Skip to main content
This guide is for Microsoft 365 and Teams administrators who are evaluating or rolling out the SeekOut agent for Microsoft 365 Copilot. It covers what the agent does, what it requires, why your data stays in your tenant, how to deploy it to your organization, and how to drive adoption after rollout. If you are an individual user who just wants to start using the agent, see Connect SeekOut to M365 Copilot Agent instead.

About the agent

The agent brings SeekOut’s talent intelligence into Microsoft 365 Copilot. Recruiters, sourcers, and hiring teams can source candidates across SeekOut’s public, GitHub, healthcare, nursing, and academic talent pools plus their own ATS pipeline and internal employees; build shortlists, compare markets, discover companies, retrieve contact information, save candidates to workspaces, export to a connected ATS, and draft outreach.

Requirements

Each person who uses the agent needs all of the following:
  • A Microsoft 365 Copilot license.
  • An active SeekOut account. The agent has no anonymous or trial mode — a user without a SeekOut seat cannot use it.
  • Whatever SeekOut entitlements the task requires. Every action runs against the user’s own SeekOut account and is limited to what that user is already permitted to do in SeekOut.
Two SeekOut features depend on configuration on the SeekOut side rather than anything you do in Microsoft 365:
  • ATS pipeline search and ATS export require a connected ATS in your SeekOut account.
  • Internal-employee search requires your organization’s employee data to be uploaded to SeekOut.
When one of these is not enabled, the agent says so and continues with what is available. Contact your SeekOut account team to turn either on.
“Capability” is a Microsoft term with a specific meaning for declarative agents — see Capabilities currently declared. The two SeekOut features above are account configuration, not Microsoft 365 Copilot capabilities.

Your data stays in your tenant

This is the section to hand to a security reviewer. Every claim below is sourced to Microsoft’s own documentation, not to SeekOut’s description of itself, so it can be verified independently. The short version: SeekOut’s MCP server has no access to your tenant. Your users call out to SeekOut; SeekOut never reaches in.

Where each part runs

The SeekOut agent is a declarative agent, and that architecture is what answers most security questions about it. Microsoft’s model splits it in two: Everything in the first two rows stays inside Microsoft’s boundary, on Microsoft’s infrastructure, under your user’s own permissions. Only the third row leaves — and it leaves because your user asked it to. So capabilities never hand SeekOut anything. SeekOut does not implement a capability, does not receive its inputs, and does not see its output. That holds as the agent declares more of them: a capability extends what Copilot can do for your user, not what SeekOut can see.

SeekOut has no access to your Microsoft Entra tenant

SeekOut holds no Microsoft Entra app registration in your tenant. The app package requests no Microsoft Graph permissions, declares no webApplicationInfo, and creates no admin consent to grant — which is why you will not find a SeekOut enterprise application in your directory. The only identity SeekOut sees is the SeekOut account the user signs in to over OAuth on first tool use. SeekOut authenticates that user against SeekOut’s own directory and authorizes them with their own SeekOut entitlements. It never authenticates against, queries, or reads Microsoft Entra ID, and it cannot enumerate your users, groups, or directory objects. Grounding on Microsoft 365 content — SharePoint, OneDrive, mail, chats, Copilot connectors — is a Microsoft-side concern under Copilot’s own permission model, in which “Copilot only surfaces organizational data to which individual users have at least view permissions” and the Semantic Index “honors the user identity-based access boundary so that the grounding process only accesses content that the current user is authorized to access” (Microsoft). If the agent later declares a knowledge capability, that grounding still happens inside Copilot under your user’s permissions. It does not become a SeekOut data feed.

The direction of every call

SeekOut requests nothing from your tenant. SeekOut’s MCP server has no way to query, browse, or pull your Microsoft 365 data. It receives only what Copilot sends it, and it cannot ask for more. Copilot decides what that is, inside your tenant: “If an agent is needed, Microsoft 365 Copilot generates a search query to send to the agent on the user’s behalf. The query is based on the user’s prompt, Copilot activity history, and data the user has access to in Microsoft 365” (Microsoft). That composition happens entirely within Microsoft’s boundary, on your user’s behalf, from data that user is already entitled to. Your data governance, your user permissions, and your admin controls determine it — nothing on the SeekOut side does.

Verify it yourself

What SeekOut does with what you send

The sections above cover your side of the boundary. This is ours — the request Copilot sends us, and the response we return. Data returned from SeekOut becomes part of the Copilot conversation and is retained under your Microsoft 365 Copilot settings, so review those alongside this rollout — the two halves are governed separately, and Microsoft recommends checking an agent’s privacy statement and terms of use before enabling it (Microsoft).

Before you deploy

Authentication

The agent uses OAuth 2.0 authorization code flow against SeekOut. The first time a user invokes a SeekOut tool, Copilot prompts them to sign in to SeekOut and authorize the connection. There is no tenant-wide service credential and no admin consent step in SeekOut — authorization is per user, and each user acts as themselves. You control who can reach the agent using Microsoft 365 agent management; SeekOut controls what each authorized user can then do, using that user’s existing SeekOut permissions.

Network

The agent calls these SeekOut hosts over TLS on port 443. Allow them if your organization restricts outbound traffic:

Capabilities currently declared

This list will grow. Adding a capability changes what Copilot can do for the user inside Microsoft’s boundary; per the table above, it does not widen SeekOut’s access. Admins can review the current capability set for the installed version in the Microsoft 365 admin center at any time.

Usage limits

SeekOut enforces rate limits per user, not per organization. Defaults are 1,000 requests per day and 10 requests per second for each user, and SeekOut can adjust an individual user’s limits on request. See Usage limits.

Deploy the agent

1

Find SeekOut in the Microsoft 365 admin center

Sign in to the Microsoft 365 admin center and open the agent management area (Agents & connectors). SeekOut appears as an external partner agent.
2

Review the agent

Check the publisher, description, and permissions against your organization’s requirements, using the data-flow and authentication details above. Microsoft’s Manage agents in the Microsoft 365 admin center describes the review, availability, and blocking controls in detail.
3

Make it available to the right people

Allow the agent for your whole organization, or scope it to the specific users or groups who hold SeekOut seats. Scoping to your recruiting and talent teams is usually the better starting point, because everyone else would be blocked at the SeekOut sign-in step anyway.
4

Confirm licensing overlap

Verify that the users you granted access to have both a Microsoft 365 Copilot license and a SeekOut seat. A mismatch is the most common cause of rollout support tickets.
5

Pilot before broad rollout

Start with a small group of recruiters. Have each of them complete the first-use SeekOut sign-in and run a real search, so you surface any conditional-access or network issues before a wider release.
Users find and open the agent from the Agent Store in the Microsoft 365 Copilot app. If a user reports that the Add button is unavailable, the agent has not yet been allowed for that user in the admin center.

Drive adoption

Once the agent is available, three things account for most of the difference between a successful rollout and a quiet one.
1

Tell users to open the agent, not just chat

A regular Microsoft 365 Copilot chat does not use SeekOut on its own. Users must open the SeekOut agent from Agents → More agents, or invoke it with @SeekOut from another conversation. This is the single most common point of confusion after rollout.
2

Tell users to select "Think deeper"

The agent is built for the Think deeper response mode. Auto can produce unreliable answers. Include this in your rollout note.
3

Give people a first prompt

Sourcing questions work best when they are specific. Share a few starting points:

Find senior backend engineers in Seattle with Python and distributed systems experience.

Compare the talent market for senior backend engineers across Seattle, Austin, and New York.

Build a talent dashboard for Principal ML Engineers.

For more, see Prompting patterns and Workflows.

Manage access after rollout

  • Remove access for a user or group: change the agent’s availability in the Microsoft 365 admin center.
  • Block the agent for the organization: block it in the admin center. This stops access at the Microsoft 365 layer.
  • Revoke a SeekOut session: a SeekOut administrator can revoke a user’s MCP session from the SeekOut admin console. See Security overview.
  • Remove the SeekOut seat: without an active SeekOut account, the agent cannot return data for that user, regardless of Microsoft 365 access.

Troubleshooting

The Add button for the SeekOut agent is unavailable

The agent has not been allowed for that user. Allow it in the Microsoft 365 admin center, scoped to that user or their group, then have them try again.

Users can open the agent but every request fails at sign-in

The user does not have an active SeekOut account, or their SeekOut account is disabled. Confirm the seat with your SeekOut account team.

A SeekOut feature reports that access is not enabled

ATS functions need a connected ATS in your SeekOut account, and internal-employee search needs uploaded employee data. Both are configured on the SeekOut side.

Answers are unreliable or incorrect

Confirm the user selected Think deeper rather than Auto.

Sign-in or tool calls time out

Check that seekout-search-mcp.seekout.io and app.seekout.io are reachable over TLS on port 443 from your users’ network, and that no conditional-access or proxy rule is blocking the OAuth redirect. For anything else, see Troubleshooting and FAQ.

Get help

Contact SeekOut Support at [email protected] or your SeekOut account team. Include your organization name, the affected user, and what the agent returned.