Skip to content

ONYX1 Office

Connect your digital office team to ONYX1, test it, give each team member a key, and ask Claude to hand work over. Everyone can ask, and each person sees only their own work and approvals.

For owners, office staff and crewAvailable on Pro and Enterprise, as a paid add-onLast reviewed
On this pageWho can use it

ONYX1 Office is a digital office team that does office work for you: a Chief of Staff and five specialists. They work from your ONYX1 data. You talk to Claude, Claude talks to ONYX1, and ONYX1 hands the work to your team. ONYX1 stays the record of your business.

The team runs on an Office server that the ONYX1 team sets up for you. Settings → ONYX1 Office links ONYX1 to that server. Only the owner and admins can see it.

Who can use it

Everyone in your workspace can ask the team for things through Claude, whatever their role. You do not need to be an owner or admin. What changes from person to person is what they get back:

  • You see only your own work. The work you hand over, and the answers to it, are yours. A colleague cannot look up your work, and you cannot look up theirs. If you ask about work that is not yours, ONYX1 answers that it cannot find it, the same as for work that does not exist. The owner can look up anyone's work, except work in which the team read someone's own Microsoft 365: only that person can see it (see What connecting allows).
  • You get only what your role can see in ONYX1. The team cannot show you anything you could not open yourself. For example, a crew member's daily brief has their own jobs and hours, with no invoices, quotes or leads. Nobody's brief has profit figures. Anything your role cannot see is left out of the brief, so a missing section does not mean zero.
  • Approvals are decided by the owner, or by an admin for their own work. When the team asks for a yes on work you handed over, the request is listed for you and only you, and the owner can see every one, except those on work in which the team read someone's own Microsoft 365. The owner can approve or reject any of them. An admin can approve or reject the ones on their own work. For everyone else, the request is listed as waiting for the owner to decide, and Claude refuses if you ask it to decide one.

To use it, connect Claude to ONYX1 with your own login (see Connect Claude). The Settings page for the Office server stays with the owner and admins.

Before you start

  • ONYX1 Office is a paid add-on, so it is not part of any plan. ONYX1 switches it on for your workspace. If ONYX1 Office is missing from Settings, it is not on for you yet, or an owner hid it (see Show or hide features). To get started, email support@onyx1.app.
  • Your workspace also needs the AI & integrations module, which comes with the plan, not the add-on (see Plans and what each includes). Without it you can still use this page, but Claude cannot sign in, Claude's address refuses every request, and team member keys stop working. The add-on does not switch it on.
  • The ONYX1 team sets up your Office server and fills in the Office server address for you in Settings → ONYX1 Office. They give you the other two things you need: the Office company id and the Office key. Have them ready.

Connect your Office server

  1. Open Settings → ONYX1 Office.
  2. Under Office server connection, check that the Office server address is filled in, then enter the Office company id. The ONYX1 team fills in the address for you. If it is blank, contact support@onyx1.app rather than typing one.
  3. Paste the key into Office key.
  4. Turn the switch on. While it is off, Claude cannot use your Office server: the office tools answer that the digital office is switched off. Team member keys stop working too, and ONYX1 refuses their calls and records them, until you turn it back on.
  5. Select Save.

The key field is write-only. Once a key is saved, the page shows Saved beside the field and never shows the key again. Leave the field blank when you save later changes and ONYX1 keeps the saved key. Paste a new key to replace it. If you change the address or the company id, ONYX1 removes the saved key when you save, so it is never sent to a different server. Paste the Office key again in the same save. While the address or company id differs from the saved one and the key field is blank, a notice beside the key field says the saved key will be removed when you save.

Saving a new address, company id or key sets the connection back to Not checked, because the last result described a different server. Changing the company id also clears the role choices, because a team member in one company means nothing in another.

If ONYX1 refuses the address, the message says why. An address needs to start with https://, be a public address (not localhost or an internal network address), have no username or password in it, and have nothing after a ? or #.

Test connection

Under Connection status, select Test connection. It stays unavailable until an Office key is saved, and it tests the saved connection, so save any changes first. ONYX1 checks six things and shows the result of each as OK, Check, Failed or Not checked. If ONYX1 cannot reach your Office server, the three checks that need it show Not checked. Before you test, a step you have not finished yet shows To do.

The pill at the top summarises the result:

  • Online: your Office server answered, asks callers to sign in, and knows your company.
  • Needs attention: your Office server answered, but it is not safe or ready to rely on. For example, it is still starting, it is running without sign-in, or it does not accept your key or company id.
  • Offline: ONYX1 could not get a usable answer.
  • Not checked: nothing has been checked since the connection was last saved.

Last checked is the time of the latest check, in New Zealand time. Last working is the last time a check came back Online. A check is a test you run, or a request from Claude that reaches your Office server, so the pill and these times can also move when Claude uses your team. A request that fails can turn the pill to Offline or Needs attention. Select Test connection to confirm it has recovered.

What each line means

If a line fails and the fix is not something you can do from this page, contact support@onyx1.app.

  • Your Office server is reachable fails when ONYX1 cannot reach your Office server, it takes too long to answer, or it reports that it is unhealthy. Check that the address is right, then contact support. It shows Check when the server is still starting, has not finished first-time set up or reports an unexpected status. Contact support to finish it.
  • Your Office server asks callers to sign in shows Not checked until your Office server is running normally. It fails with "Your Office server is running without sign-in." In that state anyone who can reach the address could act as the server's administrator, so ONYX1 does not count the connection as working, and Claude cannot hand out work or decide approvals until it is fixed. Contact support.
  • Company found fails when your Office server does not accept the key, the key is not allowed to use that company, or the company id does not exist. Check the company id, or ask the ONYX1 team for a new Office key, then save and test again.
  • Team connections pass on who asked fails when a team member's ONYX1 connection on your Office server does not pass on which task and person each request is for. ONYX1 refuses every request from that connection, so that team member gets no ONYX1 data until it is fixed. The line names the connection. It shows Check when ONYX1 finds no ONYX1 connection yet, when all of them are switched off, or when it could not read the list. Ask the ONYX1 team to fix it, then test again.
  • Six roles mapped to agents fails when no role is chosen, or when a chosen team member no longer exists on your Office server. It shows Check when only some roles are chosen. A department whose role has no team member cannot be given work. See Choose a team member for each role.
  • Agent key issued for each role shows Check until every role has a key. It does not stop the connection working, but a team member without a key cannot read your ONYX1 data.

The two lines about roles and keys do not need your Office server, so they are filled in before you test.

Choose a team member for each role

The six roles are Chief of Staff, Office Administrator, Operations Coordinator, Customer & Sales Coordinator, Finance & Business Analyst and Marketing Coordinator. Save the connection first: the role list stays unavailable until a connection exists, and Refresh agents needs your company id and key. Then, under Agent roles and keys:

  1. Select Refresh agents. ONYX1 lists the team members on your Office server. It keeps the one you saved for a role while the server still lists it. For any other role it picks the likely team member by matching their title or name to the role name.
  2. Check the choice beside each role. Choose Not mapped to leave a role empty.
  3. Select Save mappings.

ONYX1 does not guess when two team members fit one role equally well, so that role stays empty for you to choose. Until you select Refresh agents, each list shows only the saved team member, as Saved agent and the start of their id.

Give each team member a key

Each team member reads your ONYX1 data through their own key, not a shared one, and each role has one key. A key can use only the ONYX1 tools its role needs, and never a tool that needs the Read + money / sensitive actions level. It cannot read ONYX1 resources or prompts, only use tools. Separate keys also mean you can replace one without disturbing the others. A key does not give the team member any access of its own, and it does not matter who created it. The team always works with the permissions of the person who asked: when a team member works on a request, ONYX1 finds out who made that request and lets the team member use only the ONYX1 tools that person's own role can use, narrowed to the role's tools. Work that ONYX1 did not hand to the team gets no ONYX1 data at all. Beside each role, the page shows Key created with the date, or No key yet.

  1. Beside a role, select Create agent key.
  2. Select Copy token. ONYX1 shows the token once and cannot show it again.
  3. Follow the steps shown under the token to add it on your Office server. If the ONYX1 team looks after your Office server, ask them how to hand the token over.
  4. Select I have saved it.

To replace a key, select Replace key and confirm. The old key stops working straight away, so that team member cannot read ONYX1 until the new token is added on your Office server. If you lose a token, replace the key. To take a team member off ONYX1 altogether, select Remove key and confirm. The key stops working straight away and the role shows No key yet. Removing a key is recorded in the Audit log.

Team member keys also stop working while the connection is switched off, when no connection is saved, and when ONYX1 has not switched ONYX1 Office on for the installation. In each case ONYX1 refuses the call and records it.

Creating or replacing a key, and every tool call a team member makes, is recorded in the Audit log. The Actor of a team member's tool call is the person who asked, because the team member worked with that person's permissions. It shows as AI assistant followed by the tool's name (for example "AI assistant · find jobs"), with the role and the person at the start of the detail, for example Agent (finance) for Tama · find_jobs(query=Smith) → ok. A call ONYX1 refuses because it cannot tell whose request it is has the action mcp.agent_refused, and its Actor is the owner or admin who created the key. The detail ends in the outcome, such as ok, denied, invalid or error. The role is written as chief_of_staff, office_admin, operations, customer_sales, finance or marketing. Filter by Action mcp. or set Entity to AI assistant to see them. Calls Claude makes start with AI instead of Agent.

Connect your Microsoft 365

If your business uses Microsoft 365, each person can connect their own account so ONYX1 Office can work with their mail, calendar and documents when they ask. Connecting is optional. ONYX1 Office works with your ONYX1 data without it, and needs it only for a person's own mail, calendar and documents. ONYX1 has to switch Microsoft 365 on for your installation first. Until it has, My account and Settings → ONYX1 Office say so.

There are two steps, and they are done by different people.

Approve ONYX1 Office for your organisation (once, by an administrator)

A Microsoft 365 administrator approves ONYX1 Office once for the whole organisation. The owner or an admin opens Settings → ONYX1 Office, finds Microsoft 365, and uses the address under Approve for your organisation. If you are not the Microsoft administrator, send them that address. They sign in to Microsoft, review what is being approved and accept. Nothing else changes in ONYX1, and nobody's account is connected by this step.

Connect your own account (each person)

  1. Open My account.
  2. Under Microsoft 365, select Connect Microsoft 365.
  3. Sign in to Microsoft with your own work account. Microsoft always asks which account to use. Because your administrator has already approved ONYX1 Office, this is usually one click with no further questions.

The Microsoft account has to use the same email address as your ONYX1 sign-in. If it does not, ONYX1 does not connect it and tells you which email to sign in with; you can also ask your owner to update your ONYX1 email. Each Microsoft account can be connected to one person in your workspace only.

My account then shows the account you connected. Everyone connects their own account, whatever their role. Nobody can connect an account for someone else or use another person's connection. The owner and admins can see only that a person has connected and which account (see See who has connected); they cannot see anyone's mail, calendar or documents.

If Microsoft 365 is missing from My account, ONYX1 Office is not on for your workspace. If it says Microsoft 365 is not switched on for this installation, email support@onyx1.app.

What connecting allows

When you ask, your digital office team can read and search your email, read your calendar, and find documents in OneDrive and SharePoint. It can write drafts in your own mailbox. It sends an email only after you confirm the exact message. It can reach only what you can already open in Microsoft 365, so it cannot see a mailbox, calendar or document you cannot. Claude itself does not read your mail: the team members do the work you hand over.

There are limits on what the team can read:

  • Email: it reads the first 8000 characters of a message and the names and sizes of its attachments, never the attachments themselves.
  • Documents: it can find any document you can open, but it can read only plain text files under 1 MB (such as .txt, .csv, .md and .json). It cannot open Word, Excel or PDF files.
  • Calendar: it reads events in a window of at most 31 days.

What each team member can do with Microsoft 365 depends on its role:

  • The Chief of Staff and the Office Administrator: email, calendar, documents and drafts.
  • The Customer & Sales Coordinator: email, documents and drafts, but not the calendar.
  • The Operations Coordinator: calendar, documents and drafts, but not reading email.
  • The Finance & Business Analyst: documents and drafts, but not reading email or the calendar.
  • The Marketing Coordinator: documents only.

Sending email

When you ask the team to email someone, it writes a draft in your own Drafts folder and asks you to confirm it. Nothing is sent until you do.

  1. Ask Claude "What is waiting for my approval?". The email is listed with the Microsoft account it comes from (yours), who it is to, the subject, the full text, the names of any attachments, and any recipients outside your organisation.
  2. Ask Claude to approve or reject it. Claude reads the exact email back to you first, with every recipient, and sends it only when you confirm that exact email.

A few rules apply to every email:

  • It is sent as you. It goes from your own mailbox and appears in your Sent Items.
  • Only you can confirm it. The owner and admins cannot see or confirm an email from your mailbox, and you cannot confirm anyone else's. You do not need the owner's yes for your own email, which is separate from the approvals described under Connect Claude.
  • An edit needs a new confirmation. If you change the draft in Outlook after Claude read it back (the To, Cc or Bcc recipients, the subject, the text or the attachments), ONYX1 does not send it. Claude reads the new version back and you confirm that one.
  • It is sent once. If Microsoft does not confirm that an email was sent, ONYX1 does not try again by itself. Check your Sent Items before you ask for it again. If a send is still unfinished after about ten minutes, ONYX1 marks it as failed, not confirmed, and tells you to check your Sent Items.
  • Rejecting sends nothing. The draft stays in your Drafts folder.
  • Confirming needs the right level. Claude can confirm an email only on a connection set to Read + money / sensitive actions. If your Microsoft 365 connection has expired you can still reject an email, but you cannot confirm it until you reconnect. The email stays waiting for your decision, and Claude tells you to reconnect in My account.
  • There are limits. The team cannot attach files, and it will not ask to send a draft that has Bcc recipients. If you add Bcc recipients in Outlook yourself, the read-back lists them and the email goes out only if you confirm it. A draft can have at most 40 To and Cc recipients between them, and the team writes plain text of at most 8000 characters. It sends only from your own mailbox, never a shared one. If you attach a file in Outlook yourself, its name is shown when you are asked to confirm.

Each request and each send is recorded in the Audit log with who it was for and how many people it went to, and never the subject, the addresses or the text.

ONYX1 does not store your email, calendar or file content. What the team reads is passed to the team member doing your task, and anything the team writes into the result it gives you is kept with that work in ONYX1, like any other result. A request in which the team read your email, calendar or files (or wrote a reply to one of your messages), and its results, can be seen only by you in ONYX1: not by the owner and not by an admin. Because the owner cannot see that work, the team does not raise owner approvals inside it. Requests are processed on your company's Office server, so whoever administers that server could see the team's working records. The one other exception is an email you are asked to confirm: ONYX1 keeps its To and Cc recipients, its subject and the first part of its text (up to 2000 characters) so it can ask you, and it reads the full draft from Microsoft again whenever it shows it to you and when it sends it. Apart from that, ONYX1 stores the address and identifier of the account you connected and the sign-in that lets it act as you, which is protected and never shown to anyone, in ONYX1 or on a screen. Connecting and disconnecting are recorded in the Audit log, which shows who did it and when and never any mail, document or sign-in details. When a team member uses a Microsoft 365 tool, or writes a result or a hand-off, the Audit log shows only the names and lengths of what was passed, such as query=<22 chars>, never the words.

See who has connected

The owner and admins can see who has connected under Settings → ONYX1 Office → Microsoft 365, Who has connected. It lists each person's name, the Microsoft account they connected and whether it is connected or needs reconnecting. It never shows mail, documents or sign-in details.

Reconnect or disconnect

  • Needs reconnecting: a connection can expire or be ended in Microsoft. My account then shows needs reconnecting, and the team cannot use your Microsoft 365 until you select Reconnect and sign in again.
  • Disconnect: open My account and select Disconnect under Microsoft 365. ONYX1 deletes the stored sign-in straight away and ONYX1 Office stops working with your mail, calendar and documents. You can connect again at any time. Disconnecting removes only ONYX1's copy of your sign-in. The organisation's approval stays in Microsoft until your administrator removes it there.

Connect Claude

Under Connect Claude, the page shows the address Claude connects to: https://onyx1.app/api/mcp/office. In Claude, add it as a custom connector, sign in to ONYX1 and approve the connection. The steps are the same as for claude.ai in Connect an AI assistant and ask it how to use ONYX1.

Claude then has six tools for your team. Between them it can:

  • give you a daily brief
  • hand a piece of work to a department
  • ask a department a question
  • check on work already handed over
  • list the approvals waiting for you
  • approve or reject one of them: the team's requests for a yes (only the owner, or an admin on their own work, see below), or an email the team wrote in your own mailbox, which only you can decide (see Sending email)

Everyone can use these tools, and each person gets only their own work and what their role can see (see Who can use it). What Claude can do depends on the level you choose when you approve the connection:

  • Read only: the daily brief, work status and the list of approvals. Handing work over and asking a question are refused.
  • Read + everyday actions: also hand work to a department and ask a question.
  • Read + money / sensitive actions: also approve or reject an approval, if your role may decide it (the owner, or an admin on their own work), and confirm or reject an email from your own mailbox.

Things to ask Claude

  • "Give me my daily brief." Everyone gets today's and tomorrow's jobs, their own hours this week and what the team is doing on their work. Roles that can see them in ONYX1 also get what happened in the last 24 hours, money owed and overdue invoices, quotes gone cold, the lead pipeline and approvals waiting in ONYX1. It has no profit figures.
  • "Ask the finance team which invoices are overdue and who we should chase first." A question gets an answer back without changing anything.
  • "Hand this to operations: draft next week's crew plan for the Mt Wellington job." Claude sends a broad or multi-part request to the Chief of Staff, who splits it up between the specialists.
  • "What is the status of that work?" Work takes time. ONYX1 tells Claude that queued or working means it is not done, and that it is finished only when the status is completed. If ONYX1 could not start the team on a piece of work, Claude says it is recorded but has not started yet, and checking its status starts it.
  • "Reply to Priya's email about the roof and say we can start Monday." If you have connected Microsoft 365, the team writes the reply as a draft in your Drafts folder and asks you to confirm it. Nothing is sent until you do (see Sending email).
  • "What is waiting for my approval?" You see the requests the team raised on work you handed over, and the owner sees every request except those on work in which the team read someone's own Microsoft 365. If you are the owner, or an admin looking at your own work, you can then approve or reject one. Anyone else sees it listed as waiting for the owner to decide.

What the team cannot do

ONYX1 enforces some limits whatever the team is asked to do. The team can never get you more than you could open yourself: a crew member's request is answered from their own jobs, hours and gear, and an admin's request cannot reach anything only the owner can see. If you ask for something your role cannot see, the team member is refused and says so. A team member's key can use only the tools listed for its role, never a tool that needs the Read + money / sensitive actions level, and cannot use Claude's address. For example, the Marketing Coordinator's key can only look up jobs and sites in ONYX1 and find and read documents in Microsoft 365.

The team is also set up to raise an approval request before it sends anything to a customer, publishes anything, spends money or makes a change that is hard to undo. The Marketing Coordinator is told that publishing always needs your approval. Those are instructions on your Office server, not limits that ONYX1 enforces, so read each request before you approve it.

What a request says (its title, why, exactly what will happen, the risks and the impact) is kept in ONYX1 and shown from there, not copied to your Office server, and after the owner or admin decides, ONYX1 wakes the team member to carry on with the decision.

Before Claude approves or rejects something, ONYX1 reads the request back and runs it only when Claude confirms that exact request within five minutes. The read-back shows the title, who asked, the type of request, why, what will happen if it is approved, the business impact, the risks and the expiry, not just the title. If the request changes after the read-back, the confirmation stops working and ONYX1 reads the new version back instead.

Claude lists and decides only the requests ONYX1 raised for your team's work. An approval made directly on your Office server is not shown, and anything that is not one of those requests is refused and left to be decided on your Office server. ONYX1 also refuses a request that has expired or whose expiry it cannot read. An expiry is read as a date, for example 2026-10-10, which lasts to the end of that day in New Zealand, or as a date and time. A date and time with no time zone is read as New Zealand time.

Team member keys do not work on Claude's address. ONYX1 refuses the call and records it in the Audit log.

If something goes wrong

  • ONYX1 Office is missing from Settings: the add-on is not on for your workspace, or an owner hid it. See Before you start.
  • The page says "ONYX1 Office is part of your account, but ONYX1 has not switched the Office server connection on for this installation yet." ONYX1 has to switch that on for you. Email support@onyx1.app.
  • Saving says "ONYX1 Office isn’t switched on for your account.": the add-on is not on for your workspace.
  • Saving says "Only an owner or admin can manage ONYX1 Office.": ask the owner or an admin to do it.
  • Test connection shows Offline: check the address, then contact support.
  • Claude cannot hand work to a department: that department's role has no team member. Choose one, as described above.
  • The ONYX1 sign-in window for Claude shows Can't connect with AI & integrations isn’t on your workspace’s plan. The workspace does not have the AI & integrations module. An owner can change the plan in Settings → Plan & billing.
  • Claude's address or a team member's call is refused with not_entitled: the workspace is missing the AI & integrations module or the add-on.
  • Claude says an approval is not one it can decide, or that its expiry cannot be read: contact support, or ask the team to raise a fresh request.
  • Claude says it cannot find a piece of work or an approval that you know exists: it was probably asked for by someone else, and you see only your own. Ask the person who handed it over, or the owner, who can see everyone's except work in which the team read someone's own Microsoft 365.
  • Claude says only the owner or an admin can approve or reject a request: that is how approvals work. Ask the owner, or an admin if it is on their own work.
  • Claude says an approval has expired or is no longer pending: someone has already decided it, or its expiry has passed. Ask the team to raise a fresh request.
  • A team member's call is refused with "agent keys are switched off for this workspace": the connection is off, not saved, or switched off for the installation. See Connect your Office server.
  • A team member's call is refused because ONYX1 cannot tell whose request it is: the task was not handed over through ONYX1, the team member was started some other way (for example by someone commenting on the task on your Office server), the task has already finished, the person who asked is no longer active, or they have not set up two-factor sign-in that your workspace requires. Ask Claude to hand the work over again. If every call from one team member is refused, the Team connections pass on who asked line of Test connection will say why.
  • Test connection is unavailable after you changed the address or company id: ONYX1 removed the saved key when you saved. Paste the Office key, select Save, then test again.
  • Connect Microsoft 365 ends with "We could not connect Microsoft 365": try again. If it keeps happening, ask your Microsoft administrator to check that ONYX1 Office has been approved for the organisation (see Connect your Microsoft 365).
  • Claude says an email was not sent because the draft changed, is no longer in your Drafts folder or is not a draft any more: ask Claude to read the email back again, or ask the team to write it again.
  • Claude says Microsoft did not confirm that an email was sent: check your Sent Items. ONYX1 does not send it again by itself.
  • Connect Microsoft 365 tells you to sign in with the Microsoft account for your ONYX1 email: the account you chose uses a different email address. Sign in with the account that uses your ONYX1 email address, or ask your owner to update your ONYX1 email. If it says the account is already connected to someone else in your workspace, each Microsoft account can be connected to one person in your workspace only.
  • Claude says to connect Microsoft 365 in ONYX1 first, or that the connection has expired: you have not connected it, or it needs reconnecting. See Connect your own account.
  • Connect Microsoft 365 says the sign-in link had expired or was already used: select Connect Microsoft 365 again. A link works once and for about ten minutes.
  • Claude says it is not permitted to use a tool: the connection's level is too low for that tool. Disconnect it in Settings → AI & integrations and connect again at a higher level.