July 13th, 2026

You can now decide, per team member, exactly which tools can Ekkie use on their behalf and per Company which tools are available for Ekkie to execute.

The EkkieChat settings page is one place to grant access across all your managed companies at once. A mode switch at the top gives three views, each with the same layout — pick who you are changing on the left, choose what to grant on the right, and Apply it to everything selected in one action:
Permissions — grant the Microsoft permissions Ekkie's Enterprise Application needs, across all selected companies companies. Select the companies you want to overview, press ‘Load Permissions‘, it will pull all the permissions from all the Enterprise Applications of those companies, now either click on certain permissions form the list to add them to the ‘To Grant on Apply‘ list, all permissions from that list will be added to all the Enterprise Applications of those companies, or click on ‘Grant Permission‘ button to add a completly new permission to all Enterprise Applications, finally click Apply to N companies and, if you have the clearance they will be granted.

Company Tools — choose which tools are enabled for each company, and which require approval. Click on a Tool so see what is the minimal permissions set required for that tool to be usable by Ekkie, if not granted grant them in the ‘Permissions’ section.

User Tools — choose which tools are enabled for each support engineer, and which require approval.

Applying to many companies (or users) at once
The left panel lists your companies (in Permissions and Company Tools) or your engineers (in User Tools). Select any combination, use All, or search to narrow the list, a running count shows how many are selected.
Every permission or tool shows a coverage count, how many of the selected items already have it. Expand it to jump-select just the ones that have it or just the ones missing it, then apply only to those.


Apply pushes your choices to every selected company or user. Large rollouts run in the background.
Applies are patches, not replacements, only what you toggled is written, so each company and engineer keeps its own distinct settings. Granting is idempotent: anything already in place is skipped, so re-running is always safe.
Enterprise Application permissions

Ekkie performs Microsoft 365 actions on each customer through its own Enterprise Application installed in that customer's Microsoft tenant, which must hold the right Microsoft permissions there. In the Permissions view you:
Build the set of permissions to grant — type to search and pick a suggested match, use the permission picker, or click one from the coverage table. Each queued permission shows how many selected companies already have it.
Load Permissions scans the selected companies and shows what each already holds. Check my permissions probes, per company, whether you have the admin rights to change that tenant — shown as a status: Allowed, No permission (you lack the admin role there), Not consented (Ekkie was never set up in that tenant), Missing permissions, or Tenant not found.
Apply asks for confirmation (it writes directly into each customer's Microsoft tenant), then grants across the selected tenants; companies that share one Microsoft tenant are handled once. The results group anything needing attention by cause, each with a one-line fix — correct the tenant ID, open an admin-consent link, or ask a tenant admin for access.
Opening a single company shows every permission Ekkie currently holds there (each tagged with the tools that use it), where you can grant or revoke individual permissions.
Good to know: this grants permissions to an app that is already admin-consented in the tenant — it cannot create that first-time setup. Where Ekkie was never consented, open the provided consent link (a tenant admin completes it) first. Changing permissions requires a directory admin role (for example Global Administrator or Application Administrator) in the customer tenant; failures are isolated per company, so fix the flagged ones and re-run.
Tool access
Tools are listed by product category (Entra ID, Exchange Online, Defender, Intune, Teams, Autotask, Ekkie, Web Search), each collapsible with All / Read Only / None shortcuts.
Each tool shows a Type badge — read (does not change the tenant) or write — an Enabled switch, an Approval switch, and its minimum required Microsoft permissions.
The switches are coverage-aware across your selection (all, none, or some of the selected have it), and toggling one sets the target for every selected company or user at once.
Turning on a tool that makes changes (a write tool) switches on its approval requirement by default. Approval can only be set on an enabled tool.
Microsoft documentation-search tools are always available to Ekkie and don't appear in the list. Changes take effect for new conversations shortly after you apply them.
How company and user tool settings combine
Tool access is set in two places, per company and per engineer, and the two combine for each conversation:
Available = both must agree. A tool can be used in a conversation only if it is enabled for both that company and that engineer. Enabling it for a person does not grant it in a company where it is off, and vice versa.
Approval = either can require it. A tool requires approval in a conversation if either the company or the engineer marks it as requiring approval (in addition to the always-approval tools above). Approval only ever applies to tools that are actually available.
Good to know: because availability is the overlap of the two, a tool can look enabled in one view but still not work if the other view has it off, the combined result is not shown on this page. Managing User Tools requires the Users Management role. A company or engineer that has never been configured starts with nothing enabled;