
FlowLeap + Microsoft 365 Mail
Your team's mailboxes stay theirs. The AI gets its own — on your domain, with its own name — and works the correspondence from there. Documents get forwarded to it like you'd forward them to a colleague.
Works with the tools you already use
How the connection works
The AI gets its own mailbox
Not access to yours. We set up a mailbox on your domain as the AI's identity, or repurpose one you're barely using, the way you'd give a new junior an address. Give it a name your team will actually say out loud — they will start referring to it like a colleague, and that's the point. Every message it has ever sent sits in one mailbox you own and can read.
Your admin authorises it once, scoped to named mailboxes
A registered application in your Microsoft Entra ID tenant, over OAuth2 against Microsoft Graph. Consent at tenant level does not mean access to the tenant: we constrain the application with an Application Access Policy limited to the specific mailboxes you nominate. Everyone else's mail is unreachable by construction rather than by promise, and you can verify it in your own admin centre.
Sending sits behind the right person
The AI sends as itself. Where it acts on a particular person's behalf, that person owns the approval and the send, so their name is on their own client's mail. Sensitive inboxes — usually the principal's — stay out until you decide otherwise, and plenty stay out permanently.
It learns, then earns autonomy
Everything starts in shadow mode: the AI drafts, you approve, nothing goes out unreviewed. Your approvals and corrections are the training signal, not just a safety net. Once the same kind of item has been approved unchanged around twenty times, the system asks whether it should handle that one on its own. You say when — and you can take it back.
What we don't do
- We don't read mailboxes outside the scope you nominate — and you can audit that yourself.
- We don't send anything from a workflow still in shadow mode.
- We don't grant ourselves autonomy. The system asks, you decide, and you can revoke it.
- We don't create or change mailbox rules, forwarding or auto-replies on your mailboxes.
- We don't delete mail, and we don't move it out of your tenant.
Before day one — the bit that actually delays starts
Two admin jobs, both small, both worth lining up before we begin.
- Create the AI's mailbox on your domain — or point us at an existing one that's nearly empty. It needs a licence like any other mailbox.
- Persist the application connection — a tenant admin has to grant and persist consent, and apply the Application Access Policy to the mailboxes you've chosen.
If your IT is outsourced, that provider is who we need on the call — not just the partner who signed. In practice this is the single most common thing that holds a build up: everything else is ready and the work sits waiting on a permission nobody in the room can grant. Tell us on the first call who administers your tenant and we'll bring them in from the start.
What FlowLeap can do in Microsoft 365 Mail
Read
- The AI's own mailbox
- Nominated shared and individual mailboxes
- Message bodies, threads and conversation history
- Attachments, including items nested in forwarded chains
- Sent Items, for tone, structure and precedent
- Categories, folders and flags already in use
Prepare
- Replies drafted on the correct thread, in the right person's voice
- Chase and follow-up sequences, tracked per client
- Documents named, classified and filed to SharePoint or OneDrive
- A per-client action list built from what's actually in the inbox
- File notes recording what was asked, agreed or instructed
Send and act — as itself, or on your approval
- Send from the AI's own mailbox once a workflow is trusted
- Apply categories and file messages to folders you've defined
- Attach captured documents to the matching ledger transaction
- Release a drafted reply — by the person it belongs to, from Outlook, as normal
In shadow mode everything is a draft. As the AI proves a workflow, it starts sending from its own mailbox — every message visible in that mailbox, and the autonomy revocable at any point.
Core workflows
Six workflows we build first on Microsoft 365 Mail. Each one is defined down to the parts that actually go wrong.
Statement and document intake, by forward
ContinuousWhat it does. Your team, your clients, and the banks themselves forward documents straight to the AI's mailbox. It works out which client, entity and period each one belongs to, names it to your convention, files it, and queues it against the right transaction. In practice this beats a shared folder: forwarding is a habit people already have, and a bank statement emailed the day it's issued arrives days before the same data in a downloadable file.
What makes it messy
Almost nothing arrives clean. Statements come as photographs taken at an angle, two slips side by side in one image, invoices three levels down a forwarded chain, several documents in one zip, a body that says “see attached” with nothing attached, the same invoice twice from two addresses, and a sender domain that doesn't match the entity it belongs to. And the whole route usually depends on one person remembering to forward things — when they're on leave or off for a family emergency, intake simply stops.
What comes back. Filed and named documents matched to client and period, a queue for the ones it can't place, and the missing-attachment cases flagged for a chase — without one person's diary being the single point of failure.
The chase loop
ContinuousWhat it does. Works out what's still outstanding against the ledger, drafts the follow-up on the existing thread rather than a fresh email, tracks who has replied and who hasn't, escalates on your schedule, and stops the moment the document actually arrives.
What makes it messy
Three to five follow-ups per client per month is normal, and hours a week disappear into it. The worst version is chasing something the client already sent, buried in a thread nobody reopened. Some chases repeat forever for structural reasons — a bank feed that keeps dropping means asking the same client to reconnect it, week after week, which erodes the relationship faster than the missing document costs you. Tone varies by client, and knowing when to stop emailing and phone is judgement.
What comes back. Chases threaded correctly — drafted in shadow mode, sent from the AI's mailbox once trusted — a live view of who owes what, and no chase sent for a document already in the building.
Repetitive client questions
ContinuousWhat it does. Recognises the questions you answer every month — where's my invoice, what do I owe, is my VAT submitted, can you resend that — pulls the answer from the ledger, and drafts the reply on the thread in the voice of whoever owns that client, learned from their own Sent Items.
What makes it messy
The question repeats; the answer usually isn't in the email. It needs a live figure from the ledger, and someone has to notice when a routine question is the start of a problem — or a request for advice you should be charging for and shouldn't answer off the cuff. A reply in nearly-your-voice is worse than no reply, so this one stays in shadow mode longer than the rest.
What comes back. A reply with the figures already in it and the source shown, plus a flag when a question needs a human rather than an answer.
Remittances and payment advices
DailyWhat it does. Picks remittance advices and payment notifications out of the inbox, reads them including the PDF attachments, and proposes the allocation against open invoices.
What makes it messy
Every payer formats a remittance differently, they cover a lump sum across several invoices, they apply deductions without saying so, or they never arrive at all — leaving a receipt with a reference that's just a person's name. Often the advice lands days before the money. And the same person routinely pays for more than one entity, or a relative pays on their behalf, so the payer name alone never settles which client it belongs to. Where a note or reference does exist, it's frequently wrong — it has to be interrogated, not believed.
What comes back. Proposed allocations with the remittance attached as evidence, a shortlist of receipts still waiting on an advice, and the genuinely ambiguous ones left alone rather than guessed.
Triage, the action list and the diary
DailyWhat it does. Turns the inbox into a per-client action list — what was asked, what was promised, what has a deadline — ranked with deadline-bearing items first, and drafts the diary blocks for the work only you can do.
What makes it messy
Commitments live halfway down threads nobody reopens, and a deadline mentioned in passing on Tuesday is invisible by Friday. At most practices the principal is the bottleneck and the inbox is the real task list, so anything unseen isn't done — and in provisional tax season nobody is reading anything at all.
What comes back. A ranked action list per client, deadlines surfaced, and drafted diary blocks for the work that needs your hours.
File notes and the correspondence trail
ContinuousWhat it does. Records what was asked, agreed and instructed by email against the client record, with the message referenced, so the decision trail exists somewhere other than one person's inbox.
What makes it messy
Client instructions arrive by email and stay there. When a query lands months later, or someone is on leave, or someone leaves the firm, the reasoning is gone — and reconstructing it means searching a mailbox that may no longer be there.
What comes back. Dated file notes against the client, each linked to the message it came from.
Enabled per mailbox, per client, per workflow — you choose what it reads, what it drafts, and what it's eventually allowed to send.
How it starts
We onboard the AI the way you'd onboard a junior: one workflow at a time, simplest first, running in shadow mode beside your team for a couple of weeks until it reliably produces the result your people would have produced. You approve, correct, and watch. When you trust it, you switch that workflow on and we start the next one.
If your team doesn't work in email
Some practices have deliberately moved off email and run everything through a practice management system. If that's you, the inbox is still where clients live even when your team isn't — documents and questions arrive there whether anyone wants them to.
FlowLeap works either way: it can work the mail and surface the results into the system your team already uses, rather than adding another place to look. If a tool doesn't appear inside the workflow people already have open, it doesn't get used. We've seen that often enough to design for it.
Processing hundreds of client documents getting tedious?
Book a quick call with us to see how FlowLeap AI can automate your document processing to accounting tasks
Book a 30-minute call