Skip to content

Microsoft 365 Copilot

Bring your PlaidCloud data into Microsoft 365 Copilot. Once the PlaidCloud agent is installed and a person is granted access, they can ask Copilot about their projects, tables, dimensions, and allocation models in plain language — no separate login, no PlaidCloud window, no SQL.

“List my PlaidCloud projects.” “What tables are in Enterprise Profitability, and show me the first rows of one.” “Why did the allocated IT cost for the Atlanta cost center go up last quarter?”

PlaidCloud publishes a small agent that plugs into Microsoft 365 Copilot. When someone asks Copilot a question about their data, the agent securely connects to your PlaidCloud workspace, runs the request under that person’s own permissions, and Copilot explains the answer.

  • Read-only for most people. The common access level is read-only — list and describe projects and tables, read table data, list dimension members, and explain allocation results. It never invents numbers; every answer comes from a real query against your data, and each answer carries a confidence signal and plain-language caveats — see Answers You Can Trust.
  • Each person sees only their own data. Requests run as the signed-in user, bounded by the same PlaidCloud roles and access controls they already have. The agent can never reach credential, identity, or access-control settings.
  • No access until granted. Installing the agent is not the same as granting access. A signed-in person gets a clear “no access has been granted” message until a PlaidCloud administrator gives them an access level. This is deliberate — see Access Levels.

For what happens behind those points — the published agent package, the dedicated OAuth client, and how access levels are resolved and enforced — see Copilot Architecture.

The full path, in order. Up to three roles are involved — often the same person wears more than one hat. Steps 1–5 install the agent; step 6 is what actually lets data flow.

# Step Who Where
1 Download the agent package (.zip) PlaidCloud workspace admin PlaidCloud control plane → Workspaces
2 Allow custom apps Microsoft 365 / Teams admin Teams admin center → Setup policies
3 Upload the package Microsoft 365 / Teams admin Teams admin center → Manage apps → Actions
4 Add the agent in Copilot Each user Microsoft 365 Copilot → More agents
5 Sign in Each user Copilot (one time)
6 Grant an access level PlaidCloud administrator PlaidCloud

Your organization’s agent package is a single .zip, ready to download yourself from the PlaidCloud control plane — nothing to request and no file to wait for.

  1. Sign in to the PlaidCloud control plane and open Workspaces from the left navigation.

  2. Open the workspace that holds your data (the Edit or View action).

  3. At the bottom of the workspace dialog, click Download Copilot Package and save the .zip.

Microsoft 365 / Teams administrator. By default, Microsoft 365 blocks apps that aren’t from the public store, so the PlaidCloud agent can’t be installed until you turn this on.

  1. In the Teams admin center, go to Teams apps → Setup policies → Global (Org-wide default).

  2. Set Upload custom apps to On, then Save.

Microsoft 365 / Teams administrator. Add the .zip to your organization’s app catalog.

  1. In the Teams admin center, go to Teams apps → Manage apps.

  2. Click the Actions menu at the top-right of the page, then Upload new app.

  3. Choose the .zip you downloaded. The app uploads and publishes (you’ll see Published version 1.0.0), supported across Teams, Outlook, and Copilot.

  4. On the app’s page, set Availability — Everyone (org-wide default) for general rollout, or a specific group for a pilot.

The agent now needs to be added to each person’s Copilot.

  1. Open Microsoft 365 Copilot (m365.cloud.microsoft/chat or in Teams) and click More agents in the Agents list.

  2. Find the PlaidCloud agent and click Add. It then appears in the Agents list, ready to open. Every workspace’s agent is named PlaidCloud; where you have more than one, the workspace name is shown in the agent’s description to tell them apart.

The first time a person opens the agent and asks a question, Copilot prompts them to sign in. This is a normal, one-time step.

  1. Open the agent and ask a question, for example “List my PlaidCloud projects.”

  2. When prompted, choose Sign in and complete the PlaidCloud sign-in.

After that the connection is remembered — people don’t sign in every time, or every day. A fresh sign-in is only needed occasionally (roughly monthly) or if access changes.

The first time the agent reads PlaidCloud data, Copilot asks once: “I’ll connect to PlaidCloud to help with this and future requests. You can manage access anytime in Settings.” Choose Allow. After that, the agent runs its read-only lookups without asking again, so a multi-step question is answered in one pass. All PlaidCloud agent actions are read-only, and access is still limited to what the person’s PlaidCloud access level, permissions and row-level security allow.

This is the step that turns “no access has been granted” into real answers. After a person has signed in, a PlaidCloud administrator grants them an access level (see Access Levels below). Access is deny-by-default: with no level assigned, the agent connects but returns no data.

Each level is a PlaidCloud group, and a person belongs to one of them:

Level Group
Read-only Microsoft 365 Copilot Read Only
Read/Write Microsoft 365 Copilot Read and Write
Full Microsoft 365 Copilot Full Access

A person who isn’t in any of these groups gets a message telling them to ask an administrator to add them to the Microsoft 365 Copilot Read Only group (or one of the other two). Add them to the group that matches the access they need.

Once a level is granted, the person simply asks again — there’s no need to sign out or reinstall. Access is checked live on every request, so the next message returns data.

Every PlaidCloud Copilot user holds one of three levels. The level is a ceiling on what the agent may do; within it, the person’s own PlaidCloud permissions still apply, so the agent can never show or change data they couldn’t already reach themselves.

Level Tools the agent loads Can it write? Raw SQL Typical use
Read-only Read and lookup tools only — list and describe projects and tables, read table data, list dimension members, explain allocations. No. Read and describe only. Read-only queries only (SELECT and set operations); a statement that would write is refused. Most people. The safe default.
Read/Write Everything in read-only, plus the write tools the person is permitted to use, such as updating table data, editing dimension nodes and uploading documents. Yes — structured writes only, each still bounded by the person’s own permissions. Read-only queries only. Changes go through the write tools, never raw write SQL. Analysts who maintain data.
Full (deprecated — removed January 15, 2027) The person’s complete PlaidCloud tool set, minus the always-blocked actions below. Yes — structured writes and raw SQL that writes, bounded by the person’s own database role. Read and write SQL. Power users and builders.

A few rules apply at every level:

  • Deny-by-default. No level assigned ⇒ no access. Nothing is exposed until someone is granted a level.
  • Most permissive wins. If a person somehow holds more than one level, the highest applies.
  • Some actions are never available to the agent — even at Full. Credential, identity, access-control, and code-deployment tools stay human-only, whatever the person’s own PlaidCloud permissions. The agent can never, at any level:
    • change credentials or access control — data-connection credentials and who owns or has access to a connection, document-store credentials and their access control, project access control, a project’s ERP posting mode, member accounts, group membership and roles, distribution lists, password resets, or publishing; and
    • deploy or author code — user-defined function code, JupyterLite apps, or Panel apps.

Open Copilot, select your PlaidCloud agent, and ask in plain language. Good starting points:

  • Find your work: “List my PlaidCloud projects.” / “What tables are in project X?”
  • Read data: “Show me the first 20 rows of the customers table.” / “What values are in the Region dimension?”
  • Explain results: “Why did the allocated cost for the Atlanta cost center change between Q1 and Q2?”

The agent picks the right tool, runs the query against your data, and Copilot answers — leading with the result, then a short table or summary. If a request needs data you don’t have access to, or a change above your level, it says so rather than guessing.

Asking Questions That Get Straight Answers

Section titled “Asking Questions That Get Straight Answers”

Copilot finds the right analysis path, project and table for a business question, and it reads any error PlaidCloud returns, corrects its request and tries again — you don’t need to rephrase after a hiccup. A few habits make answers faster and more exact:

  • Name the measure and the filter in plain words. “FY2027 EBITDA in UDM, Allocated and DairyCheese” names the measure (EBITDA) and the filters (fiscal year, unit of measure, scenario, business unit). A filtered total comes back in a single lookup.
  • Say which scope you mean. If a total could be a whole company, a division or one business unit, say which. When it’s ambiguous, Copilot asks rather than guessing.
  • Check the filters Copilot states. Every answer lists the filters it applied. If one isn’t what you meant, say so and Copilot reruns it.
  • Name the analysis path when you use more than one. See Analysis Paths.
Symptom Cause and fix
Can’t find Upload new app in Manage apps It’s in the Actions menu at the top-right of the page, not the grey toolbar. If it’s missing entirely, Allow custom apps isn’t on yet.
“Uploading custom apps is not allowed” on install The Upload custom apps policy is off. Turn it on (step 2), wait for it to propagate, and retry.
The agent isn’t in Copilot’s Agents list Look under More agents and click Add. An org-wide-published agent can take time to appear; to test now, sideload the .zip to yourself.
“No Microsoft 365 Copilot access has been granted to this user” Expected until an access level is granted. The person is signed in and connected — they just need a level. Ask again right after it’s granted.
“Ask an administrator to add you to the Microsoft 365 Copilot Read Only group” (or a different level) The person isn’t in a Copilot access group yet. Add them to the group for the level they need, then have them ask again.
Copilot says it doesn’t have a tool to query PlaidCloud The agent package is out of date. Update it to the latest version from the control plane and start a new chat.
A request to change data is refused The person’s access level (or their own PlaidCloud permissions) doesn’t allow that write. Raise their access level if appropriate.
Asked to sign in again after it was working Normal — the saved connection is refreshed periodically (roughly monthly). Sign in once more and continue.
Answers seem to need data the person can’t reach Expected — the agent only ever returns data the signed-in user is already permitted to see.
A read-only user can sign in but can’t read tables Interim, being addressed: read-only Copilot users currently need broader analyze access to read tables — contact support@plaidcloud.com.

When PlaidCloud releases a new version of the agent package, an administrator updates it in three steps:

  1. Download the package again from the control plane (Step 1).

  2. In the Teams admin center, open Manage apps, select the PlaidCloud agent, and choose Update to upload the new .zip (Step 3).

  3. Ask your users to start a new chat with the agent. A chat already open keeps the earlier behavior.

Access levels and sign-ins carry over; nobody needs to sign in again. If Copilot keeps using the previous version after the update, remove and re-add the agent: open the Agent Store, choose the agent’s … menu and Uninstall, then add it again from Built by your org. Start a new chat afterwards.

You download the agent package yourself from the control plane — see Step 1. For access levels, or anything that isn’t behaving as described here, contact your PlaidCloud representative or support@plaidcloud.com.