Microsoft 365
Productivity & documentsWork with Microsoft Teams, Outlook, and OneDrive/SharePoint: post messages and DMs, read or manage Outlook calendar events, and list/read/write files (including Excel .xlsx spreadsheets, Word .docx, PDFs) in OneDrive and SharePoint document libraries
What workflows can do with Microsoft 365
- Get Current User
- List Teams
- List Channels
- Post Message as Bot
- Send Direct Message as Bot
- Send Direct Message as You
- Read Calendar
- Create Calendar Event
- Update Calendar Event
- Delete Calendar Event
- List OneDrive Files
- List SharePoint Sites
- Read OneDrive File
- Upload OneDrive File
Full action reference
| Action | What it does |
|---|---|
| Get Current User | Get the authenticated user's Microsoft Teams profile |
| List Teams | List the Microsoft Teams the user is a member of |
| List Channels | List channels within a Microsoft Teams team |
| Post Message as Bot | Post a message to a Microsoft Teams channel as the Malleable bot (not as the workflow owner). Can reply in threads and @mention people. Content is Teams HTML. |
| Send Direct Message as Bot | DM a user (by email/UPN) as the Malleable bot. They must have the Malleable Teams app installed, or the tool returns a clear error. |
| Send Direct Message as You | DM a user (by email/UPN) as you, the connected account, so the message looks like it came from you. Requires your explicit approval to set up; otherwise use Send Direct Message as Bot. |
| Read Calendar | Read events from the connected Microsoft (Outlook) calendar with date filtering |
| Create Calendar Event | Create a calendar event with attendees, optionally attaching a Teams online meeting link |
| Update Calendar Event | Update fields on an existing calendar event by ID |
| Delete Calendar Event | Delete a calendar event by ID |
| List OneDrive Files | List files and folders in OneDrive or a SharePoint document library, by folder or filename search. |
| List SharePoint Sites | Search SharePoint sites the user can access and return each site's default document library drive ID. |
| Read OneDrive File | Read a OneDrive/SharePoint file — PDF, image, CSV, .xlsx, .docx, or plain text — and make it available to read-file. |
| Upload OneDrive File | Upload a file to OneDrive or a SharePoint document library — create a new file or overwrite an existing one. Source is an uploaded file, an HTTPS URL, or inline text. |
Access and security
- You grant access on Microsoft 365's own consent screen, and Malleable stores the resulting token, never your password.
- Each workflow chooses whose Microsoft 365 account the actions above use: its owner's for every run, or that of whoever starts the run, which keeps each person to what their own account can reach.
- You can revoke access at any time in Microsoft 365's settings.
Malleable is SOC 2 Type II audited and doesn't train AI models on your data. More in Security & data handling and our Trust Center.
Connection details for IT
Malleable asks for these delegated Microsoft Graph permissions, so it acts only as the signed-in person: offline_access, User.Read, User.ReadBasic.All, Team.ReadBasic.All, Channel.ReadBasic.All, Chat.ReadWrite, ChatMessage.Send, Calendars.ReadWrite, Files.ReadWrite.All, and Sites.ReadWrite.All. Chat.ReadWrite and ChatMessage.Send send direct messages as that person; Calendars.ReadWrite is for the calendar actions; Files.ReadWrite.All and Sites.ReadWrite.All read and save files in OneDrive and SharePoint; the rest keep the connection signed in, identify people, and list teams and channels. An administrator can approve Malleable for everyone at once, and has to if your tenant doesn't let people approve apps themselves. To post in a Teams channel, add the Malleable app to that team. To message people as Malleable, a Teams admin installs the app for them, for example with an app setup policy.