Atlas implementation guides

Practical guidance for a governed rollout.

Use these public guides to plan connections, permissions, approvals, and first-use verification before you expand access.

MCP-nativeApproval-firstPer-org isolation

Need help with an environment-specific decision? Talk to our team.

Bring your own LLM

Atlas is provider-portable by design. Start by documenting which workloads need a specific provider, confirm data-residency and retention terms, then test quality, latency, and cost against a representative workflow before making a provider the default.

Privacy, data rights, and GDPR requests

Keep your data inventory, retention policy, and processor list current. For a data-subject request, identify the organization and records in scope, export the requested information, apply approved correction or erasure steps, and retain the request decision in the audit trail.

Set up an agent

Give each agent one bounded purpose, the smallest set of read tools it needs, a defined token budget, and clear approval requirements for every write. Run it against a small sample first, review its audit entries, then expand its scope only after the result is reliable.

Search the audit log

Begin with a narrow time range and the affected record, then add actor, product, action, or approval filters. Review the before-and-after payload and the authorizing approval together; export only the filtered result needed for an investigation or compliance review.

Billing and payment changes

Workspace owners manage plan, invoice, and payment details from the billing area. Before changing a plan or payment method, confirm the account owner, seats, usage, and effective date; retain the invoice and the resulting billing event for reconciliation.

Connect Microsoft Outlook

An administrator authorizes the Microsoft 365 connection, grants the requested mailbox and calendar permissions, and chooses the users or groups in scope. Verify a test contact, event, and message before enabling a wider sync. Revoke access from Microsoft 365 if the connection is no longer required.

Upload, search, and connect files

Upload only documents your organization is permitted to process, then confirm their ownership and access scope. For Google Drive or OneDrive, authorize a least-privilege connection, select the intended folders, and verify search results with a small pilot before indexing a larger library.

Configure approval policies

Classify actions by risk. Allow low-risk reads freely; require an explicit approver for consequential writes such as sending mail, changing records, publishing content, or exporting data. Test each rule with a non-production example and review the audit event it produces.

Connect Microsoft Copilot

Prepare the approved Atlas tools and scopes first, then configure the Microsoft Copilot connection with a least-privilege identity. Validate tool discovery, read behavior, and the approval flow for writes with a pilot group before making it available more widely.

Connect a custom domain

Add the domain in Atlas Sites, create the DNS record shown by the setup flow, and wait for verification before publishing. Confirm the canonical host, HTTPS certificate, redirects, and a form submission after the domain becomes active.

Build your first Vibe app

Start with one approved workflow and a small set of fields. Build the page, add the minimum server-side function needed, test the permission boundary and audit entries, then publish a version that can be reviewed and rolled back independently.

Ready to put the guidance into practice?

Choose the product that fits the outcome you want, then start with a guided trial.

MCP approvals · Audit logs · MFA