Microsoft / Outlook — 365 · Exchange · Consumer
Outlook for Windows (classic + new), Outlook for Mac, Outlook on the web, Outlook mobile iOS + Android, Outlook consumer (outlook.com / live.com / hotmail.com), and on-premises Exchange 2016 / 2019 / 2022 — all supported via one add-in manifest.
Deployment: Centralized Deployment through the Microsoft 365 admin center for tenant-wide rollout, per-user sideload for pilots, or admin push via Exchange Admin Center → Add-ins for on-prem.
Identity: ADFS, SAML 2.0, OIDC — transparent. The add-in rides the user's already-authenticated mailbox session; we never broker tokens.
Google / Gmail — Workspace · Gmail · Consumer
Gmail on the web, Gmail mobile (iOS + Android), Gmail consumer (@gmail.com), and Google Workspace tenant-wide — one Workspace Add-on covers every surface by Google's design.
Deployment: Marketplace SDK for tenant-wide install (private to your Workspace), or per-user install for pilots.
Identity: Google SSO, Cloud Identity, hybrid AD — transparent. The add-on rides the user's Workspace session.
Deployment paths — pick the shape IT already runs
01 Per-user sideload. One user installs, one mailbox covered. Right for a pilot of under ten people. No tenant-wide policy change, no IT ticket queue — a single analyst can prove the cockpit in an hour.
02 Tenant-wide centralized deployment. IT admin pushes once; every mailbox in the tenant gets the add-in on next mail-client restart. Right for 10 to 25,000 mailbox single-tenant deployments. Never touches an end-user credential — rides the existing SAML, OIDC, or ADFS session.
03 MSSP per-customer rollout. One MSSP workspace, many client tenants. Per-tenant routing rules, verdict policy, and audit log. Right for managed-security providers serving SMB or mid-market clients across a region.
SIEM / SOAR + downstream response
Assessor verdicts, IOC promotions, and ZAP actions stream as webhook JSON to your SIEM / SOAR of choice. STIX / TAXII export is on the way for cross-vendor intel sharing (gated behind tenant approval).
The cockpit doesn't require anything downstream — but if you have Splunk, Sentinel, Chronicle, Elastic, or Cortex XSOAR, every event is available as structured JSON with the same schema as the on-screen breakdown.
