Manual

Connecting your accounts: Google, Microsoft 365, email and tools

Once a channel is connected, Orion already talks to you. This chapter is about what it can reach: you link Google or Microsoft 365 — calendar, email and documents —, forward your email so it reads what comes in, connect third-party tools, and let the assistant you already use (Claude, ChatGPT or Grok) look up what Orion knows.

Read in: Portuguese · Spanish

Where it talks to you — WhatsApp, Telegram or voice — and the channels where it serves your public are in the chapter Connecting Orion.

Google and Microsoft 365

Connecting one of these two accounts is what most increases what Orion can do. You can connect both, one, or neither — nothing here is required.

Google

Two ways, pick the easier one: through the link Orion sends in step 3/4 of the setup (in Connecting Orion), or through the dashboard, at Orion → Google → "Connect Google". Authorize on the Google screen and the page refreshes on its own.

What it can doExample request
See, create, edit and cancel events in Calendar"How does my calendar look tomorrow?" · "Book a meeting with Ana on Tuesday at 3pm"
Send email through Gmail on your behalf"Reply to this email saying we're set for Friday"
Create and edit documents and spreadsheets in Drive"Put together a spreadsheet with these numbers"
Look up your Contacts (read-only)"What's the email of Ricardo from Acme?"

Four limits worth making clear from the start, because they explain almost every "why couldn't it do it?":

It does not read your Gmail inbox. The permission requested is send, not read. For Orion to read what arrives, use the email forwarding described below.

In Drive, it only sees what it created itself. That is the minimum scope (drive.file). If you ask "list my Drive files", only the files Orion created come back — your older documents it does not see, does not open and does not edit. When it tries, that is exactly what it answers.

It does not grant access to anyone. When it creates a document or spreadsheet, Orion gives you back the link; sharing it with someone else is up to you. (In OneDrive, on the Microsoft side, it can generate a sharing link — the asymmetry is real.)

The calendar says how far it was read. It reads up to 5 of the calendars checked in your Google Calendar list; if there are more, it says how many were left unread. When a calendar has more events in the requested window than it brought back, it says how many it read and that there are more, and it does not claim a time is free after the last event it read.

The page itself sums up the permissions requested: your email address, Calendar, Gmail send, Drive files it creates, and read-only Contacts.

Microsoft 365

If your company lives in Outlook and Teams, this is your chapter. Open Orion → Microsoft 365 and click "Connect Microsoft 365". A Microsoft window opens; after you authorize, close it — the page refreshes on its own.

On most accounts this is one click and needs no IT admin. If your company has turned off per-user consent, the Microsoft screen will say "Approval required". In that case, click "Generate admin link" on the same page: the link comes already copied, you send it to IT, and their approval unblocks the whole organization at once.

What it can doExample request
Read and triage the Outlook inbox (the most recent messages)"Anything important in my email?"
Send and draft email in Outlook"Reply to Ricardo saying we're set for Friday" · "Leave a draft for me to review"
See, create, edit and cancel events in Calendar"Book a meeting with Ana on Tuesday at 3pm" · "Cancel Thursday's and tell the guests"
Read and send messages in Teams — 1:1 and group"What happened in the project chat today?" · "Tell the team on Teams that the release is out"
Create and update spreadsheets in Excel, create documents in Word"Put together a spreadsheet with these numbers" · "Write the minutes of this meeting"
List, organize and share files in OneDrive"Create the Clients 2026 folder and send me the sharing link"
Create pages in OneNote and tasks in To Do"Note this down in OneNote" · "Add to To Do: call the accountant"

And the limits, which here are different from Google's:

It reads your Outlook inbox — directly, with no forwarding, but not all of it. Connecting Microsoft 365 grants email read access. It is more power and it is also less privacy than the Google side; the choice is yours, and disconnecting is one button on the same page. What it reads each time: only the Inbox folder, the most recent messages — up to 25 — and, for each one, the sender, the subject, the time and the beginning of the text. Other folders (junk, archive, subfolders) and older messages are left out, and in Outlook it has no search by sender or subject. So when it answers, it says how much it read and what was left out, and it does not treat that part as the whole mailbox: if the email you are looking for did not show up there, that does not prove it never arrived.

Teams channel messages are not accessed. It reads and writes in 1:1 conversations and in group chats. Team channels (those tabs inside a team) would require an admin permission that the product deliberately does not request. Here too the read is partial, and it says so in its answer: the list brings up to the 20 conversations with the most recent activity, and in each conversation it reads up to the last 30 messages (very long ones, only the beginning).

Personal Microsoft accounts do not work. The connection is built for corporate/educational accounts (work or school).

If a new feature asks you to reconnect, reconnect. The permissions for files, drafts, OneNote and To Do were added on July 28, 2026. Anyone who authorized before that keeps email, calendar and Teams working normally, but the new features will answer by asking for a reconnection — which is the same button as the first time.

On the Outlook calendar, it reads only the main one. Shared and team calendars are left out, and it looks up to 30 days ahead. When the calendar has more events in the requested window than it brought back, it says how many it read and that there are more, and it does not claim a time is free after the last event it read.

About sending things on your behalf

This is worth stating precisely, because it is a point where the promise and the behavior have to match.

When Orion is about to fire off a send to a third party (email, WhatsApp, Teams message, calendar invitation with external guests), there is an automatic hold: the system holds the send, shows you a draft field by field — "Send confirmation — nothing has been sent yet" — and only sends after your yes. That draft is assembled by the system itself, not narrated by the model, and your yes is bound to that exact text: change one comma and you have to confirm again.

This hold applies to every send of this kind, not only when the turn read external content first — an email, an attachment, a web page, a group message. In those cases it is also a defense against planted instructions: what it has just read may be exactly what is asking for the send.

It applies on a direct request from you, on a clean turn — "send an email to João saying we're set for Friday" —: it resolves the contact and shows you the draft before sending. And it applies in voice conversation: the draft is read aloud and the yes is spoken.

In practice, the habit that works: when you want to work on the wording before the card, split it into two requests. "Write the email to João about the proposal, but don't send it yet." You read it, adjust it, and only then: "go ahead and send it."

Forwarded email

This is the optional step that most changes the routine of anyone who lives in the inbox. It exists because Orion does not read your Gmail — the permission it asks for on Google is send. Forwarding is what gives it the other side.

  1. In the dashboard, open Orion → Emails and click Copy on the address field. It has the form [email protected].
  2. In your provider (Gmail, Outlook, iCloud, Yahoo…), set up auto-forwarding to that address.
  3. Gmail sends a confirmation request to Orion's address, one you would never see. If the mailbox that asked is one of your accounts (the connected Google or Microsoft account, the prospecting sending mailbox or your sign-up email) and the request really came from Google, Orion tries to confirm it on its own and lets you know on your channel with it, saying which mailbox it confirmed. One step is still yours: go back to Forwarding and POP/IMAP, refresh the page, select "Forward a copy of incoming mail to" Orion's address and click Save Changes. Without it, nothing arrives. If the mailbox that asked isn't one of your accounts, or if Google doesn't accept the confirmation, Orion does not confirm. It lets you know, with the link and the code, and you decide: if it was you, just open the link; if it wasn't, ignore it. You get at most one such notice per mailbox per day. On official WhatsApp, outside the 24-hour window, that notice is short and goes without the link. If Orion can't confirm the request really came from Google, it neither confirms nor notifies you. In all these cases, the request, with the link, stays in Orion's email inbox: just ask Orion for it.

From then on, the question that unlocks everything is simple: "anything important in my email?". It summarizes what arrived, sorts out what matters, reads the whole email when you ask, opens attachments (PDF, image, Word, Excel, CSV, text) and drafts replies. The reply goes out through the account you connected — Gmail, if Google is connected; Outlook, if it is Microsoft.

The Emails page shows what it has already received, with the counters for New, Skimmed, Read and Total.

Who wrote it, and through which mailbox. In a forwarded email, the sender Orion shows is whoever wrote it, not the mailbox that forwarded it, and Orion knows which of your mailboxes it came through. If the same email arrives twice, through two forwarded mailboxes or two routes, only one copy is kept.

When you ask "did Ricardo reply?" or "any email from Acme?", Orion's instruction is to search all your forwarded email, read and unread, before answering. If the search comes back empty, it should say it found nothing in what was forwarded to it — not that the person never wrote, because email sent to one of your addresses that is not forwarded to Orion, or that your mailbox did not forward (Gmail, for example, does not forward spam), never reaches it. And if it looked at only part of it (only the unread ones, or only the most recent results of a search with many matches), it should say which part — and when you ask it to open "the email from Acme" and more than one matches by sender or subject, it opens the most recent one and should tell you there are others. If an answer comes without that search, ask: "search the emails".

If nothing arrives, it tells you. When Google is connected but no email has ever reached the agent's address, Orion notices — because not even the provider's confirmation showed up — and sends you a message explaining what is missing. It does this once and repeats at most one more time, a few days later. After that, it stops.

Corporate email can block it. Many Google Workspace and Microsoft 365 admins block external auto-forwarding. If that is your case, ask IT to allow "external auto-forwarding" — or connect a personal email.

On Microsoft 365 there is no forwarding. Anyone who connected Microsoft has already granted read permission: Orion reads Outlook directly, without this step. If you use both, forwarding still serves mailboxes that are not in Outlook. The prospecting sending mailbox is a separate account, which Orion does not read, even when it is Microsoft: what reaches it only gets to Orion if it is forwarded (see "Forwarding the sending mailbox to Orion" under Prospecting).

Third-party tools

Beyond Google and Microsoft 365, Orion can use external tools from a platform-approved catalogue. They live under Orion → Integrations, and the principle is always the same: you supply the credential for your own account. These tools are not part of your plan — the account and whatever it costs are yours, and Orion simply learns to operate them in your conversations.

The catalogue is curated: only tools the platform has reviewed get in. You do not register addresses of your own.

Connecting takes three steps: paste the credential the tool gave you, click Connect, and the panel tests the connection right away. From then on each integration has Test connection, Pause and Remove — removing deletes the stored credential.

One detail that often goes unnoticed: connecting an integration does not hand it to your AI workers. Each worker needs you to tick, on the Governance page, which integrations it may use. Unticked ones stay blocked for that worker even while connected.

Invoicing

The catalogue includes a Brazilian tax-document integration covering service invoices (NFS-e), goods invoices (NF-e and NFC-e) and transport documents, plus cancellations and correction letters.

Before counting on it, three things need to be clear.

It requires a digital certificate. For any invoice to be issued by software, automatically, the Brazilian government requires an ICP-Brasil digital certificate (A1 or A3) — it is what signs the document on the company's behalf. This is not a requirement of our platform or of the integration: it applies to every tax software in the country, with no exception and no shortcut. The certificate is configured in your account with the tax tool, not here.

Without a certificate, the path is the government issuer. Anyone without a certificate — which is most sole traders — issues free of charge on the official NFS-e portal and app, signing in with a gov.br account. There is a simplified mode there that asks for two fields: the customer's tax ID and the amount. The gov.br login works for issuing on screen; it does not work for automatic issuing by software.

Orion never issues anything on its own. No invoice is generated in the background, by an automatic routine, or without you asking. And when the request comes from an AI worker rather than from you, issuing is treated as a financial action: it follows your organization's autonomy policy and is never waved through just because an approved work plan existed. Even so, the habit matters: an invoice is a legally binding document, and the amount, the customer and the type of service you dictate are the ones that reach it.

Tax responsibility is yours. Orion is not your accountant and does not choose your service's tax code — you set that once, in the tax tool or in the government issuer. An error in the code, the amount or the recipient is the responsibility of whoever issued the invoice.

Connect your assistant (Claude, ChatGPT, Grok)

You can connect the assistant you already use every day — Claude, ChatGPT or Grok — to what Orion knows about your operation. Ask it there, "what did we agree with this client in June?", and the answer comes from here.

The direction matters, and it is the opposite of Integrations: there Orion uses third-party tools; here an outside assistant consults Orion.

Three different things are called "connecting", and they are worth telling apart. Connecting a channel means linking Orion to your WhatsApp or your Telegram so you can talk to it there — that is the chapter Connecting Orion. Connecting your assistant is what this part explains: the Claude, ChatGPT or Grok you already use starts consulting what Orion knows, and no key is copied anywhere. Bringing your own AI key (BYOK) is the opposite of that: there it is Orion that starts running on your AI provider's key instead of ours — it is a plan choice, and it lives in the chapter "Plans, leaving, and glossary". If you ask Orion to "connect Claude", it will ask which of those last two you meant.

How to connect

The simple path is signing in with your account. In your assistant, add a connector pointing at the address the panel shows under Orion → Integrations, and nothing else. It opens an Orion sign-in; you sign in as usual, see what is being asked for, and approve. Nothing to copy or store. The authorization lasts 90 days and you can revoke it whenever you like, on that same screen.

Before you approve, check where the access goes. Right under the assistant's name, the screen highlights the address that will receive the authorization — for example, Access goes to: claude.ai. The name is what the assistant says about itself, and anyone can pick any name; the address is where the authorization actually goes. When the destination is an app installed on your device, the screen says an app on this device.

The screen also warns you, before the Authorize button, when:

  • the name — or the address itself — looks like a well-known assistant, such as Claude, ChatGPT, Gemini, Copilot, Cursor, Grok or Orion itself, and the address is not one of the addresses we know for that assistant;
  • the destination is a program on your own device — that is normal for assistants that run on your computer, such as coding assistants;
  • the address is numbers only, not a website name;
  • the address has accented letters or letters from another alphabet — it then appears in its technical form, starting with xn--, so it cannot pass for another site.

The warning does not block anything: if the assistant is yours and you just started the connection, you can approve. If it wasn't you, refuse. With any warning except the one about a program on your device, Refuse takes you back to Integrations, not to the flagged address. Claude, ChatGPT and Grok, connected the normal way, show no warning. A legitimate assistant can show the warning when it receives the authorization at an address we don't yet know as its own; the same rule applies. And the warning does not catch every imitation: the address is what counts. Approve only if it really belongs to the assistant you use.

When you approve you answer two questions — and both start at the smallest scope:

  • How far can it read? "The organization only" (the default) or "also my personal layer".
  • Can it write? Unticked by default, and it is a choice separate from reach: you can keep reading to the organization only and still allow writing. When the reach is the organization’s, the screen warns you about the shared-key risk before you tick it.

If you would rather use a key — or if your assistant cannot do that sign-in — the same block lets you create one. Name the connection, copy the key right away (it appears once; after that we keep only a fingerprint of it) and paste the address into your assistant. A key lasts 90 days, you can hold up to five at a time, and revoking cuts access immediately.

What it can then see

Everything below arrives with the role of whoever authorized the connection — the person who approved the login or created the key — in the organization: what that person does not see in the panel, the assistant does not see either. If the person who authorized the connection is deactivated or removed from the organization, the connection stops responding.

From the organization: the pipeline snapshot, the revenue forecast for open deals, the open deals themselves and the people due for contact today; the deliverables and tasks, each with its progress and the original deadline alongside the replanned one; each team's delivery plans and the people's work plans, with cycles, reports and assessments; the dashboard, the teams and who is on each; and what is waiting on you — approvals, assessments, signatures and anything an AI worker wants decided.

And the decision record: what was decided, why, the context, the lessons and the deviations from the method. That is what separates an assistant that opines from one that checks what was already agreed before proposing. A decision later replaced is not presented as current. A note about someone's work plan — the explained deviation of a cycle, for example — only shows up for people who can open that plan, and the full archive of lessons, for Admin, HR and Audit.

Long lists come in pages and always state the total: if there are 245 deliverables and it showed 50, it knows 195 are missing and can ask for the rest.

Choosing "also my personal layer", it further reaches the conversation and decision history with each contact, your personal list (the one in the panel, which is yours and is not the organization's work) and the detail of work plans — which carry per-person assessments. With "the organization only", those stay out.

What it can change, if you allow it

With write permission it opens and updates deliverables, creates, updates and deletes tasks, records decisions, keeps your personal list and operates inside a plan — opens a draft work plan, adds and adjusts activities, records a cycle report and a progress note.

What it does not do through this connection, and why:

  • Make a pact — sign, assess, appeal or close a plan early. On the record a signature is yours; an outside assistant does not sign in your name.
  • Send — message, e-mail, invitation. That lives inside Orion, where the send confirmation and recipient guards are.
  • Create a CRM contact — a record about another person is created inside Orion, where the deduplication and organization-scope rules apply.
  • Delete work that has moved — a task with progress is not deleted through conversation, because removing a line silently changes the deliverable's progress. Zero the progress first, and then it is a deliberate act.

Two guarantees that always hold. It stays limited to what you can do under your role: if you cannot create a task in the panel, neither can it. And every act is recorded as coming from that assistant, with your name as the person who authorized it — which is why, if you allow writing on a key other people may use, whatever they have it create or change is recorded under your name. The screen warns you before you tick it.

It sees exactly what you see in the panel: nothing that was already outside your view appears through this path. And reading depends on an active plan — if the subscription lapses, the connection stops answering.

Ready-made questions

The assistant also receives a set of ready-made questions — in Claude they show up as slash commands, and you pick them, never the model. They save you from having to work out what is worth asking: prepare for a meeting with a client, close the week, "why did we decide that?", the state of a deliverable, "are we late?". With the personal layer you also get "what do I have today", and with write permission, "record a decision we just made".

The list respects what your connection reaches: a question the assistant could not answer with the scope you granted simply does not appear.

When new capabilities appear

The assistant caches the list of things it can do at the moment it connects. When Orion gains a capability, whoever was already connected keeps seeing the old list until reconnecting. Replies then carry a notice. To update it, remove the connector and add it again — reconnecting or starting a new conversation does not refresh the list: the assistant keeps the contract from the moment it was installed, and reconnecting only redoes the sign-in.

Where to paste it, in each assistant

The path differs per product and they change often. The summary below is the essentials; the complete, current instructions always live in each product's own documentation.

  • Claude — under Customize → Connectors, click + then Add custom connector, paste the address and click Next. Claude may say it "couldn't determine the server settings" — that is expected, carry on. Leave Authentication alone: Orion asks for the sign-in itself when you connect. Only choose None if you are using the key path, since the key already travels inside the address. On Team and Enterprise plans the organization owner adds it first (Organization Settings → Connectors → Add → Custom → Web); each person then connects their own. The free plan allows a single custom connector. Docs: Anthropic support.
  • ChatGPT — the feature lives in developer mode. Turn it on under Settings → Security and login → Developer mode (it warns about elevated risk: that is the mode that allows a not-yet-verified connector). Then open chatgpt.com/plugins, click + and paste the address into the URL field. For authentication choose OAuth; if you are on the key path, choose No authentication, since the key already travels in the address. The connector you create shows under Drafts, and that is where you switch individual tools on or off. Available on paid plans, on the web. Docs: OpenAI help centre.
  • Grok — open grok.com/connectors, click New Connector, choose Custom and enter the server address. Docs: xAI docs.

All three have a single address field. Signing in with your account, the address is short and holds no secret:

https://mcp.orionworkers.com/mcp

On the key path the key travels inside the address — and then treat it like a password: whoever holds that address reads your operation. If it leaks, revoke it in the panel and create another; it takes one click.

What it is actually good for

  • Prepare for a meeting without switching screens. "Before the Acme call: what have we agreed with them, what is still open, and what did we promise for this month?"
  • Write a proposal with the right history. The assistant already knows the price you charged, what was discussed and what was left out — you stop pasting context by hand.
  • Close the week. "Which deals are set to close this month and what do they add up to?" — the number comes from the same arithmetic the panel shows, not from an estimate.
  • Let nobody go cold. "Who should I have contacted and haven't?"
  • Answer an old question. "Why did we discount for this client back in June?" — the question no assistant without memory can answer.

Keep reading