dpow.app for your IT team

Last updated 6 October 2026

One page for the IT administrator asked to approve dpow.app.

dpow.app is design management software for construction, from DPOW Group Ltd (company number 17276695, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ). It builds and keeps a project's information register, programme, RFIs and reports, and files documents into your own SharePoint.

Approve dpow for your organisation

This opens Microsoft's own approval screen for the whole organisation, so nobody on your team sees a "Need admin approval" message when they sign in. Only a Global Administrator or Cloud Application Administrator can approve. The dpow application (client) id is 2fd62e33-471c-4f9d-98eb-444762c668b7.

In short

Permissions requested and why

At sign in

Permission (delegated)Why
openid, profile, email, User.ReadSign the person in and link their dpow account to their Microsoft account
offline_accessFinish background work (building folders, filing exports) without asking the person to sign in every hour
Sites.ReadWrite.AllFind the SharePoint site, build the project folder tree, and read and write SharePoint lists the person chooses to link
Files.ReadWrite.AllUpload files that pass the naming check, write registers and generated documents into the CDE, read the tender files the person selects, and match files to the register

That is the whole sign in request. dpow does not ask for access to anyone's personal OneDrive.

Only when a person switches the feature on

Permission (delegated)FeatureWhy
Mail.Send, Mail.ReadWriteOutlook mailSend the weekly report from the person's own mailbox (a copy stays in their Sent Items), or create it as a draft in their own Drafts folder for them to check and send
Calendars.ReadWriteCalendar panelShow the person's next three weeks of events beside the project and add due dates when asked. This lets dpow read every event in that window, not only its own
Tasks.ReadWriteTo Do panelShow the person's To Do lists and add project actions when asked

Microsoft asks the person for these only when they switch that feature on. Nobody is asked for mail, calendar or To Do access at sign in.

Only if an administrator chooses it

Permission (delegated)Why
Group.ReadWrite.AllOnly for the optional "grant site creation permission" step, to create a private Microsoft 365 group site for projects. It needs an administrator, and it is never part of normal sign in. You can create the site yourself instead

Not requested: Mail.Read, Files.Read.All, Sites.Read.All, any Directory.* permission, Sites.FullControl.All, or any application permission.

Strict mode: one SharePoint site only

For IT teams that want dpow confined to one site, an admin can switch the organisation to strict mode. dpow then asks Microsoft for Sites.Selected in place of Sites.ReadWrite.All and Files.ReadWrite.All, so it can reach the one SharePoint site you grant and nothing else. A person's access is the overlap of what you granted dpow and what that person can already reach.

What IT does:

  1. Create a dedicated SharePoint site for dpow (for example "Project CDE"), or choose an existing one.
  2. Grant the dpow app write access to that one site. Microsoft requires an administrator to do this, using one of the two ways below.
  3. Approve dpow for your organisation with the button at the top of this page.
  4. In dpow, an organisation admin opens Settings, enters the site address under strict mode and turns strict mode on. Everyone then reconnects Microsoft once, to the one site, and dpow builds the CDE there.

Grant write access with Microsoft Graph

As an administrator with Sites.FullControl.All (for example in Graph Explorer), first find the site id:

GET https://graph.microsoft.com/v1.0/sites/yourcompany.sharepoint.com:/sites/ProjectCDE

Then grant dpow write access to that site, using the id from the answer:

POST https://graph.microsoft.com/v1.0/sites/{site-id}/permissions
Content-Type: application/json

{
  "roles": ["write"],
  "grantedToIdentities": [
    { "application": { "id": "2fd62e33-471c-4f9d-98eb-444762c668b7", "displayName": "dpow" } }
  ]
}

Or with PnP PowerShell

Grant-PnPAzureADAppSitePermission -AppId 2fd62e33-471c-4f9d-98eb-444762c668b7 -DisplayName dpow -Site https://yourcompany.sharepoint.com/sites/ProjectCDE -Permissions Write

Where data lives

WhatWhere
Project filesYour SharePoint, under your retention and access policies. dpow fetches a file when someone asks for it
Register, programme, RFIs, audit trail, chat historydpow's database, Supabase
App hostingVercel

Held by dpow, not in your SharePoint: files SharePoint refuses (kept privately until moved into SharePoint), RFI and other attachments and site photos uploaded in the app, organisation logos, 3D models for the scope viewer, fee proposals when SharePoint is unavailable, the AI reading of a tender pack, chat answers, and a text index of register rows used to answer questions.

Sub-processors

Vercel (hosting), Supabase (database, sign in, private file storage), OpenAI and Anthropic (AI), Resend (email), Stripe (payments), and Twilio or Meta for the optional WhatsApp assistant. Microsoft is not a sub-processor: dpow works in your tenant under your own Microsoft agreement. Full list: sub-processors.

Data processing agreement

dpow acts as your processor for project data under a UK GDPR Article 28 data processing agreement.

Security summary

Full detail: Security at dpow.app.

The AI questions

QuestionAnswer
What does the AI read?Only what a person asks it to: tender files they select, text they paste, register data needed for their question, or a site photo they submit. It does not crawl your SharePoint
Do our files leave SharePoint?The files stay in your SharePoint, and dpow fetches one only when someone asks for it. The text a person sends to an AI feature goes to the AI provider for that request, to answer the question
Which providers?OpenAI and Anthropic, through their APIs, on dpow's accounts by default
Do they train on our data?No. Your documents are processed to answer questions, not used to train models. Anthropic's terms state: "Anthropic may not train models on Customer Content from Services." OpenAI states that "data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)". Both checked 2 October 2026
How long do they keep it?Anthropic deletes API inputs and outputs within 30 days by default; OpenAI keeps abuse monitoring logs up to 30 days. Both keep longer only where content is flagged for a policy breach
Can we use our own AI account?Yes. An admin can add your organisation's own key (Anthropic, OpenAI, Azure OpenAI or Gemini, or another OpenAI compatible provider). AI then runs under your own contract. Keys are encrypted at rest and never shown back in full
Can the AI act in our tenant?No. It can only return text, which dpow checks before use. AI documents are drafts, labelled "AI-generated: review before issue"

Contact

DPOW Group Ltd, pc at dpow.co.uk. Email us if the approval does not complete, or if you want the strict mode steps talked through.