
Connecting AI workflows to Outlook and SharePoint through Microsoft Graph
Pipeline steps that read and write email, attachments and documents in Microsoft 365, acting with each user's own delegated access.
- Partner
- A multinational advisory firm
- Period
- October 2024 to January 2026
- Microsoft 365 steps
- 4
- Email reader and writer, SharePoint reader and writer
- Upload chunks
- 4 MB
- For large attachments through upload sessions
- Access
- Per user
- Delegated tokens from linked accounts
The challenge
Much of the partner's working data lived in mailboxes and SharePoint sites. Pipelines that could not reach those systems left people copying files and emails in by hand.
What we built
Account linking that lets each user connect a Microsoft account with chosen permissions, and four pipeline steps that use Microsoft Graph to read and send email and to read and upload documents in SharePoint or OneDrive.
What was delivered
- Email and SharePoint available as sources and destinations in any pipeline
- Large attachments sent through chunked upload sessions
- Linked accounts scoped to a workspace, project or asset, with refresh and removal
Partner background
Our partner is a multinational advisory firm whose teams work with large volumes of documents, spreadsheets, databases and email. It wanted one internal platform where those teams could build data pipelines and AI agents themselves, instead of commissioning a new application for each need. The platform had to run inside the partner's Microsoft 365 and Azure environment, keep each team's work separate, and move work from experiment to production through controlled environments.
The challenge
Data sits in Microsoft 365
Reports, requests and source files arrived by email or were stored in SharePoint. Automation that stopped at the edge of those systems still required manual work.
Acting as the user
Sending email or writing to a site must happen with the right person's permissions, not a broad shared credential.
Attachments are large
Simple API calls limit attachment size. Real reports and exports exceed those limits and need a different upload method.
Objectives
- Read email, attachments and documents into pipelines
- Send email and upload files as pipeline outputs
- Act with each user's delegated permissions
- Handle attachments of realistic size
- Make failures clear when access expires or is removed
Our role
CharCentric provided technical leadership and architecture within a multidisciplinary engineering team, and contributed directly to implementation. The platform was built over 16 months, from October 2024 to January 2026, as a Python and FastAPI backend on Azure.
Scope and timeline
Account linking was built in October and November 2025. The Outlook and SharePoint steps were built between October 2025 and January 2026.

Approach
Link once, use everywhere
Users link a Microsoft account through OAuth with chosen scopes. The linked account is attached to a workspace, project or asset, so pipelines in that scope can use it without handling credentials directly.
Microsoft Graph as the single interface
All four steps call Microsoft Graph v1.0. One API covers Outlook, SharePoint and OneDrive, which keeps authentication and error handling consistent.
Follow the platform's limits
Attachments use Graph upload sessions in 4 MB ranges, the size Microsoft recommends, instead of single requests that fail on large files.
Implementation

Account management
Endpoints initiate and complete the OAuth flow, list linked accounts, refresh tokens and remove access. Each step checks that a usable token exists before it starts and asks the user to relink the account if it does not.
Email reader
Retrieves messages with sender, recipients, received time and attachments, and returns them as structured data for downstream steps.
Email writer
Creates a draft with recipients, CC, BCC and body, opens an upload session for each attachment, uploads it in 4 MB ranges with progress logging, then sends the draft.
SharePoint steps
Resolve a site from its host and name, then read documents or upload files to SharePoint or the user's OneDrive.

Tools and technologies
| Tool | Purpose |
|---|---|
| Microsoft Graph v1.0 | Outlook, SharePoint and OneDrive access |
| Microsoft Entra ID | OAuth and delegated permissions |
| aiohttp | Asynchronous API calls |
| FastAPI | Account management endpoints |
| PostgreSQL | Linked account records |
What was delivered
- Pipeline steps
- 4
- Account endpoints
- 6
- Upload chunk size
- 4 MB
- Scope levels
- 3
- Two Outlook steps and two SharePoint steps in the pipeline library
- Per-user delegated access through linked Microsoft accounts
- Chunked uploads for large attachments, with progress logged
- Clear errors when access is missing or expired
Why it matters
Automation earns its keep when it reaches the systems people already use. Integrating with Microsoft 365 under each user's own permissions extends pipelines into everyday work without weakening access control.
If your organization is planning a platform of this kind, or needs a specific part of one designed and delivered, we would be glad to discuss it.