runpoint.
← What you’ll need

Access setup for IT

Someone at your company is taking the No Bullshit AI Boot Camp. They want Codex or Claude Code to work with their email, calendar, and files. Each person signs in with their own account, so the tool reaches only what that person can already reach. Ask them which tool they chose, then follow the section for your platform.

Google Workspace

If they use Codex

  1. In the Google Admin console, open Security › Access and data control › API controls › Manage App Access. Find the ChatGPT app and set it to Trusted, or approve the Gmail, Calendar, and Drive scopes it requests.
  2. If your company has ChatGPT Enterprise, a ChatGPT admin also turns on Gmail, Google Calendar, and Google Drive under Admin › Plugins. On ChatGPT Business and personal plans, these are on by default.
Scopes and IDs

Scopes requested: Gmail gmail.modify; Calendar calendar.events and meetings.space.readonly; Drive drive, drive.readonly, drive.metadata.readonly, and drive.activity.readonly. If a scope isn’t approved, the user sees an authorization error.

OpenAI: Google app data controlsGoogle: control which apps access data

If they use Claude Code

  1. In the Google Admin console, open Security › Access and data control › API controls › Manage third-party app access › Add app. Search for Claude and set it to Trusted. It takes about 15 minutes to apply.
  2. If your company has Claude Team or Enterprise, an Owner adds the Gmail, Google Calendar, and Google Drive connectors under Organization settings › Connectors.

Claude: Google Workspace connectors

Optional: command-line access

Some participants use the gws command-line tool so the AI can, for example, save email attachments into folders. It is an open-source project that Google says is not an officially supported product. It needs an OAuth client from a Google Cloud project.

  1. Create a Google Cloud project under your organization and enable the Gmail, Google Calendar, and Google Drive APIs.
  2. Configure the OAuth consent screen. With the External user type in Testing status, sign-ins expire every 7 days. The Internal user type limits access to your domain and avoids that limit. The gws guide documents External, so test Internal once before relying on it.
  3. Create an OAuth client of type Desktop app and share the client file with the participant privately.

Google: refresh token expiration

Microsoft 365

If they use Codex

  1. If your company has ChatGPT Business or Enterprise, a ChatGPT admin opens Admin › Plugins › Configure Microsoft permissions and selects Review permissions in Microsoft Entra. An Entra admin accepts the permissions for the ChatGPT app. The ChatGPT admin then turns on Outlook, SharePoint, or Teams separately.
  2. If the person uses a personal ChatGPT plan and your tenant blocks user consent, grant admin consent for the ChatGPT app in Entra under Enterprise applications › the app › Permissions › Grant admin consent. This needs at least the Cloud Application Administrator role.
Scopes and IDs

Outlook permissions requested include Mail.Read, Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, MailboxSettings.Read, and offline_access.

OpenAI: admin controls for appsOpenAI: Outlook appsMicrosoft: grant admin consent

If they use Claude Code

  1. The Microsoft 365 connector covers Outlook, OneDrive, SharePoint, and Teams. It needs a work account on a Microsoft business plan. Personal Outlook.com accounts won’t work.
  2. A Global Administrator grants consent once for the organization. The simplest way is to connect Microsoft 365 in Claude under Customize › Connectors and check the box to consent on behalf of the whole organization. Claude’s guide also covers manual setup with admin consent links.
  3. If your company has Claude Team or Enterprise, an Owner adds Microsoft 365 under Organization settings › Connectors.
Scopes and IDs

Service principals for manual setup: M365 MCP Client 08ad6f98-a4f8-4635-bb8d-f1a3044760f0 and M365 MCP Server 07c030f6-5743-41b7-ba00-0a6e85f37c17. Write actions need a separate consent and organization setting.

Claude: Microsoft 365 connector

Optional: command-line access

For command-line work with mail and files, use the Microsoft Graph PowerShell SDK. Microsoft has retired the older Graph CLI. If the participant needs their own app registration:

  1. Register an app for this organizational directory only.
  2. Add the Mobile and desktop platform with the redirect URI http://localhost, and set Allow public client flows to Yes.
  3. Add delegated Microsoft Graph permissions such as Mail.Read, Calendars.Read, Files.Read.All, and Sites.Read.All. Grant admin consent if your consent policy requires it.

Microsoft: desktop app registration

Please don’t send passwords to us. Each person signs in during setup. If you’d rather do this together, you’re welcome to join the participant’s first session.

Questions: sam@runpoint.ai

Admin paths checked September 25, 2026. Vendors rename menus often; the linked guides are the source of truth.