Skip to main content
The SuperOffice integration app SuperOffice Document Library needs permissions to integrate SuperOffice CRM Online with your SharePoint site. To enable the system user, a Microsoft 365 Global Administrator who is also Owner of the selected site must sign in once. SharePoint Administrator isn’t sufficient. In that one-time sign-in, the administrator:
  1. Approves the app in the tenant.
  2. Gives the app read and write access to the selected site only (Sites.Selected).
After this, the app can read, write, and delete documents, set permissions on them, and create documents as a system user (a non-existing SharePoint user). All of this is limited to the selected site. No signed-in user is needed.

Types of permission

  • Delegated: the app acts on behalf of the signed-in user, with that user’s rights.
  • Application: the app acts as itself, without a signed-in user.
Sites.Selected exists only as an Application permission. To give the app access to one specific site, SharePoint requires a user token with the delegated scope Sites.FullControl.All. That’s why a Global Administrator must sign in once. The delegated token is used only for this setup step.

What we use the scopes for

Delegated permissions (Global Administrator, one-time setup)

SuperOffice doesn’t store tokens for User.Read and Sites.FullControl.All. You may remove these 2 delegated scopes after setup.

Application permission (SuperOffice Document Library, ongoing)

This permission is stored and used continuously. Don’t remove Sites.Selected, or features that depend on the system user stop working.

Steps and required roles

If you aren’t a Global Administrator, copy the authorization link from the wizard and send it to someone who is. If your tenant doesn’t allow users to approve apps themselves, other users see Need admin approval until a Global Administrator has approved the app. For the full list of roles needed for setup, see Requirements.