Microsoft Copilot security directory

Envoy

Published by Envoy, Inc.

Medium risk

An Envoy connector that allows you to be able to connect your Envoy account (our REST API endpoints) to any other connectors. An example would be to create bulk invites in Envoy with details from a Microsoft Excel Online spreadsheet.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 11 tools or capabilities.

  • Add blocklist filter
  • Create Invites
  • Get blocklist filters
  • Get company info
  • Get flows
  • Get invites
  • Get list of employees
  • Get locations
  • Get one Entry
  • Get one Invite
  • Update one Invite

The interactive security report will load automatically.