### Documentation

Get started

- [Surfaice documentation](/docs/ai)

- [What is Surfaice?](/docs/concepts/what-is-surfaice/ai)

- [Quickstart](/docs/quickstart/ai)

- [Start by role](/docs/guides/start-by-role/ai)

- [Sign in and SSO](/docs/guides/sign-in/ai)

Guides

- [Workspaces](/docs/guides/workspaces/ai)

- [Connectors](/docs/guides/connectors/ai)

- [Chat with Hugo](/docs/guides/chat-with-hugo/ai)

- [Skills](/docs/guides/skills/ai)

- [Working with Hugo](/docs/guides/working-with-hugo/ai)

- [Punch Walk Guide](/docs/guides/punch-walk/ai)

- [Lease abstraction](/docs/guides/lease-abstraction/ai)

Use cases

- [Use cases overview](/docs/use-cases/overview/ai)

- [Teams & personas](/docs/use-cases/by-team/ai)

- [Lease administration](/docs/use-cases/lease-administration/ai)

- [CAM reconciliation](/docs/use-cases/cam-reconciliation/ai)

- [Store development](/docs/use-cases/store-development/ai)

- [Construction & closeout](/docs/use-cases/construction-and-closeout/ai)

- [Portfolio & renewals](/docs/use-cases/portfolio-and-renewals/ai)

- [Operations & facilities](/docs/use-cases/operations/ai)

Skills library

- [Skills library](/docs/skills/ai)

- [Lease & portfolio skills](/docs/skills/lease-and-portfolio/ai)

- [Store development skills](/docs/skills/store-development/ai)

- [Estimating & bid skills](/docs/skills/estimating-and-bids/ai)

- [Reporting & briefing skills](/docs/skills/reporting/ai)

- [Apps & automations](/docs/skills/apps-and-automations/ai)

- [Workspace admin skills](/docs/skills/workspace-admin/ai)

Concepts & trust

- [Permissions](/docs/concepts/permissions/ai)

- [Data handling](/docs/concepts/data-handling/ai)

- [Agent limitations](/docs/concepts/hugo-limitations/ai)

- [Trust FAQ](/docs/concepts/trust-faq/ai)

- [Audit trail](/docs/concepts/audit-trail/ai)

Help

- [FAQ](/docs/faq/ai)

- [Release notes](/docs/release-notes/ai)

- [Security overview](/docs/security/ai)

- [Support](/docs/support/ai)

- [Status](https://status.surfaice.pro)

- [Security](/security/ai)

- [Open app](https://agent.surfaice.pro)

Get started

- [Surfaice documentation](/docs/ai)

- [What is Surfaice?](/docs/concepts/what-is-surfaice/ai)

- [Quickstart](/docs/quickstart/ai)

- [Start by role](/docs/guides/start-by-role/ai)

- [Sign in and SSO](/docs/guides/sign-in/ai)

Guides

- [Workspaces](/docs/guides/workspaces/ai)

- [Connectors](/docs/guides/connectors/ai)

- [Chat with Hugo](/docs/guides/chat-with-hugo/ai)

- [Skills](/docs/guides/skills/ai)

- [Working with Hugo](/docs/guides/working-with-hugo/ai)

- [Punch Walk Guide](/docs/guides/punch-walk/ai)

- [Lease abstraction](/docs/guides/lease-abstraction/ai)

Use cases

- [Use cases overview](/docs/use-cases/overview/ai)

- [Teams & personas](/docs/use-cases/by-team/ai)

- [Lease administration](/docs/use-cases/lease-administration/ai)

- [CAM reconciliation](/docs/use-cases/cam-reconciliation/ai)

- [Store development](/docs/use-cases/store-development/ai)

- [Construction & closeout](/docs/use-cases/construction-and-closeout/ai)

- [Portfolio & renewals](/docs/use-cases/portfolio-and-renewals/ai)

- [Operations & facilities](/docs/use-cases/operations/ai)

Skills library

- [Skills library](/docs/skills/ai)

- [Lease & portfolio skills](/docs/skills/lease-and-portfolio/ai)

- [Store development skills](/docs/skills/store-development/ai)

- [Estimating & bid skills](/docs/skills/estimating-and-bids/ai)

- [Reporting & briefing skills](/docs/skills/reporting/ai)

- [Apps & automations](/docs/skills/apps-and-automations/ai)

- [Workspace admin skills](/docs/skills/workspace-admin/ai)

Concepts & trust

- [Permissions](/docs/concepts/permissions/ai)

- [Data handling](/docs/concepts/data-handling/ai)

- [Agent limitations](/docs/concepts/hugo-limitations/ai)

- [Trust FAQ](/docs/concepts/trust-faq/ai)

- [Audit trail](/docs/concepts/audit-trail/ai)

Help

- [FAQ](/docs/faq/ai)

- [Release notes](/docs/release-notes/ai)

- [Security overview](/docs/security/ai)

- [Support](/docs/support/ai)

- [Status](https://status.surfaice.pro)

- [Security](/security/ai)

- [Open app](https://agent.surfaice.pro)

# Connectors

Connect Surfaice to systems of record with consent, role controls, and inherited permissions.

Connectors let Surfaice read (and, when you enable it, write back to) systems your team already uses. A **connector** is a consented link from your Surfaice workspace to one of those systems, Hugo then uses it under **your** permissions.

| Kind of system | Examples you may already run |

| --- | --- |

| Lease administration | Lucernex |

| Files / DMS | SharePoint, Google Drive |

| Email | Outlook (per-user mailbox) |

| Market / deals data | CoStar |

| Construction / projects | Procore, Smartsheet, Sitefolio |

| Facilities / work orders | ServiceChannel, FEXA |

Exact availability depends on your workspace configuration. New to Surfaice? Read [What is Surfaice?](/docs/concepts/what-is-surfaice/ai) first.

## Principles

### Nothing connects without consent

Administrators approve Surfaice in your Microsoft 365, Google Workspace, or other tenant. Each system of record follows the same rule: no silent tenant-wide grabs.

### Email is per user

Mailbox access is granted by the individual user to their own mailbox. There is no tenant-wide mailbox read. A user can only reach email they could already open themselves.

### Roles gate who even sees a connector

Connector availability is governed by role inside Surfaice. Roles that should not use a connector never see the option.

### Permissions are inherited, never expanded

A signed-in user sees exactly the data their existing role in Lucernex, SharePoint, or another system already grants. Surfaice does not grant new access.

### Exclusions apply across skills

Keywords, senders, domains, and folders can be excluded instance-wide (for example HR or legal topics). Those exclusions apply to every email-touching skill by default.

## Typical setup sequence

1. IT approves the application

Your identity / SaaS admins consent to Surfaice in the relevant tenant.

2. Surfaice roles are assigned

Only intended roles (for example lease admin) get connector entitlements.

3. Users connect their own accounts

Users complete OAuth for personal connectors such as Outlook.

4. Rollout stays staged

Connectors go live one at a time on explicit sign-off and can be revoked in your IdP at any time.

## What you should see in the app

1. Connectors settings

Each integration shows connected / not connected. OAuth connectors display the signed-in account email.

2. Consent screens

Microsoft or Google consent lists the exact permissions Surfaice requests, no broader than needed for lease and project workflows.

3. Role visibility

If you do not see Lucernex or Outlook at all, your Surfaice role may not include that connector, contact your admin.

## Related

- [Working with Hugo](/docs/guides/working-with-hugo/ai), access denied and connector troubleshooting

- [Permissions](/docs/concepts/permissions/ai)

- [Data handling](/docs/concepts/data-handling/ai)

- [Security overview](/docs/security/ai)

- [Workspaces Previous](/docs/guides/workspaces/ai)

- [Chat with Hugo Next](/docs/guides/chat-with-hugo/ai)