TeamConnect AI · AI agent & governance

The AI agent for Microsoft Teams that knows your organization.

Evidence behind every match, and only the answers each person may receive.
30-minute working sessionBought through Microsoft Marketplace or the Microsoft Teams StoreAll you need to go live: a Microsoft billing account and two global admin consents per app
TeamConnect AI · Agent in Microsoft Teams
Sample — names fictional.

What people ask

Ask the AI agent a work question. Get an answer you can act on.

Find the right colleague, coordinate your team, and see what expires next, all in everyday language. Because each answer draws on your organization’s own records, nobody has to look it up for you.

Find the right person

Ask for a skill, work and project experience, and a language, then see who is reachable right now.

Run the day

See who on your team is working today and from where, then get meeting times that suit every time zone you span.

See your organization as it is

Ask how a department spreads across job functions and cost centers, and also see the functional lines beside the direct ones.

Stay ahead of expiry

Know which contracts and certifications expire soon in the countries and offices you manage, while there is still time to act.

Evidence behind the shortlist — see the recorded skills, their validation status, and the experience behind each match. The agent reports only what your directory holds, and it says so when a record is empty.
TeamConnect AI · Agent answer in Microsoft Teams
TeamConnect AI agent answering in Microsoft Teams: a request for Singapore colleagues with Six Sigma Black Belt and Lean Management, five years in claims management and English. Two matches are returned under a stated scope of region APAC, each with years of recorded experience, office, language, and both qualifying skills shown as HR-validated
Sample — names fictional.

Governed answers

Same AI agent. Same access. Different permitted answers.

The risk is not only what AI can reach, but also what it can return. Agent Roles leave your data and your permissions unchanged; instead, they decide what the agent may say back, and to whom.

An HR Admin asks

“Contracts expiring in my country.” The answer then lists the employment contracts with a recorded end date in that window, across the country’s offices, with contract type and holder.

A line manager asks the same

The answer then covers the manager’s own team, because a manager needs to know in time when the contracts of the people they lead end.

An employee asks the same

The employee, however, gets a card naming the capability and the reason the agent cannot serve it. It is not an error, not a blank reply, and not a quietly narrowed version of the answer.

Only what the AI agent may say differs

All three sign in to the same Microsoft 365 with the same underlying access. The difference is what the agent may say to each of them, which is exactly what a refusal has to get right.

TeamConnect AI · Capability access in Microsoft Teams
Capability access settings in TeamConnect AI: one prompt with its sensitivity set to Highly Confidential, three Agent Roles assigned, and a Microsoft 365 security group picker beside them, with a note that access can be granted through an Agent Role or a selected security group
Sample — names fictional.

Confidence in the result

Answers you can check. Access decisions you can review.

Where the answer supports it, each match shows the records behind it, so you can see why the agent named a colleague. Security, in turn, reviews the recorded access decisions in one place — for one agent, not one per department.

You ask in
  • Everyday language
no syntax to learn, no field names to remember
  1. 01

    Your question

    Describe the work you need done, in the words you would use with a colleague.

  2. 02

    Relevant records

    Where the answer supports it, see the matching skills, their validation status, and the recorded experience.

  3. 03

    Permissions applied

    The agent then checks the request against your configured access and the scope you are responsible for.

  4. 04

    A decision to review

    Allowed or denied, with the reason and the context kept alongside it.

Then recorded in
  • Audit Trail
recorded access decisions — not a transcript of the conversation
TeamConnect AI · Audit Trail in Microsoft Teams
Audit Trail in TeamConnect AI showing recorded access decisions: allowed and denied counts, each row with its outcome, sensitivity and permitted scope, and a detail panel for a denied request giving the requester, the assigned role and the reason the clearance was too low
Sample — names fictional.

Governance

AI agent governance: you choose who each capability answers to.

Govern each capability by Agent Roles, by Microsoft 365 security groups, or by both together, and decide per capability. When you grant access through a group, its membership stays where you manage it today, in Microsoft Entra ID.

Two ways to govern the AI agent

Agent Roles describe responsibilities and ship with the product, while Microsoft 365 security groups are the ones you already govern in Microsoft Entra ID. A capability can use either, or require both, so access follows the model you already run.

50+ roles, plus your own

More than fifty predefined roles cover common business responsibilities, from Employee and Line Manager to CHRO, CIO, CFO, CISO, Procurement, Compliance, and Privacy. Each role decides what the agent returns to the people who hold it, and you can also add roles of your own.

Set per capability

Each capability carries its own access model, its own role or group list, and its own sensitivity ceiling — General, Restricted, Confidential, or Highly Confidential. As a result, control sits with each capability, not with one switch per person.

Exportable for review

Export the catalog’s governance fields, so a compliance reviewer can check how you configured access without needing access to the product.

TeamConnect AI · Agent Catalog in Microsoft Teams
Agent Catalog in TeamConnect AI: prompt totals and counts by security tier, with each capability listed alongside its sensitivity and the Agent Roles or Microsoft 365 groups permitted to reach it
Sample — names fictional.

Reach

One AI agent for questions across your whole organization.

Ask about the teams, countries, and offices you are responsible for, and get the answer instead of waiting for a report. Four things decide how far the agent reaches, and the capabilities behind it grow every week.

Across your people data

Ask about profiles, skills, certifications, work and project experience, reporting lines, contracts, cost centers, offices, working hours, availability, licenses, devices, and application ownership.

The questions leaders ask

Find, count, compare, and roll up, then spot what is missing, see what expires, and check what happened.

Seven ways to slice the answer

By business unit, cost center, country, department, division, office, or region, so the same question fits the way you manage.

An answer for each role

From Employee and Line Manager to CHRO, CIO, CFO, CISO, Procurement, Compliance, Privacy, and Facilities, plus the roles you define, each with the answers it may receive.

Also in the AI agent — scheduled updates that reach people without anyone typing, with each recipient’s access checked before delivery · prompt statistics by security tier · an export of the governance fields for review · and a catalog that holds prompt types for Cubeet agents, Microsoft 365 Copilot, and other agents.

Buyer questions

What security and HR ask about the AI agent.

The questions that decide whether you let an AI agent near your people data.

Access and Agent Roles

Can we define our own Agent Roles?

Yes. More than fifty predefined Agent Roles cover common business responsibilities, and you can add roles for your organization. Assign a custom role to people and choose which capabilities it can reach; you set its clearance and scope, rather than inheriting them from a predefined role.

How do Agent Roles relate to Microsoft 365 security groups?

A capability can accept Agent Roles, Microsoft 365 security groups, or both, and its own security and scope requirements still apply. Agent Roles describe common business responsibilities, while security groups are the ones you already manage.

So when you grant access through a group, you keep managing that membership in Microsoft Entra ID, just as you do today.

What happens when someone asks something their role does not permit?

The agent declines the request and explains why. Rephrasing the question does not change that, because the decision rests on what the person may receive, not on how they ask. Administrators can then review the recorded decisions, including denials, in Audit Trail.

Scheduled updates and the audit trail

Can the agent answer before anyone asks?

Yes. Supported updates run on a schedule instead of waiting for someone to type, for example skill-validation reminders and campaign reminders. The agent checks each recipient’s access before delivery and records the decision in Audit Trail.

What can administrators review in the audit trail?

The recorded access decisions: who asked, which capability matched, when, with what scope, and whether the agent allowed or denied the request. For a scheduled update, the recipient is the person on record.

The trail deliberately leaves out the questions and answers themselves. That way, reviewers can examine access decisions without the audit becoming a copy of protected answers.

Licenses, your data, and where the AI agent runs

Does everyone in our organization need the AI agent?

No. TeamConnect and TeamConnect AI are compatible, so you can license TeamConnect AI, which includes the agent, for management, sales, and roles that work across departments, and TeamConnect for everyone else. Because TeamConnect AI includes the TeamConnect foundation, nobody needs both.

Will our prompts and answers train AI models?

No. The foundation models behind the agent run in Microsoft Azure and do not train on your prompts and responses without your permission or instruction, in line with Microsoft’s published policy.

TeamConnect AI reaches your Microsoft 365 directory only through the permissions your organization approved, and it applies the access controls you configured.

Where can we use the agent?

Microsoft Teams gives the full card experience, including evidence and actions where the answer supports them. You can also reach the agent from Microsoft Outlook and Microsoft 365 Copilot, where the response adapts to what each host can render.

Ask it something only your directory knows

See the AI agent for Microsoft Teams answer your own questions.

Bring them to a thirty-minute demo, and the refusals will tell you as much as the answers do. Weighing the cost? See the business case first.