Covara logoDocs
Integrations

Microsoft Teams

Set up the private Microsoft Teams pilot and link members to Vara safely.

The Microsoft Teams integration gives linked Covara members a personal chat with Vara, including Covara library retrieval and one-PDF-at-a-time upload. It uses one Covara-operated bot identity. No customer API key or Microsoft Graph consent is required.

Prerequisites

  • An approved enterprise private-pilot account with the teams_gateway entitlement
  • A team account member who has integrations.manage for tenant setup
  • A current Covara membership for every person who links a Teams identity
  • The Covara Teams app package installed or approved by your Microsoft 365 administrator
  • A named business owner, technical operator, security approver, incident owner, retention class, and pilot-review date

Owner Enable And Activation

Open Integrations

Go to /home/{your_org_name}/developers/integrations and select Enable Microsoft Teams.

Generate an activation code

Choose Generate activation code. The one-time code appears only in the dialog and expires shortly; Covara stores only a protected digest.

Redeem it in a personal chat

Open the approved Covara app in Microsoft Teams and send connect <code> in a personal chat. Do not paste the code anywhere else.

Confirm the tenant

Return to Integrations and verify that the connection is Connected, the expected safe tenant suffix is shown, and the policy is teams_dm_v2.

Each eligible member opens the same Integrations page and chooses Link my Teams identity. Send the displayed connect <code> command to Vara in a personal Teams chat before it expires. A code links only the signed-in Covara user and the Microsoft identity validated by Teams; Covara never links by email, UPN, or display name.

Supported Behavior

  • Personal/direct-message conversations only
  • Text input, one PDF attachment at a time, and text/Markdown output
  • Covara library search/selection with /docs, /attach, /clear, and /scope
  • PDF staging that asks for /type <policy type> before extraction begins
  • Processing status with /status
  • Plain language, deep intelligence, and claims advocacy toggles with /mode
  • Policy Genius report, executive summary, and claim-dispute workflows with /report, /summary, and /claim
  • Server-owned immutable policy profile teams_dm_v2
  • Current membership, account entitlements, allowed origin, link, installation, and policy checked again immediately before each agent turn
  • Source titles and page numbers in replies when Vara returns citations

Existing Vara And Session Continuity

Teams uses the same Vara engine, account-scoped document retrieval, tool controls, metering, document extraction queue, and chat storage as the web assistant. Messages from one personal Teams conversation continue the same Teams-origin Vara session for that linked user. The resulting session can be reopened from AI Assistant in the Covara web workspace; responses do not receive a special Teams badge.

Unsupported Behavior

The private pilot does not support channels, group chats, non-PDF or multiple attachments, reactions, message edits/deletes, adaptive cards, streaming partial answers, voice, Teams SSO, Microsoft Graph, resource-specific consent, Outlook, or proactive campaigns. Direct bot file upload is available only in Microsoft Public cloud; in other Microsoft clouds, upload the document in Covara web and select it with /docs.

Disable Versus Disconnect

Disable stops new Teams messages immediately while retaining the tenant installation, member links, and normal Vara history for authorized recovery. Disconnect revokes the installation and active Teams identity links. Existing chat history remains subject to the account's normal retention policy; disconnecting does not erase it.

Privacy, AI, And Retention Disclosure

Microsoft delivers the message to Covara, and Covara processes it with the same AI and account-data controls used by Vara on the web. Message content is stored in the Covara chat history under the linked user and account. Infrastructure audit records contain IDs, policy/version, state, timing, and safe error codes—not a duplicate transcript. Microsoft and Covara retention obligations still apply; do not send information your organization has not approved for the pilot. Review the privacy policy and your pilot's recorded retention class.

AI output is a review aid. Validate material coverage conclusions against cited policy language and professional judgment. Use the Integrations page link to report an unsafe or incorrect response.

Troubleshooting

  • A code fails: it may be expired, already used, for another tenant, or mistyped. Generate a new code; failures intentionally do not disclose account details.
  • A linked member is denied: confirm the person still belongs to the Covara account and the installation is connected. Membership removal blocks the next queued turn.
  • Replies stop: ask an integration manager to review the safe health code in Integrations. A Microsoft 401/403 places the installation in an attention state and requires operator review or reconnection.
  • A channel message is rejected: move to a personal chat. Channels and group contexts are intentionally unavailable.
  • An attachment is rejected: attach one PDF under the configured size limit. If your Microsoft cloud does not support direct bot file delivery, upload it in Covara web and select it with /docs.

What Safe IDs To Send Support

Send support@covara.ai your organization slug, approximate timestamp and time zone, safe installation suffix or internal installation ID shown by an authorized manager, request/workflow ID if displayed, and the safe error code. Never send the pairing code, Microsoft bearer/JWT token, bot secret, customer API key, message contents, or a full raw Microsoft tenant/user/conversation/activity ID.

On this page