Several SharePoint sites across two Microsoft tenants reaching a single AI assistant
Last updated on

How to Connect Multiple SharePoint Sites to Grok Bot

One Grok Bot session can reach SharePoint sites across more than one Microsoft tenant, through Carly. Sites inside a single tenant come along with the account you sign in as, because SharePoint access is a property of your account rather than of each site. The second tenant is the part that needs Carly. Carly holds your Gmail and Outlook mailboxes, both sets of calendars and your drives in the same place.

The problem you might have is two tenants. That one is real, it is where the shared browser starts to hurt, and xAI does not document it either way.

Five sites in one tenant is not a multi-account problem

SharePoint does not hand out per-site connections. Your work account carries whatever site permissions it has been granted, and anything you can open in a browser tab, a signed-in agent can open in the same tab. xAI’s SharePoint documentation for the consumer Grok product uses exactly this framing when it describes searching “across all SharePoint sites you have access to”. Access is the unit, not the site.

So: sign the Bot’s browser into your work account once, and every site that account can see comes with it. Adding a sixth site later needs nothing done on the Grok Bot side. If the Bot reaches one site in your tenant and not another, that is a permissions question for whoever owns the second site, and no assistant setting will fix it.

A consultant with their own tenant plus two client tenants, or anyone mid-merger, is asking a different question. The rest of this page is for them.

A plugin, an invocation surface and a trigger are three different things

This is why hunting for “SharePoint” in Grok Bot’s settings keeps producing near-misses. Grok Bot inherits Cursor’s integration model, and that model has three tiers that are easy to confuse:

TierWhat it grantsWhere the list lives
PluginActual data access, read and write toolsCursor’s plugin marketplace, shown as Plugins in Grok Bot
Account integrationInvocation, meaning you summon an agent from that appCursor’s integrations documentation
Trigger sourceAn event that starts a run on its ownCursor’s automations documentation, shorter than the tier above

SharePoint appears on none of the three.

The account-integration tier is the one that misleads, because Microsoft Teams is on it, and a Microsoft surface on a Microsoft-shaped list looks promising. Read what it does. Cursor’s documentation says the Teams integration lets you “use Cloud Agents to work on tasks directly from Microsoft Teams by mentioning @Cursor with a prompt”, and its setup steps ask you to connect GitHub, GitLab, Azure DevOps or Bitbucket as a repository provider. The object is repository-shaped. It reads nothing in Teams, let alone in SharePoint.

So even if SharePoint joined that list tomorrow, it would be a doorbell, not a drive: a way to summon an agent from a SharePoint page, not a way for it to read your libraries.

What the plugin catalogue actually contains

Grok Bot’s connectors appear as Plugins, drawn from Cursor’s marketplace and published out of Cursor’s public plugins repository. That repository is enumerable rather than merely searchable, which makes this negative unusually solid. Its first-party plugin directory holds exactly eighteen entries: Apollo, Ashby, Circleback, Clay, DocuSign, GitHub, Gmail, Gong, Google Calendar, Google Drive, HubSpot, Intercom, Navan, Playwright, Profound, Salesforce, X and Zoom. The listing is not truncated. No SharePoint, no OneDrive, no Outlook.

The obvious summary of that list is wrong in both directions. Microsoft is not absent from the marketplace, since it publishes an Azure plugin and a Microsoft Dataverse plugin under its own name, which makes the asymmetry sharper rather than softer: Microsoft ships plugins for coding agents and ships nothing that reaches M365 content. Cloud storage is not absent either, because Box is there as a verified publisher. What is missing is specifically Microsoft storage and M365 content, and across the third-party listing SharePoint does not appear once.

The contrast with xAI’s other product is instructive, because Grok on grok.com has the per-site control you want here. In application-permission mode, xAI says the console “displays a site picker after consent is granted”, an admin adds each site to an allow list, and “only sites added here will be reachable through the connector”. It is also marked available on Grok Business and Enterprise plans only, needs an Azure AD tenant ID, and needs a Microsoft 365 administrator to consent for the whole organization. None of that exists in Grok Bot, which uses Cursor authentication and shares no connector catalogue with grok.com.

Sort your case

Your situationThe honest answerHow solid is it
Several sites in one tenantAlready covered by one sign-in, nothing to configureDocumented in Microsoft’s access model
You want a native SharePoint pluginNone exists, for one site or twentyVerified against Cursor’s own plugin repository
You want the Bot to open SharePoint in its browserWorks, and it is the only file path with no pluginDocumented
Two tenants held apart inside Grok BotNot possible, sessions are shared across Bots by designDocumented as not separable
Two live Microsoft sessions at the same timexAI does not document this either wayUndocumented, so test it
A routine that fires when a document landsNo storage event exists in either documentation setVerified absent
Your own MCP server for SharePointTeam policy implies members may add serversInferred, and the flow is undocumented

Two tenants is the hard case, and the browser is shared

xAI’s own wording is blunter than the marketing. Every Bot on your account works on one cloud computer. The documentation states that “the computer is assigned to your user account, not an individual Bot”, that “because the browser is shared, signing in for one Bot makes the session available to your other Bots”, and that each Bot’s screen gives “separate work surfaces, not separate security boundaries”. Installed plugins follow the same rule, being account-wide and “not isolated to one Bot”.

A Bot can therefore reach a second tenant by signing into it, but no documented way exists to tell one instruction which tenant it means. Whether the browser holds two live Microsoft sessions at once is undocumented, which is not the same as documented as impossible. The ordinary fix is a separate browser profile per tenant, and you cannot do that here, because you do not own the Bot’s browser profile, you take over its one shared browser.

Expect friction even when it works. xAI lists four situations where the Bot stops and hands control back: a password or passkey, two-factor authentication, a CAPTCHA, and a payment or identity check. A Microsoft 365 sign-in wall routinely hits three of the four. xAI’s own caveat covers the rest: Grok Bot “can use many browser-based tools, including services without a dedicated connector”, but “a site may still block automation, require a new login, present a CAPTCHA, or require human confirmation”.

What Grok Bot can actually do with a SharePoint document

ActionGrok Bot and SharePointStatus
Search across sitesNo documented tool, only the SharePoint web UI in the Bot’s browserNot documented
Browse a librarySame, browser-driven onlyNot documented
Read a documentBrowser, or attach the file to the chatAttaching is documented
Create, update, delete, upload, shareNo documented tool, browser-driven onlyNot documented
Work in the shared workspaceFiles land in /workspace on the cloud computer, not in SharePointDocumented

That last row catches people out. The Bot has a real filesystem and real file handling, and none of it is your document library. Anything it produces stays on its own machine unless you move it.

Two documented paths work reliably.

Attach the file. xAI’s files documentation lists Word, Excel and PowerPoint files, PDFs, CSV, JSON, YAML, source code, HTML, email files and Jupyter notebooks. The desktop composer “accepts up to six attachments at a time”, with documents, images and audio up to 25 MB each. It sidesteps the connector question completely, and behaves identically for a document from your own site and one from a client’s, which makes it the one path that is genuinely tenant-agnostic.

Paste a share link. xAI says to paste a link “when the Bot can access the page from its computer or a connector”, and that if the page is private you sign in through the computer or install the relevant connector. For SharePoint there is nothing to install, so signing in through the computer is the whole route. A link scoped to people in one organization fails for a session signed into a different one, which is worth knowing before you conclude the Bot is broken.

Nothing fires when a document library changes

Two things can start a Grok Bot routine: a schedule, or an event from a Cursor account integration where one is supported. That covers Slack and GitHub notifications well. It does not cover the ordinary business events, such as a record changing in a CRM or a file landing in shared storage, that people most often want to automate.

The vocabulary is bounded by Cursor’s integrations, and xAI names only two examples: a Slack message and a GitHub notification. Cursor’s automations documentation goes further, grouping triggers into schedules, source control events from GitHub, GitLab and Bitbucket Cloud, Slack events, webhooks, Linear, Sentry and PagerDuty. Treat that longer list as Cursor-side rather than as a promise about Grok Bot routines, since xAI documents only the two.

Either way the SharePoint answer is the same. No file-created, file-modified or library event exists anywhere in either documentation set, and Microsoft Teams, which does at least appear as an account integration, has no trigger rows at all. The troubleshooting guidance gives the game away: for an event-triggered routine it tells you to confirm “the source channel, repository, and matching rule are still valid”. The vocabulary is literally channels and repositories.

Starting on an event rather than only on a clock is a real step past assistants that can only schedule. It just does not extend to documents.

1. Consolidate inside your own tenant with shortcuts

This is the path when the extra sites belong to your own organization.

  1. Open the SharePoint site and go to the document library you need.
  2. Choose Add shortcut to OneDrive, or select a single folder and use Add shortcut to My files.
  3. Repeat for each library, so one signed-in account sees everything in one place.
  4. Ask the Bot to open OneDrive rather than hopping between site URLs.

Microsoft prefers this route. Its sync documentation says you can either “add shortcuts to libraries and folders to OneDrive or use the Sync button in the document library”, and recommends “using OneDrive shortcuts as the more versatile option when available”. Shortcuts also cost nothing in storage: shared folders added this way “do not use any of your OneDrive storage space” and count against the owner’s instead. Three documented limits apply. Up to 100 folder shortcuts from a single person’s OneDrive or Teams site, up to 1,000 shortcuts across files and folders, and only shared folders rather than individual shared files.

2. Cross tenants with guest access instead

Here is the fork, and the two halves are mutually exclusive. Microsoft is explicit that the shortcut route stops at your organization’s edge: “the procedures in this article are available only to internal users”, and “you can’t add shortcuts to folders that are shared with external users”. For a client’s site, shortcuts are not the answer.

Guest access is. Microsoft’s external sharing overview says external sharing can be used “to share between licensed users on multiple Microsoft 365 subscriptions”, and its Entra B2B documentation covers sharing “files, folders, list items, document libraries, and sites with external people”. Invited guests “each get an account in the directory and are subject to Microsoft Entra ID access policies such as multifactor authentication”, and the one-time passcode path applies only to people who do not already have a work or school account.

  1. Ask the other organization to invite your work address to the site as a guest.
  2. Redeem the invitation once in a browser you control.
  3. Have the Bot open the site URL and confirm it resolves under your existing identity.
  4. Expect a multifactor prompt, and be ready to take over the computer for that step.

That is the structural advantage: guest access makes the second tenant’s sites reachable under the identity the Bot is already signed into, rather than asking one browser to hold two tenants. Whether redemption and the ongoing session survive cleanly inside a shared agent browser is not documented by either vendor, so test it on a site you do not care about first.

One timing note, because this changed recently. Microsoft states that starting May 2026 it enables SharePoint and OneDrive integration with Entra B2B for all tenants regardless of the previous setting, and that “the ability to disable the integration is removed”. Guidance written before that is out of date, and Microsoft warns that external users holding older one-time passcode links may hit an access error and need the content reshared.

If you would rather bring SharePoint to an agent as tools instead of as web pages, our SharePoint MCP page covers that route. On a team plan it may not be your call: xAI says Grok Bot “follows your team’s existing Cursor plugin and MCP policy” with “no separate Grok Bot plugin controls”, and a Cursor admin can disable MCP for everyone.

Connect every account to Carly

  1. Sign in at carlyassistant.com.
  2. Open carlyassistant.com/integrations.
  3. Find SharePoint and click Connect.
  4. Authorize the first Microsoft identity and confirm the address.
  5. Click Connect again for the next one, signing out of the preselected Microsoft session first so the right account is used.
  6. Repeat until every account appears in the connected list.

Each one is its own authorized connection, so your own tenant and two client tenants stay three separately addressable things rather than shared sessions on one machine.

Add Carly to Grok Bot

  1. Select Plugins in the Grok Bot sidebar, or tap your avatar and choose Plugins on mobile.
  2. Add Carly’s remote MCP server, https://carlyassistant.com/mcp/.
  3. Finish the authorization in the browser tab that opens. If it sits on Waiting for authorization, use Reopen.
  4. Sign in to the Carly account holding the connections above.
  5. Confirm Carly appears under Installed.

Grok Bot takes remote MCP servers rather than local ones, and Carly’s is hosted, so it qualifies. Plugin connections belong to your Grok Bot account rather than an individual Bot, and team plans inherit Cursor’s MCP policy, so an admin can gate it.

Then name the target in every instruction, so the account being acted in is explicit rather than whichever session happens to be live.

Grok Bot versus Carly on SharePoint

NeedGrok BotCarly
Reach many sites in one tenantYes, through one browser sign-inYes
A native SharePoint connectionNone existsYes
Hold two tenants as separate identitiesNo, sessions are shared across BotsYes, each authorized on its own
Address one specific site in an instructionNo routing existsYes, by name
Read a document without a connectorYes, attach it or drive the browserYes, through the connected account
Start work on an event, not just a clockYes, but Slack and GitHub shapedYes, on mail and calendar events
Long-running work after you close the laptopYes, on its persistent cloud computerRuns server-side

Give Grok Bot its due. A persistent cloud computer with a real browser is a genuinely different capability, and it is why the Bot can work in a SharePoint site with no connector in existence. For a one-off job on documents you can attach it is a strong tool, and its documentation is more honest about the shared-machine trade-off than most vendors manage.

Carly answers the other shape of the problem. SharePoint is a native connection, and each Microsoft identity is authorized separately, so your own tenant and two client tenants stay three addressable things rather than three cookies in one browser. You name the tenant and the work goes there. Documents are reachable as documents, not as a page someone has to be signed into, and workflows start when something arrives rather than when a clock says so.

Free Zapier-style workflows; AI agents from $35/month. Start with SharePoint or the full integrations page.

Quick fixes

ProblemWhat to do
You cannot find SharePoint in PluginsIt is not there; the catalogue has no Microsoft storage or M365 content plugin
You followed a Grok SharePoint setup guide and nothing matchedThat guide is for grok.com, a separate product with admin consent and a Business or Enterprise plan
The Bot sees one site in your tenant but not anotherA SharePoint permissions issue on that site, not a Grok Bot setting
The Bot cannot open a share linkThe page is private or scoped to another organization, so sign in through the Bot’s browser
Add shortcut to My files is unavailable for a client’s folderShortcuts are internal-only; use a guest invitation to that site instead
A second Microsoft sign-in appears to displace the firstUndocumented behaviour, so consolidate on the Microsoft side rather than relying on it
Plugins are greyed out or say disabled by team adminGrok Bot inherits Cursor’s plugin and MCP policy, so ask your admin
Grok Bot is missing from your app entirelyAccess needs SuperGrok Heavy, Cursor Ultra, Cursor Teams Premium or a trial, Privacy Mode (Legacy) blocks it, and there is no Linux desktop app

Frequently asked questions

Does Grok Bot have a SharePoint connector?

No. Cursor’s public plugin repository, which is what the Plugins screen draws on, lists eighteen first-party plugins and none is SharePoint, OneDrive or Outlook. Microsoft’s own published plugins there cover Azure and Dataverse rather than M365 content.

Do I need to do anything special for five sites in one tenant?

No, and that is the useful part. SharePoint permissions belong to your account rather than to each site, so one signed-in work account in the Bot’s browser reaches every site that account can open, and adding another later needs nothing done in Grok Bot.

Can Grok Bot reach a client’s SharePoint in a different tenant?

Only through the browser, and the clean route is a guest invitation, which Microsoft documents for sites and document libraries through Entra B2B. That makes the client’s site reachable under your existing identity rather than needing a second Microsoft session. Whether one shared agent browser holds two tenants at once is not documented either way.

Can a Grok Bot routine start when a document lands in a library?

No. Routines run on a schedule or, where supported, on an event from a Cursor integration, and xAI names only a Slack message and a GitHub notification. No file or library event exists in either documentation set.

What is the most reliable way to get a SharePoint document into Grok Bot today?

Attach it. Word, Excel, PowerPoint, PDF and CSV are supported, up to six attachments at a time in the desktop composer and 25 MB each, and it behaves identically whichever tenant the document came from.


Related: What Grok Bot does · Multiple OneDrive accounts in Grok Bot · Multiple Outlook accounts in Grok Bot · Best AI assistants for SharePoint · Best AI assistants for multiple Microsoft accounts · Carly’s SharePoint integration

Ready to automate your busywork?

Carly schedules, researches, and briefs you—so you can focus on what matters.

See what people say

"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.

Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.

On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."

Gus Ibrahim, Founder & Director, IHR