This page is for technical evaluators. The product pages stay marketing-led; the integration specifics live here so they’re easy to update as Microsoft’s APIs evolve.
Metadata Bot — integration
Reads and writes SharePoint managed metadata (column values, term sets) across a tenant.
Microsoft surfaces
- SharePoint Online REST + CSOM — read/write managed metadata, retrieve term sets
- Microsoft Graph —
driveItemfile operations, taxonomy reads - Webhooks — real-time tag/untag, within SharePoint’s 5-second response deadline
- Optional AI providers — OpenAI, OpenRouter, Azure Computer Vision (OCR)
What AutoTag needs access to
- Read your term store and taxonomy
- Read and write managed metadata across sites, including record-classifying writes
- Tenant-admin consent, so it can discover and work across site collections
- Your own AI provider key (OpenAI, OpenRouter, or Azure) — you supply and control it
Supported content
Every SharePoint column type. Any file format — Office, PDF, images (via OCR), plain text. SharePoint Online and SharePoint Server (Subscription Edition, 2019, 2016, 2013).
Governance Bot — integration
Orchestrates Microsoft’s sensitivity and retention labelling at scale — backfill, drift detection, and container governance across tenants. AutoTag drives Microsoft’s native labelling; it does not replace Purview classification.
File-level sensitivity & retention labels — Available now
What it does
- Applies sensitivity and retention labels to files, individually or as a large backfill
- Reads the labels already on a file before deciding whether to act
- Applies retention labels in bulk across lists and libraries
What AutoTag needs access to
- Read existing sensitivity and retention labels on files
- Apply sensitivity and retention labels to files
- Elevated site access where a retention label classifies content as a record
All granted as standard app permissions — no admin needs to stay signed in.
Cost
Applying a sensitivity label is metered by Microsoft at $0.00185 USD per file (SharePoint/OneDrive). AutoTag enforces dry-run cost estimation and a per-run budget cap before any metered write.
Honest constraints
- Office clients do not apply headers, footers, or watermarks from at-rest stored labels — that’s client-side application only
- Signed PDFs are not supported
- Reading label info doesn’t work for files using custom permissions or DKE (Double Key Encryption)
Drift detection — Available now (report-only)
What it does
- Scans content across sites to see which label each item actually carries
- Cross-checks Microsoft’s own oversharing and sensitive-site reports at scale
- Reports where the labels in place diverge from your policy
One-click remediation of detected drift is on the roadmap.
Container governance — Phase 2
What it does
- Sets default sensitivity labels and sharing rules at the site level
- Applies labels to Microsoft 365 Groups and the Teams connected to them
What AutoTag needs access to
- SharePoint admin rights to set site-level labels and sharing defaults
- Permission to update labels on Microsoft 365 Groups and Teams
- An Entra ID P1 license (minimum) in the tenant
Setting labels on Groups and Teams is the one area Microsoft requires a signed-in admin rather than a background app — so AutoTag runs these through its delegated-admin mode, with the admin consenting once.
Honest constraint
Microsoft routes Teams governance through the underlying group/site, not a Teams API. AutoTag includes a delegated-admin mode to perform these writes, but Teams’ own apps and tools are explicitly not a target.
Channel sites & adjacent workloads (Phase 3)
- Discovery: extends current Bot site/list/library discovery to recognise channel sites as a distinct site class
- APIs: shared with the file-level and container pillars
- Honest constraint: AutoTag does NOT promise independent container labelling for private/shared channels. Microsoft’s inheritance model overrides
Deployment & data residency
- AutoTag deploys directly inside your Microsoft 365 tenancy
- Your data does not leave your tenant
- JFDI Consulting does not access your data at any point
- Supported authentication: Entra-managed app registration with the permissions listed above
Works with every modern SharePoint
Ready to put metadata on autopilot?
Talk to JFDI about deploying AutoTag in your tenancy.



