Follow one email.
The fastest way to review a mail tool is to trace a single message. Here is an owner’s email about a leak, from the moment it arrives to the moment your manager’s reply goes out.
Fictional example. The people and building are made up.
- 1
Priya emails your firm
It lands in your Microsoft 365 mailbox, the same as always.
- 2
Strata Inbox reads it
Mail.ReadOnly from the mailbox you connected, using the permission you granted.
- 3
It's filed under your firm
Firm-scopedRecords are tied to your firm, and access is checked in application code.
- 4
A draft is written
Being verifiedAn AI provider helps draft the reply from the building's documents. Provider data-use and retention terms are being verified.
- 5
Sarah checks and approves it
Human approvalOwner-facing replies need a person's approval. Nothing goes to Priya before then.
- 6
It's sent from your address
Mail.SendIn the same conversation. The send is recorded in the activity record.
Four permissions, in plain words.
This is what Strata Inbox asks Microsoft for, and why. Check the actual Microsoft consent screen for the complete request. Administrator approval and supported mailbox access depend on your tenant configuration.
Permissions Strata Inbox asks for
- Your name and email
User.Read - To sign you in.
- Read mail
Mail.Read - To read incoming email in the mailbox you connect, so it can be sorted and answered.
- Send mail
Mail.Send - To send the replies you approve, from your own address.
- Stay connected
offline_access - To keep access between sign-ins, subject to Microsoft policies and revocation.
What’s settled, and what isn’t yet.
Strata Inbox has not launched yet. Here is where each part of a security review stands today.
Approval for owner replies
In placeOwner-facing replies require human approval. Scheduled summaries are separate service emails. Confirm their recipients and schedule during setup.
Microsoft sign-in
In placeStaff sign in with their Microsoft work account rather than giving Strata Inbox a password. Mailbox access still depends on permissions and connection tokens.
Firm separation
In application codeRecords are associated with a firm and access is checked in application code. These controls need ongoing review and do not eliminate security risk.
Activity record
RecordedActivity such as reads and sends is recorded. Confirm event coverage, retention and customer access or export options during your review.
Where data is processed
Being verifiedConfirm providers and processing locations for the database, documents and AI. Check application processing, logs, backups and support access separately.
AI provider data use
Being verifiedFirm guidance is separate from model training. Review provider data-use and retention terms before connecting a production mailbox.
Disconnection and deletion
Being verifiedDisconnecting a mailbox and deleting stored data are different actions. Confirm deletion scope and retention for active records, backups and provider logs.
This page does not guarantee Australian-only processing or zero provider retention.
Read the prelaunch privacy summary