Writing

Where it runs, and what I can see

Before anyone asks what I would build, they ask where it would live and what I would be able to see. That is the right first question. Here is the whole answer, and the four ways it can be set up depending on how much of your accounts you want to open.

The short version

I work inside your Microsoft accounts through an admin login that you create, in your name, with the permissions we write down before I start. Everything I do goes through that login and lands in your own record of changes: every setting, every app, timestamped, with my name on it. Nothing is installed on your computers. Nothing of yours leaves your accounts. Your people sign in the way they already do, and your own security rules keep applying, to me included. When we are done, you switch my login off and keep everything.

That paragraph is complete and it is true. The rest is detail.

Four ways it can be set up

Not every company wants to open the same door, and I don't think they should have to. Each of these is a fine answer. What changes is how much I can do for you, and I would rather show you that trade plainly than talk you into the top of the list.

1. Your accounts, all the way in

You give me an admin login in your Microsoft accounts and, if anything needs a home outside them, a cloud account in your name. I can do everything: check the accounts against published standards and fix what fails, hand you the before and after, set up the email protections, build the records and the workflows, run the agents, and connect it all to your accounting system. You give up nothing, and you can see all of it. This fits a company with no IT department that wants one person to own the whole picture.

2. A room of your own

Your IT team sets aside a dedicated space inside your Microsoft accounts for this work, a login for the workflows to run under, and a list of the connections it may use. Everything I build lives in that room. I do not touch your email settings, your sign-in rules, or anything outside it. When the work needs numbers from elsewhere (your cost system, your schedule, your equipment list) they come in through a path your IT team already trusts, and someone on your side owns it. What you give up is the work that reaches across the whole account: the security review and the email protections. This is the usual answer at a company with an IT team, and the one I expect at a utility.

3. One seat at your table

One license for me in a space you already have, under rules you already wrote. What I build there is the core: the records, the app your people use, the reports, and the workflows that use Microsoft's standard connections. No custom connections, nothing hosted outside, and no agents. I build everything to run this way first, so nothing I offer depends on more trust than you have decided to give. This fits a company that wants to see the work before it opens another door, and it moves to the second or first arrangement later without rebuilding anything.

4. Nothing in your accounts

It runs in mine. Your people come in as guests or through a portal, and your data arrives as an export or a feed you control. You give up your own sign-in rules over it and your own record of changes, and where your data lives becomes a line in a contract instead of a fact you can check yourself. I offer this last and price it as what it is, because it puts me in exactly the position I warn about in Why you should own your own data. It suits a very small company, or one that is not ready to open anything yet, and it can be moved into your accounts later.

What I can see, and how you turn it off

In the first three arrangements my access is one named login, with two-step sign-in, holding a written list of permissions and nothing more. Where your plan allows it, those permissions switch on only while I am working and switch themselves off afterward. Every action shows up in your own record with the time and my name, and I will show whoever looks after your accounts where to read it. You can turn the login off yourself, any day, without asking me. I suggest trying it once early on, so you know that it works.

The tools I use to do the work quickly, and the same way every time, are mine and run on my own equipment. They reach your accounts only as actions taken by the login you gave me, which is why every one of those actions appears in your record. They include AI, and they are part of what the monthly fee covers.

If a piece has to run outside your accounts

Sometimes one piece belongs outside: a step that reads documents, or a small program that has no home in Microsoft 365. When that is the case it is named in the agreement before I build it: which piece, what information crosses to it, and what happens to that information when we part ways. You should never learn where your data goes by reading a workflow.

What you will need to have ready

  • A login for me, or the room, from whoever administers your Microsoft accounts. It takes a day, but it needs your administrator, not me.
  • Two-step sign-in on that login. I set it up. Five minutes.
  • Licenses in your own name. A Microsoft 365 plan that includes sign-in rules (most business plans do), a license for each person who will use an app, and a pay-as-you-go cloud account only if something is hosted. Licenses are the slow part. Ask about them first, not last.
  • Two or three moments when your administrator clicks approve: accepting the login, allowing an app, allowing the first connection. I tell you before each one, so nobody meets a consent screen by surprise.

Moving from less to more

If the second or third arrangement is where you want to start, good. Ask for the record of changes in the first week and read it. Ask for the security review of your accounts, which I run read-only and hand over whether or not we go further. Ask to see the same systems running before anything is built in yours. Each of those costs you nothing, and each is a reason to open the next door, or not to.

The sentence to keep is this one: you keep the system, I keep the method. Removing me is one click, not a migration.

Start a conversation Why you should own your own data

Unfamiliar word? The glossary explains them in plain English. More notes on the work, or subscribe by RSS.