What Gets Synced
ClosedLoop AI has read-only access. It never creates, changes, or deletes an event, and it does not read email.
Private events (events marked private or confidential in Outlook) are stored as busy time only: the start and end time, without the title, organizer, attendees, or join link.
History: ClosedLoop AI imports each calendar’s full history, then keeps it up to date. Large organizations can take a while to import; the integration shows that the history import is still running.
What a Microsoft 365 Administrator Approves
One approval covers your whole organization. Users do not connect one by one. Only a Global Administrator or Privileged Role Administrator of your Microsoft 365 organization can connect Microsoft Calendar. That administrator approves the ClosedLoop AI Calendar app in Microsoft. The app asks for exactly two Microsoft Graph application permissions, and nothing else:
ClosedLoop AI stores your organization’s Microsoft Entra tenant ID and no passwords or Microsoft tokens. Each sync signs in as the ClosedLoop AI Calendar app for your tenant only.
Microsoft publisher verification for the ClosedLoop AI Calendar app is pending, so Microsoft’s approval screen can show the app as unverified. A Global Administrator or Privileged Role Administrator can still approve it.
Setup Guide
- In ClosedLoop AI, open Integrations and select Microsoft Calendar
- Click Approve in Microsoft
- First Microsoft screen, approve the permissions: sign in with your Global Administrator or Privileged Role Administrator account, review the two permissions, and click Accept
- Second Microsoft screen, confirm your organization: Microsoft asks you to sign in again. Use the same administrator account, from the organization that just approved. ClosedLoop AI uses this sign-in only to confirm which organization approved; a guest account or an account from another organization is refused
- You return to ClosedLoop AI with the integration connected
Limit Which Mailboxes ClosedLoop AI Can Read
Limiting mailboxes is supported. ClosedLoop AI needs onlyUser.Read.All organization-wide; Calendars.Read can be limited to the mailboxes you choose. By default, Calendars.Read lets ClosedLoop AI read every calendar in your organization. To limit it to a set of mailboxes (for example, only customer-facing teams), use Exchange Online Role Based Access Control for Applications. This needs an Exchange Administrator who is a member of the Organization Management role group.
- In the Microsoft Entra admin center, open Enterprise applications, select ClosedLoop AI Calendar, and note its Application ID and Object ID. Use the Enterprise applications page, not App registrations, which shows different values.
-
In Exchange Online PowerShell (
Connect-ExchangeOnline), create a pointer to the app, a scope, and a scoped role assignment:Instead of a management scope, you can scope the assignment to a Microsoft Entra administrative unit with-RecipientAdministrativeUnitScope. -
Remove the organization-wide
Calendars.Readpermission from the ClosedLoop AI Calendar enterprise application in Microsoft Entra, and keepUser.Read.All. Microsoft adds the two grants together, so while the organization-wide grant remains, the scope has no effect. -
Check the result with
Test-ServicePrincipalAuthorization -Identity <Object ID> -Resource <a mailbox>.
How Sync Works
- Ongoing sync: ClosedLoop AI syncs calendars every hour, covering the past and the coming week, so new, moved, and cancelled meetings are picked up.
- Directory: the staff list is refreshed every few hours. New staff are added automatically; disabled accounts stop syncing.
- Errors: if some calendars cannot be read for a while, the integration says so and ClosedLoop AI retries automatically. If Microsoft withdraws the approval (for example, the app was removed in Microsoft Entra), the integration shows Action required until an administrator approves ClosedLoop AI again.
Disconnect and Revoke Access
Both steps are required to fully revoke access. Disconnecting in ClosedLoop AI alone stops the sync but leaves your organization’s approval in place in Microsoft.- In ClosedLoop AI, open Integrations → Microsoft Calendar and click Disconnect. ClosedLoop AI stops syncing and removes the stored tenant ID. Events already synced are kept.
- In the Microsoft Entra admin center, go to Enterprise applications, select ClosedLoop AI Calendar, open Properties, and click Delete. This removes the approval and both permissions, so the app can no longer read anything in your organization. Exchange removes any scoped role assignment for the app automatically.
Connect Microsoft Calendar
Set up your Microsoft Calendar integration in the ClosedLoop AI dashboard