For Microsoft 365 administrators

Morrow admin approval pack

Information for customer IT teams

Application identity

  • Application: Morrow by Amplifiable
  • Publisher: Amplifiable Pty Ltd, ACN 695 187 136
  • Microsoft application ID: 9ff4ec31-d95d-4aa1-9c9c-0e29e1158182
  • Account type: multitenant Microsoft Entra application
  • Access model: delegated access for the signed-in user, not application-wide mailbox access

Microsoft 365 connections

Morrow presents Microsoft services as separate connections:

  • Microsoft Outlook: A documented governed core of 5 Morrow capabilities. This is not the full provider catalogue. The exact delegated scopes are listed below.
  • Microsoft OneDrive: A documented governed core of 13 Morrow capabilities. This is not the full provider catalogue. The exact delegated scopes are listed below.
  • Microsoft SharePoint: A documented governed core of 13 Morrow capabilities. This is not the full provider catalogue. The exact delegated scopes are listed below.
  • Microsoft Teams: A documented governed core of 10 Morrow capabilities. This is not the full provider catalogue. The exact delegated scopes are listed below.
  • Microsoft Excel: A documented governed core of 11 Morrow capabilities. This is not the full provider catalogue. The exact delegated scopes are listed below.

Connecting one service does not connect the others. The exact delegated permissions for each connection are listed below. Amplifiable supplies a secure approval link covering only the connections being requested. Your organisation's Microsoft Entra consent policy controls who can approve it.

Exact delegated permissions

Every permission below is delegated. There are no Microsoft Graph application permissions in this request. The later connection is bounded by what the signed-in person's Microsoft 365 account can already reach.

  • Microsoft Outlook: offline_access, User.Read, Mail.Read, Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, Calendars.ReadWrite.Shared, Contacts.ReadWrite, MailboxSettings.ReadWrite
  • Microsoft OneDrive: offline_access, User.Read, Files.ReadWrite.All
  • Microsoft SharePoint: offline_access, User.Read, Sites.ReadWrite.All
  • Microsoft Teams: offline_access, User.Read, Team.ReadBasic.All, Channel.ReadBasic.All, ChannelMessage.Read.All, ChannelMessage.Send, Chat.ReadWrite
  • Microsoft Excel: offline_access, User.Read, Files.ReadWrite.All

Microsoft permissions can be technically broader than the smaller set of capabilities Morrow has released. A supported connector action is not proof that it can execute for a particular person. Effective access always passes four gates:

  • Morrow support: the capability must be released by Morrow for that connection.
  • IT consent: the request asks Microsoft for only the selected delegated scopes. Existing consent for the same application may remain.
  • Signed-in account: the person's own Microsoft 365 access remains the ceiling.
  • Review restrictions: the user can further restrict Morrow in the connection's Review pane.

Important permission boundaries:

  • Mail.ReadWrite technically permits creating, reading, updating and deleting mail in the signed-in user's mailbox. Sending is separate.
  • Calendars.ReadWrite.Shared includes calendars other people shared with the signed-in user, but not calendars that user cannot already open.
  • Contacts.ReadWrite technically permits creating, changing and deleting contacts available to the signed-in user.
  • MailboxSettings.ReadWrite can change mailbox behaviour such as automatic replies, working hours and time zone.
  • ChannelMessage.Read.All is marked as administrator-consent-required in the Morrow profile. Because it is delegated, it remains bounded by teams and channels the signed-in user can access.

How approval and connection work

  • Amplifiable confirms with the customer which Microsoft connections their Morrow needs.
  • Amplifiable sends the IT team this page and a secure approval link for the selected connections.
  • An authorised Microsoft 365 administrator reviews the selected delegated scopes in the customer's tenant.
  • After Microsoft returns the IT response, the user returns to Morrow and completes each selected connection with their own account.
  • The office-bound user connection, followed by safe checks for each selected connection family, proves operational reach.
  • The user can further restrict Morrow only in the connection's Review pane.

Token custody and isolation

Morrow uses Composio as its connection broker. Composio's current authentication documentation states that it stores and refreshes credentials against a stable per-user ID, manages the tokens, and does not pass credentials through the customer-facing application or the AI model. Amplifiable stores connection inventory, user consent and audit metadata, not raw Microsoft access or refresh tokens.

Security and data handling

Credential handling. Microsoft credentials do not pass through the Morrow interface or the AI model. Composio stores and refreshes the connected account credentials against the Morrow user's stable connection identity.

Encryption. Composio uses encryption for data in transit and at rest, access controls, security audits and monitoring.

Connection isolation. Connections are bound to a specific Morrow user and office. One user's connection is not used to run another user's Microsoft actions.

Retention and deletion. Personal and usage data is retained only as needed to provide the service or meet legal requirements. A user can disconnect the account in Morrow, and Microsoft administrators can revoke the application's consent in Entra.

Incident contact. Security questions or incident reports can be sent to privacy@amplifiable.com.au.

Administrator options

  • Review and approve the delegated permissions under your organisation's Entra consent policy.
  • Restrict assignment to the requesting user or an approved group where your tenant policy supports assignment.
  • Deny the request and ask Amplifiable for narrower capability requirements.
  • Revoke consent later in Microsoft Entra and ask Amplifiable to delete the brokered connection.

The Microsoft administrator approves the application's delegated access. The Morrow user manages what their Morrow may do with each connected service in one place: the connection's Review pane.