Skip to main content
Neo Agent reads documentation from your SharePoint document libraries so agents can search and use it during ticket resolution. You choose which libraries Neo may read, leave out any folders inside them that Neo should not index, and then map top-level folders to the companies they belong to — so a search for one client only surfaces that client’s documents.
No API key. SharePoint runs on a dedicated Microsoft 365 app — a Microsoft 365 admin consents it once, and you pick which libraries Neo may read. It writes nowhere by default. Nothing else about your Microsoft setup has to change.

How Neo reads SharePoint

Neo reads SharePoint through the Neo SharePoint Connector application, which a Microsoft 365 admin consents on your own tenant. It holds exactly three permissions — two that read, and one that grants nothing until you use it. This is what the consent screen shows you: By default Neo never writes to, moves, or deletes anything in SharePoint. Consenting the app leaves it read-only: Sites.Selected on its own reaches no site. Write access is a separate, per-site opt-in — and deleting is never possible, even on write-granted sites. The app’s permissions are what Microsoft could allow; Read access is what Neo actually uses. The two are not the same, and the difference is worth knowing: Sites.Read.All covers your whole tenant, while Neo confines itself to the libraries you list. Neo’s own code enforces that, not Microsoft — so unlike the write grants, it is a promise we keep rather than a wall your tenant puts up.
This is its own app, on purpose. SharePoint search doesn’t ride the broader Neo Azure Automations app that powers Microsoft 365 administration. The two consents are independent in both directions, so you can have SharePoint search without granting Neo any Microsoft 365 admin access at all.
Who can grant consent. Every tenant starts here — Microsoft permissions only exist where an admin has granted them, so a missing grant is the normal first step, not a misconfiguration. Microsoft accepts consent only from a Global Administrator, Privileged Role Administrator, or Cloud Application Administrator; any other account is sent back to Neo without a grant, and Neo shows Microsoft’s own reason (the AADSTS… code). If your tenant uses the admin consent request workflow, the click files a request and access starts once an approver grants it.

Connect SharePoint

1

Open the SharePoint tile

In the Neo Dashboard, open Integrations and click the SharePoint tile in the Documentation section.
2

Verify access

Click Verify access. Neo checks whether the Neo SharePoint Connector app can read SharePoint on your tenant.
  • Not consented yet (the usual first time) → an amber Admin consent needed notice with a Grant admin consent button. An admin opens it and approves the two read permissions; Microsoft returns to Neo, which rechecks the grant itself and opens the library picker. I’ve granted consent — recheck re-runs that check by hand if you need it.
  • Consent refused → a red notice with Microsoft’s reason. Almost always the signed-in account isn’t one of the three roles above; retry as an admin who is.
  • Already consented → you go straight to the library picker.
  • Microsoft didn’t answer → a message saying so, with a retry. Microsoft occasionally can’t complete the check on a tenant, and that says nothing about your consent — Neo reports it as unknown rather than asking you to grant consent again. Try again in a few minutes.
3

Choose your document libraries

Neo lists your SharePoint sites. Expand a site to see its document libraries, and tick the ones you want Neo to sync. You can select libraries across multiple sites.A ticked library syncs whole. To leave part of it out, open the library with the chevron next to its name and untick the folders Neo should not read — former customers, archives, raw exports. A folder inside an unticked folder is left out with it. The library’s checkbox turns into a dash while any of its folders are left out, and the row counts them.
Sync the libraries that hold client-facing documentation — runbooks, procedures, network diagrams. You’ll map their folders to companies in the next step.
4

Connect

Click Connect N libraries. Neo saves your selection and starts the first sync. Larger libraries take a little longer on the first run; subsequent syncs only pull in what changed. A very large library — hundreds of thousands of files — can take more than one nightly run to finish. Each run picks up where the last one stopped, and the documents it has already read are searchable straight away, so the library fills in rather than appearing all at once.
The tile flips to a Connected view: a connection card with the sync status, Trigger sync and Disconnect, then Read access and Write access side by side — each listing exactly what it covers — followed by Company mappings and Global folders.
5

Answer the global-folders question

Neo opens the Global folders picker straight after the first connect, and you have to answer it — either tick the folders that apply to every client and click Save global folders, or click Skip — nothing is global.Each library is listed as Site / Library, so libraries that share the default name “Documents” are still told apart by their site.Skip it if every library you connected belongs to one client. You can change the answer any time from Manage next to Global folders.

Map folders to companies

SharePoint has no built-in notion of which company a folder belongs to, so Neo asks you once. After the first sync, Neo scans the top folders in your libraries (2–3 levels deep), matches each to a company by name, and presents the matches for you to confirm — so you approve a list instead of mapping every folder by hand.
1

Open the review queue

On the connected SharePoint page, click Review next to Company mappings (or open it from a company’s linked-systems column on the Companies page). The row shows how many folders are still unmapped, so you can see at a glance whether anything needs review.
2

Review Neo's matches

Your folders are listed as a tree, grouped by library and nested the way they sit in SharePoint. Use the chevron next to a library or a folder to open or close a branch.A folder Neo matched to a company starts closed, because mapping it already covers everything inside it — a subfolder inherits the nearest mapped folder above it. Folders Neo found no match for stay open, since those are the ones still needing a decision. Open any closed branch to map a subfolder to a different company; the deeper mapping wins.Every folder Neo matched to a company is ticked for you, and its row shows how confident the match is:Untick anything you don’t want, retarget a folder to a different company with the picker, and click the to dismiss a folder that isn’t client documentation (dismissed folders won’t be suggested again).Folders Neo found no match for sit in the same tree with an empty picker — pick a company to map one by hand, or dismiss it. Picking a company ticks the row for you.To work in bulk, use All and None at the top. They apply to what is on screen, so search first to narrow the list, then tick the result in one click. The checkbox next to a library name does the same for that library.
The deterministic name matches appear straight away. Neo keeps working on the folders that didn’t match by name, and any AI guess it finds fills in on its own a few seconds later — you can start reviewing before it finishes.
3

Confirm

Click Map N folders. Neo saves the mappings and scopes each folder’s documents — and everything beneath it — to that company. Nothing is applied until you confirm, and only the rows you kept are mapped.
Unmapped folders stay private. A folder you don’t map (or dismiss) still syncs, but its documents are not shared across companies — they surface only where their own company mapping applies. A subfolder always inherits the nearest mapped folder above it, so you only map at the level that matters. To make a folder’s documents available to every company, designate it global (below) — global is an explicit choice, never inferred from a folder being unmapped.
If a mapping saves but Neo can’t immediately re-scope the already-synced documents (a transient hiccup), the review queue tells you which folders are affected and offers Retry re-scoping. The mappings themselves are always saved.

Mark global folders

Some documentation applies to every client — shared runbooks, internal knowledge bases, vendor guides. Mark those folders global so their documents surface in every company’s searches, regardless of folder-to-company mapping.
1

Open the picker

On the connected SharePoint page, click Manage next to Global folders. The row shows how many folders are currently designated global, or None.
2

Choose folders

Browse the library tree and tick any folder — or a whole library — whose documents should be global. Libraries are listed as Site / Library. A company-mapped subfolder inside a global folder keeps its own company, so you can share a parent broadly while still scoping specific children.
3

Save

Click Save global folders. Neo re-stamps the already-synced documents immediately, so the change takes effect without waiting for the next sync.
Global is explicit. Only folders you designate here are shared across companies. This is a deliberate safeguard — a folder is never treated as global just because Neo couldn’t match it to a company.

What gets synced

Once synced, your SharePoint documents are searchable alongside IT Glue, Hudu, Confluence, and any other documentation sources you’ve connected — scoped to the company you mapped their folder to.

See how much you are syncing

The Sync size row on the connected card shows two figures: Expect the two to differ by a lot. Most of a document library is file types Neo does not index — images, video, archives, installers — so a 400 GB library can produce well under 30,000 files. The passage count is the one that tracks how much Neo carries: a spreadsheet or CSV export splits into thousands of passages, so a few hundred data exports can outweigh every real document in the library. The picker shows the same figures per library and per folder. Open a library and each folder lists its size in SharePoint and how many passages Neo currently holds for it. Use the two together to find a folder that is small on disk and large in the index — a folder of audit-log or report exports is the usual answer — and untick it.
A blank figure means Neo could not read it this time, which is different from zero. Reload the page to ask again.

Sync on demand

Syncs run automatically on a schedule. To pull in changes right away, click Trigger sync on the connected card — the status badge next to it shows whether the last sync succeeded, is still running, or failed, and the details table below it breaks down what each sync step did.

Read access — change which libraries and folders Neo reads

On the Read access row, click Manage to open the picker with your current selection pre-ticked. Adjust the set and click Save libraries. The library list is the read boundary, not just a sync setting. A library you remove stops syncing and stops being readable — agents can no longer open its files, folders, lists or pages, and its documents drop out of search results. A library you add is picked up on the next sync. Agents can still list your sites and libraries by name anywhere in the tenant, which is how they find one to ask you about; only the content is confined.

Leave folders out of a library

You can keep a library and still leave part of it out of the index.
1

Open the library

In the picker, click the chevron next to a ticked library. Its folders load one level at a time; open a folder to see the folders inside it. The filter box at the top narrows the libraries and the folders you have already opened.
2

Untick the folders to leave out

Untick a folder and its name is struck through. Everything inside it is left out too — those folders show unticked and cannot be ticked on their own. The library’s checkbox turns into a dash and the row shows how many folders are left out. The footer lists what the save will change.
3

Save

Click Save libraries. The save completes at once; Neo then removes the documents it already indexed from the folders you left out in the background — a large folder can take some minutes to drain from search results. From the next sync on, Neo does not read those folders. Tick a folder again and save to bring it back: Neo re-reads that library on the next sync, and only the restored folder’s files are downloaded.
A click on a library’s dash ticks the whole library again, bringing every left-out folder back in one step.
Leaving a folder out affects what Neo indexes for search. Agents with the SharePoint API tool can still open files anywhere in a library you read; the tool follows the library list, not the folder list.

Write access (optional)

Agents with the SharePoint API tool can also create and update files and list items — but only on sites you name. Write access is off until you complete both steps below, and each step is visible in your own Microsoft admin surfaces. The Write access row on the SharePoint card tells you where you are without opening it:
1

Enable write consent

On the SharePoint card, open Write access and click Enable write access. A Microsoft 365 admin re-consents the Neo SharePoint Connector, which now also carries Sites.Selected. This consent grants access to zero sites — it only unlocks the next step.
2

Choose the sites

Pick the sites Neo may write to, then sign in when Microsoft asks. This sign-in is a one-time step that creates the per-site grants inside your own SharePoint; it asks for full site control for that sign-in only — Neo requests no refresh token and keeps nothing after the grants are written. Leave Consent on behalf of your organization unchecked, so the sign-in permission stays personal to the approving admin.
Microsoft enforces the boundary, not just Neo. The per-site grants live in your SharePoint (Sites.Selected), so a write to any site you did not grant is refused by Microsoft itself — independent of Neo’s own permission checks. The agent-side controls (per-group Read/Write levels and technician approval) sit on top of that.
The sign-in permission from step 2 can be removed afterwards in Microsoft Entra → Enterprise applications → Neo SharePoint Connector → Permissions; the per-site write grants stay in place. Removing a site: in the Write access list, remove the site — Neo stops writing to it immediately. The grant record inside SharePoint stays; to remove that too, an admin runs Revoke-PnPAzureADAppSitePermission (PnP PowerShell) or removes it from the site’s permissions.

Disconnect

On the connected card, click Disconnect and confirm. Neo stops syncing SharePoint and its synced documents stop updating. Your SharePoint content and the admin-consent grant on your tenant are not affected — reconnecting later picks up where you left off.

Security

  • The Neo SharePoint Connector app declares exactly Sites.Read.All, Files.Read.All, and Sites.Selected — read access plus the capacity for per-site write grants. Consenting it grants read access and nothing more: writes require the explicit per-site grants described under Write access, which only your own admin can create.
  • Deletion is impossible through Neo on every site, including write-granted ones.
  • Access runs on your own tenant; there are no separate credentials to manage, and you can revoke it at any time from Enterprise applications in the Microsoft Entra admin center.
  • Folder→company mappings are only ever the ones you explicitly confirm — Neo never auto-applies a mapping.
  • All traffic is over HTTPS, and synced content is isolated per tenant.