Back to blog home

On July 7, 2026, Anthropic updated the Microsoft 365 connector for Claude Enterprise from read-only to read/write. Your AI can now draft and send email, manage calendar events, update mailbox settings, and create or edit files in OneDrive and SharePoint.

This is not a minor feature release. It is a governance inflection point. And most Australian SMBs — including the 64% now using AI regularly — aren't ready for it.

What Changed

For the past year, Claude could read your email, search your calendar, and summarise SharePoint documents. But it couldn't act. The data flowed one way: into the model. A human was always in the loop for anything that left the system.

That barrier is gone.

With write tools enabled, Claude can now:

The one remaining read-only boundary: Microsoft Teams. Chat stays human-controlled for now.

For an Australian SMB owner who uses Claude to draft customer emails, schedule appointments, and manage supplier documents, this removes hours of copy-paste work. But it also removes the manual approval gate that was your only verification layer.

The Permission Model Matters

Anthropic designed this carefully. Write tools require two deliberate admin actions:

1. A Microsoft Entra administrator must consent to the updated permission set 2. A Claude organisation administrator must explicitly enable write tools — they are off by default

And crucially, Claude operates within each user's existing Microsoft 365 permissions. If your team member can't send from a shared mailbox in native M365, Claude can't do it either. The AI does not escalate privileges.

But here's the catch: your existing M365 permission model is now the security boundary for your AI agent's write access. If you haven't audited your permissions in the past year — and most SMBs haven't — you're now trusting an outdated access model to govern an AI that can act on your behalf.

Three Risks Every SMB Should Address This Week

1. Send-on-behalf is invisible

When Claude sends an email from your account, there is no "sent by AI" marker in the recipient's inbox. For internal coordination, that's fine. For a customer quote, a supplier negotiation, or a compliance document, the question of who authorised that communication matters.

If Claude drafts and sends a pricing proposal with an incorrect figure, who is liable? The business owner who enabled the tool? The model? The admin who approved the permission?

Until AI-generated communications are verifiable, every outbound message from your M365 tenant carries latent risk.

2. Calendar actions have downstream effects

Claude accepting or creating meetings on your behalf isn't just convenience — it's a decision that affects other people's time. A double-booked client meeting, a declined vendor call without follow-up, a meeting invitation sent to the wrong distribution list — these are real costs, not theoretical edge cases.

3. SharePoint documents need provenance

Files created or modified by Claude sit alongside human-authored documents in your SharePoint environment. If your document retention, version control, or compliance workflows don't distinguish AI-generated content from human-authored content, your records are incomplete.

For industries like construction, healthcare, and professional services — where MachineryHQ, IT Pocket Buddy, and SoulGuide serve regulated or documentation-heavy workflows — this is a compliance concern, not just an operational one.

What to Do Next

Step 1: Audit your M365 permissions

Before you enable write tools, run an access review. Identify accounts with permissions they don't need. Close orphaned accounts. The permission model you have today is the one your AI will operate within.

Step 2: Define a write-tools policy

Decide which actions are pre-approved and which require a human checkpoint. A good starting framework:

Step 3: Verify every AI action

The gap that no tool vendor is filling — including Anthropic and Microsoft — is post-action verification. Who checked that the email Claude sent was accurate? Who verified the meeting invite had the right attendees? Who confirmed the SharePoint document didn't contain errors?

This is the verification layer. It sits between your AI agent and your business outcome. And right now, most SMBs don't have one.

The Bigger Picture

Claude's M365 write tools are the most visible example of a broader shift: AI agents are moving from observers to actors. Every month, another tool crosses the line from "can read" to "can act."

The Australian SMBs that thrive in this environment won't be the ones that block AI action — they'll be the ones that govern it. Verification, permission auditing, and action logging will become as essential as the AI itself.

Anthropic has given your business a powerful tool. The question isn't whether you enable it. It's whether you're ready to verify what it does.