
- View drives
- View folders
- View followers
- View groups
- Search queries
- View roles and permissions
Read + write (recommended)
Read + write (recommended)
Agents can use 96 of the 105 SharePoint actions at this level: everything in Read-only, plus:
- Create and update list items
- View, create, and update types
- Search, create, update, and manage files
- Search, create, and manage users
- View change history
- Create and update fields
- Create and update folders
- Create and update lists
- View subscriptions
- View and update versions
- View collections
- View columns
Attachments (1)
Attachments (1)
Change history (2)
Change history (2)
Collections (1)
Collections (1)
Columns (1)
Columns (1)
Drives (1)
Drives (1)
Events (1)
Events (1)
Fields (2)
Fields (2)
Files (7)
Files (7)
Folders (3)
Folders (3)
Links (2)
Links (2)
List items (12)
List items (12)
Lists (4)
Lists (4)
Reports (1)
Reports (1)
Roles and permissions (6)
Roles and permissions (6)
Sites (4)
Sites (4)
Subscriptions (2)
Subscriptions (2)
Types (6)
Types (6)
Users (5)
Users (5)
Versions (2)
Versions (2)
Other actions (6)
Other actions (6)
Full access
Full access
Agents can use 105 of the 105 SharePoint actions at this level: everything in Read + write, plus:
- Delete list items
- Delete lists
- Delete content
- Delete folders
- Delete users
Connect SharePoint
Before you start:- You need a SharePoint account that you can sign in to.
- Your Squad subscription must be active. Squad does not connect apps while the subscription is not active.
1
Open Integrations
Open Settings > Integrations.
2
Add an integration
On the Connected apps tab, click + Add integration.
3
Find SharePoint
Find SharePoint in the catalog and click it. You can type the name in Search the catalog….
4
Choose an access level
Under Default scope, choose an access level. This level applies to every agent.
5
Click Connect SharePoint
Click Connect SharePoint. The SharePoint sign-in page opens in a new tab.
6
Sign in to SharePoint
Sign in to SharePoint and approve the request.
Change the access level
- Under YOUR CONNECTIONS, find the SharePoint account.
- Open the account menu (⋯) and click Manage scope.
- Under Default scope, choose the new level.
- Click Save access.
Set access for one agent
Every agent uses the account’s level unless you set something else for it. You can narrow one agent to a lower level, or block it.- Under YOUR CONNECTIONS, open the account menu (⋯) on the SharePoint account.
- Click Manage scope.
- Under Per-agent access, find the agent.
- Choose the Default option to follow the account’s level, choose a lower level, or choose No access.
- Click Save access.
Use more than one SharePoint account
Click + Account on the SharePoint card to connect another account. Agents use the primary account unless they are asked to use a specific one.- After you click + Account, follow the connect steps above.
- Each account has its own access level.
- The first account you connect becomes the primary account. It shows ★ PRIMARY.
- To change the primary account, open the account menu (⋯) and click Make primary.
- To tell accounts apart, open the account menu (⋯) and click Rename.
Reconnect or disconnect
Reconnect when the connection has expired, or when you need to change what the account can reach on the SharePoint side:- Open the account menu (⋯) and click Reconnect.
- Click Reauthorize on SharePoint.
- Sign in to SharePoint and approve the request.
Costs
SharePoint actions do not use Squad credits. Connected apps never use credits. For what does use credits, see What Squad costs.Troubleshooting
An agent reports that an action is not allowed on this account.- Cause: the action is outside the account’s access level, or outside the level you set for that agent.
- Fix: choose a higher level in Manage scope, or change the agent’s row under Per-agent access.
- Cause: the agent is set to No access under Per-agent access, or the account is not connected.
- Fix: open Manage scope and change the agent’s row. If the account is missing, connect it again.
- Cause: your Squad subscription is not active.
- Fix: resubscribe. See Manage your subscription.
- Cause: the sign-in for that account is no longer valid.
- Fix: use Reconnect on the account.
Common questions
Related pages
Connect apps
Add an MCP server or an API key
Use this when an action you need is not in this app.