dpow.app for your IT team
One page for the IT administrator asked to approve dpow.app.
dpow.app is design management software for construction, from DPOW Group Ltd (company number 17276695, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ). It builds and keeps a project's information register, programme, RFIs and reports, and files documents into your own SharePoint.
Approve dpow for your organisation
This opens Microsoft's own approval screen for the whole organisation, so nobody on your team sees a "Need admin approval" message when they sign in. Only a Global Administrator or Cloud Application Administrator can approve. The dpow application (client) id is 2fd62e33-471c-4f9d-98eb-444762c668b7.
In short
- Delegated permissions only. dpow acts as the signed in person only. It never has app only access across your tenant, and it can never do more than that person's own Microsoft account can do.
- Your files stay in your SharePoint, with the few exceptions listed below. dpow fetches a file when someone asks for it.
- AI only reads what a user asks it to, and your documents are not used to train AI models.
- Strict mode limits dpow to one SharePoint site you choose.
- Remove it any time in the Microsoft Entra admin centre, Enterprise applications.
Permissions requested and why
At sign in
| Permission (delegated) | Why |
|---|---|
openid, profile, email, User.Read | Sign the person in and link their dpow account to their Microsoft account |
offline_access | Finish background work (building folders, filing exports) without asking the person to sign in every hour |
Sites.ReadWrite.All | Find the SharePoint site, build the project folder tree, and read and write SharePoint lists the person chooses to link |
Files.ReadWrite.All | Upload files that pass the naming check, write registers and generated documents into the CDE, read the tender files the person selects, and match files to the register |
That is the whole sign in request. dpow does not ask for access to anyone's personal OneDrive.
Only when a person switches the feature on
| Permission (delegated) | Feature | Why |
|---|---|---|
Mail.Send, Mail.ReadWrite | Outlook mail | Send the weekly report from the person's own mailbox (a copy stays in their Sent Items), or create it as a draft in their own Drafts folder for them to check and send |
Calendars.ReadWrite | Calendar panel | Show the person's next three weeks of events beside the project and add due dates when asked. This lets dpow read every event in that window, not only its own |
Tasks.ReadWrite | To Do panel | Show the person's To Do lists and add project actions when asked |
Microsoft asks the person for these only when they switch that feature on. Nobody is asked for mail, calendar or To Do access at sign in.
Only if an administrator chooses it
| Permission (delegated) | Why |
|---|---|
Group.ReadWrite.All | Only for the optional "grant site creation permission" step, to create a private Microsoft 365 group site for projects. It needs an administrator, and it is never part of normal sign in. You can create the site yourself instead |
Not requested: Mail.Read, Files.Read.All, Sites.Read.All, any Directory.* permission, Sites.FullControl.All, or any application permission.
Strict mode: one SharePoint site only
For IT teams that want dpow confined to one site, an admin can switch the organisation to strict mode. dpow then asks Microsoft for Sites.Selected in place of Sites.ReadWrite.All and Files.ReadWrite.All, so it can reach the one SharePoint site you grant and nothing else. A person's access is the overlap of what you granted dpow and what that person can already reach.
What IT does:
- Create a dedicated SharePoint site for dpow (for example "Project CDE"), or choose an existing one.
- Grant the dpow app write access to that one site. Microsoft requires an administrator to do this, using one of the two ways below.
- Approve dpow for your organisation with the button at the top of this page.
- In dpow, an organisation admin opens Settings, enters the site address under strict mode and turns strict mode on. Everyone then reconnects Microsoft once, to the one site, and dpow builds the CDE there.
Grant write access with Microsoft Graph
As an administrator with Sites.FullControl.All (for example in Graph Explorer), first find the site id:
GET https://graph.microsoft.com/v1.0/sites/yourcompany.sharepoint.com:/sites/ProjectCDE
Then grant dpow write access to that site, using the id from the answer:
POST https://graph.microsoft.com/v1.0/sites/{site-id}/permissions
Content-Type: application/json
{
"roles": ["write"],
"grantedToIdentities": [
{ "application": { "id": "2fd62e33-471c-4f9d-98eb-444762c668b7", "displayName": "dpow" } }
]
}
Or with PnP PowerShell
Grant-PnPAzureADAppSitePermission -AppId 2fd62e33-471c-4f9d-98eb-444762c668b7 -DisplayName dpow -Site https://yourcompany.sharepoint.com/sites/ProjectCDE -Permissions Write
Where data lives
| What | Where |
|---|---|
| Project files | Your SharePoint, under your retention and access policies. dpow fetches a file when someone asks for it |
| Register, programme, RFIs, audit trail, chat history | dpow's database, Supabase |
| App hosting | Vercel |
Held by dpow, not in your SharePoint: files SharePoint refuses (kept privately until moved into SharePoint), RFI and other attachments and site photos uploaded in the app, organisation logos, 3D models for the scope viewer, fee proposals when SharePoint is unavailable, the AI reading of a tender pack, chat answers, and a text index of register rows used to answer questions.
Sub-processors
Vercel (hosting), Supabase (database, sign in, private file storage), OpenAI and Anthropic (AI), Resend (email), Stripe (payments), and Twilio or Meta for the optional WhatsApp assistant. Microsoft is not a sub-processor: dpow works in your tenant under your own Microsoft agreement. Full list: sub-processors.
Data processing agreement
dpow acts as your processor for project data under a UK GDPR Article 28 data processing agreement.
Security summary
- HTTPS everywhere, with HSTS.
- Row level security on every database table; automated tests check that no organisation can read another's data.
- Microsoft tokens and customer AI keys encrypted at rest (AES-256-GCM); tokens never reachable from the browser; Disconnect Microsoft clears them.
- Append only audit trail that no one can edit or delete.
- Client portals protected by access codes.
- Not yet done: malware scanning of uploads; an independent penetration test. No security certification is held.
- Vulnerabilities: pc at dpow.co.uk (also in our security.txt).
Full detail: Security at dpow.app.
The AI questions
| Question | Answer |
|---|---|
| What does the AI read? | Only what a person asks it to: tender files they select, text they paste, register data needed for their question, or a site photo they submit. It does not crawl your SharePoint |
| Do our files leave SharePoint? | The files stay in your SharePoint, and dpow fetches one only when someone asks for it. The text a person sends to an AI feature goes to the AI provider for that request, to answer the question |
| Which providers? | OpenAI and Anthropic, through their APIs, on dpow's accounts by default |
| Do they train on our data? | No. Your documents are processed to answer questions, not used to train models. Anthropic's terms state: "Anthropic may not train models on Customer Content from Services." OpenAI states that "data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)". Both checked 2 October 2026 |
| How long do they keep it? | Anthropic deletes API inputs and outputs within 30 days by default; OpenAI keeps abuse monitoring logs up to 30 days. Both keep longer only where content is flagged for a policy breach |
| Can we use our own AI account? | Yes. An admin can add your organisation's own key (Anthropic, OpenAI, Azure OpenAI or Gemini, or another OpenAI compatible provider). AI then runs under your own contract. Keys are encrypted at rest and never shown back in full |
| Can the AI act in our tenant? | No. It can only return text, which dpow checks before use. AI documents are drafts, labelled "AI-generated: review before issue" |
Contact
DPOW Group Ltd, pc at dpow.co.uk. Email us if the approval does not complete, or if you want the strict mode steps talked through.