GIORMO
ES IT EN
← Legal notice

Microsoft 365 mailbox access

Information for the Entra ID administrator who has to approve the application. Last updated: 28 August 2026.

1. What the application does and why it requests access

Giormo is a logistics management platform. When a client company decides to enable it, its users can read and send their own corporate email from inside Giormo, without switching applications: reviewing the inbox next to the transport file, replying to the customer and attaching the trip paperwork —transport orders, CMRs, invoices— without copying and pasting between two programs.

To do that, the application accesses the mailbox of the user who has signed in, through Microsoft Graph. Each user connects their own mailbox and only their own.

Microsoft has retired basic authentication in Exchange Online: today the only supported way for an application to access a mailbox is OAuth 2.0. That is why the application never stores nor gets to know any password; it receives a token that can be revoked at any time.

2. Why administrator approval is required

This is not a choice made by Giormo but a Microsoft policy, and there are two independent locks:

Without that step the user is stopped at the “Approval required” screen and cannot continue. Once it has been approved, their colleagues connect their mailbox without seeing any permissions screen again.

Giormo is a private platform, built for the transport industry, and is not published on the Microsoft marketplace. Until publisher verification is completed, the consent screen will show an unverified publisher warning. This is expected and does not mean the application is suspicious: the publisher domain declared in the registration is giormo.com, which is ours.

3. Permissions requested, and those that are not

The application declares a single resource, Microsoft Graph, and four permissions, all four of them delegated: they act solely on behalf of the signed-in user, never on their own.

PermissionTypeWhat for
Mail.ReadWriteDelegatedRead messages in the user’s own mailbox, mark them as read and save drafts
Mail.SendDelegatedSend on behalf of the user. Graph does not allow sending to be separated from the rest
User.ReadDelegatedCheck who owns the mailbox that has just been connected
offline_accessDelegatedRenew access without asking for credentials again

No application permission is requested (application permission, of type Role); the registration’s appRoles list is empty. This is the point that matters from a security standpoint: an application permission would let a service reach the organisation’s mailboxes with no user involved at all. There is none here. The application can only act on the mailbox of a user who has connected voluntarily, and only while their token remains valid.

Nor does it request Mail.ReadWrite.Shared (other people’s mailboxes), MailboxSettings (rules and automatic replies), or any permission over Calendar, Contacts, Files or Directory. And there are no hidden permissions that could appear later: adding any new permission would require approval just like the first one.

The flow is the authorization code flow with v2 tokens, and the implicit flow is disabled in the registration.

4. What happens to the messages

No copy of the mailbox is kept

Accounts connected through APIs —both Microsoft and Google— leave no copy of their messages in Giormo’s database. Every time the inbox is opened, a message is read or a search is run, the data is requested from Microsoft Graph at that moment and sent to the user’s browser. Neither the subject, nor the sender, nor the body, nor the attachments are stored.

The only exception is a volatile technical cache that keeps the inbox listing for 60 seconds, so the same request is not repeated while the user pages through it. It expires on its own and never reaches the backups.

What is kept: the company’s documents

When an operational document is taken from an email —the delivery note that becomes an order, the CMR filed alongside the transport, a supplier invoice—, that document and the data extracted from it are stored, because they are the object of the contracted service and the client needs them for their operations and their statutory obligations. The mailbox is not kept: what is kept is the document the user has chosen to add to their file.

Automated processing

When the user explicitly requests it on a specific document, its content may be processed by artificial intelligence models in order to extract operational data (order numbers, plate numbers, amounts, references) and avoid typing them by hand. There is no automatic processing of the inbox contents, no one at Giormo reads our clients’ email, and the data is not used to train models.

Credentials

Access tokens are stored encrypted with AES-256-GCM, never in plain text, and isolated per client.

5. How to limit who can use it

Even though consent is granted at organisation level, control over who can actually use the application stays with the client:

6. How to revoke access

Access can be withdrawn at any time, without notifying Giormo:

When an account is disconnected, Giormo cancels the Microsoft Graph notification subscription for that mailbox, deletes its credentials and removes any synchronisation data left behind. Documents already added to an order or an invoice are not deleted: they belong to the client’s records.

7. Registration details

These are the details you can use to identify and verify the application on the consent screen:

Application ID: 7d8c5a36-7576-44b4-a404-d1e3364b970c
Publisher domain: giormo.com
Redirect URI: https://app.giormo.com/oauth/microsoft/callback
Resource requested: Microsoft Graph, exclusively
Application permissions: none
Publisher: Giormo, S.L. — Tax ID ES B88752050

For any further checks, or if your policy requires publisher verification before approval, write to info@giormo.com and we will get back to you.