Someone at your company has asked you to approve Pursor.
Pursor reads the email of people who choose to connect it. Then once a week, Pursor gives the user a summary of their potential financial commitments in discussion. After the user edits, deletes and / or approves via a simple email reply, Pursor aggregates all similar commitments and presents the CEO, CFO and controller with future cash requirements, so they can be carefully planned and managed much earlier than when these would normally hit the accounting systems.
Less email back and forth, less administrative coordination, less follow-up. Significantly better cashflow visibility.
Microsoft requires an administrator to approve any application that reads mail. That approval is what this page is asking for. It takes one click, and everything you are approving is set out below in Microsoft’s own words.
The four permissions
Mail.ReadRead user maildelegatedMicrosoft: “Allows the app to read the signed-in user’s mailbox.”
This is the product. Pursor reads the mailbox of each person who connects, looking for commitments the business has made that finance does not know about yet.
Mail.SendSend mail as a userdelegatedMicrosoft: “Allows the app to send mail as users in the organization.”
Two emails a week, and only ever to the people who have connected: a short list of questions to confirm, and a Monday summary. Nothing is sent to anyone outside your organisation.
That description deserves a straight answer. Microsoft’s wording for the tenant-wide grant says “as users in the organization,” which sounds broader than what happens. Because the permission is delegated, Pursor can only send as someone who has personally connected their own account — never as anyone else. If nobody connects, this permission does nothing at all. We are removing it entirely once our own sending domain is live.
User.ReadSign in and read user profiledelegatedMicrosoft: “Allows users to sign-in to the app, and allows the app to read the profile of signed-in users.”
Name and email address, so we know who connected.
offline_accessMaintain access to data you have given it access todelegatedMicrosoft: “Allows the app to see and update the data you gave it access to, even when users are not currently using the app.”
Lets Pursor keep working after someone closes their browser. Without it we would lose access an hour after each sign-in.
What this does not grant
- No application permissions. Every permission above is delegated, which means it only works on behalf of a person who has personally signed in and consented. Approving this does not give Pursor access to a single mailbox on its own.
- No access to mailboxes of people who have not connected. We removed Mail.Read.Shared for exactly this reason — we cannot read a mailbox that has not been individually connected.
- No files, no SharePoint, no OneDrive, no Teams, no calendars, no contacts, no directory. We ask for four permissions and this is all of them.
- No mail is ever sent to anyone outside your organisation, and nothing is deleted, moved, or modified in any mailbox.
After you approve
Nothing happens on its own. Each person who wants to use Pursor still signs in themselves and grants access to their own mailbox, and each of them can disconnect at any time without involving you. You can revoke this approval for the whole organisation whenever you like, under Enterprise applications → Pursor → Permissions in the Microsoft Entra admin center.
You will be taken to Microsoft, signed in as an administrator, and shown this same list before anything is granted.
Questions before you approve? Reply to whoever sent you this link — it goes to a person, not a support queue.