Skip to content
Vrge

Outlook CRM integration, read-only

Vrge is not an Outlook add-in. It is a desktop app that reads your mailbox through Microsoft Graph with a read-only mail permission and proposes the clients, projects, invoices and payments it finds. You approve each one in the Vrge Inbox; nothing is saved until you do, and an accept can be undone for 24 hours. A personal Microsoft account connects in a minute. A work or school account may need an administrator’s approval first — the Setup section says exactly what to expect.

Mail.Read · read-only scope

NEW CLIENT

Harbourline Interiors

Contact
Priya Raman
inferred · signature block
Email
priya@harbourline.co
sender address
Project
Showroom fit-out
inferred · the brief
Note
The inquiry email, filed with the client
the email itself

One inbound brief becomes one bundled proposal: client, project and note, accepted or rejected together. Nothing is saved until you accept it.

Illustrative: your records will differ

Read-only

What Vrge reads from Outlook

  • Your Inbox folder from the last 7 days, then whatever is newThe first scan covers the past week by default. The History to scan setting on the connection widens that window, and a deep scan re-reads it. After that each run reads what arrived since the last one, newest first, up to 200 messages at a time. Only the Inbox folder is read: mail you have filed into other folders, Junk, Drafts and Archive are left out.
  • Headers, the body and Outlook’s own previewFrom, To, Subject and the received time; the message body as Outlook stores it; the short preview Outlook already computes; the conversation id that groups a thread; and any categories you have applied. That is the whole record — Vrge asks Microsoft Graph for exactly those fields and nothing else.
  • Whether a message has an attachment — never the attachmentVrge records a yes or no and uses it as one weak signal among several. It does not download attachments, so an invoice sent as a PDF is not read.
  • Your Sent Items, for Open Loops onlyA separate, smaller pass reads what you sent in the last 30 days, up to 50 messages a run, so Vrge can tell which threads are waiting on you and which are waiting on them. Sent mail never enters the client and invoice extraction path, so your own signature cannot become a proposed client. One narrow exception is read by the AI: a sent message to someone already in your CRM or contacts that is phrased as a promise — “I’ll send the quote by Friday” — is checked for a commitment worth tracking. Today that check produces nothing in the inbox.
  • Your addressOne call to Microsoft’s profile endpoint returns the email address of the account. It labels the connection in Settings and lets Vrge recognise its own messages.
  • A calendar permission on the same sign-in, unused until you add Outlook CalendarThe consent screen asks for Read user calendars alongside Read user mail, so that adding Outlook Calendar later reuses this sign-in instead of asking for a second one. The mail connection itself never calls the calendar. Events are read only if you connect Outlook Calendar as its own source, and it makes its own proposals.

Two Microsoft accounts? Connect both. Each is watched on its own, and there is no extra charge for a second account.

What Outlook turns into

Email extraction uses the AI you chose in Settings → AI & Intelligence: your own Anthropic, OpenAI or Google key, Ollama on your machine, or the optional Managed AI subscription. It is the same extractor Gmail uses. Every proposal shows the message it came from and the signals that made the case.

Proposals Vrge makes from Outlook
KindProposalEvidence
NEW CLIENTA new client, bundled with the project they described and a note holding the inquiryAn inbound email the AI reads as a new inquiry, plus at least one hard signal: a business domain, a signature block, a reply on a thread with you, engagement language, a budget or amount, or an attachment. With none of those the bundle is held back from the inbox.
TASKTasks from a project update, with a meeting noteAn email about work in progress that names a project. Action items become tasks under the matched project; the email itself is kept as a note.
INVOICEAn invoice draftA reply from a client already in Vrge about an invoice you sent.
PAYMENTA payment matched to an open invoice, or recorded on its ownA payment notification — a processor payout or a direct confirmation. The amount is matched against your open invoices; if none fits, the payment is proposed by itself, with a new client when the payer is unknown.
EXPENSEA business expenseA vendor bill or receipt with a usable amount. If no amount can be read, nothing is proposed.

The Open Loops you see come from the same mail with no AI: a reply you owe and a reply you are waiting on are computed from who spoke last in each thread, and they close themselves when the reply arrives. Only people already in your CRM or contacts can open a loop by writing in, so cold senders and newsletters never appear. All of this is the pipeline described on the Gmail page; the mailbox is the only thing that differs.

How the inbox review works

What Vrge never does with Outlook

  • Send, reply to, or forward an email.The permission Vrge asks for cannot send.
  • Mark anything read, categorise, move, archive or delete.Every call Vrge makes to Microsoft Graph is a read. Your unread count is what it was before you connected.
  • Add anything to Outlook.Vrge is not an add-in. It installs no button, pane or rule in Outlook, and Outlook looks exactly as it did. The only place you see Vrge is the Vrge app.
  • Create a draft.Drafts are outside the permission, along with sending and moving.
  • Download an attachment.It notes that one exists and stops there.
  • Propose a client or project from your own sent mail.Outbound mail is read for Open Loops and never enters the client and invoice extraction path.
  • Save anything to your CRM on its own.Every record starts as a proposal you approve, and an accept can be undone for 24 hours.

The mailbox guarantees are Microsoft’s to enforce, not ours to promise. Mail.Read is the permission Microsoft labels “Read user mail”. Sending is a separate permission (“Send mail as a user”) and so is writing (“Read and write access to user mail”); Vrge requests neither, so it could not do those things if it tried. One more thing the consent screen will tell you: the publisher is shown as Unverified. Vrge has not completed Microsoft’s publisher verification, which confirms a publisher’s identity through a Microsoft partner account and is not a review of the app itself. What that means when you connect is under Setup.

Where the data goes

Your mail goes from Microsoft to your laptop. Nowhere else, unless you choose.

Vrge is a desktop app. When you connect Outlook it opens Microsoft’s own sign-in page in your browser, and Microsoft hands the sign-in code straight back to the app on your machine, which trades it for a token using PKCE — the OAuth flow built for desktop apps, with no client secret to hold. The token is stored there. There is no Vrge server in that exchange — not for the sign-in, not for renewing it, and not for the messages. Every message is fetched by the app, from Microsoft Graph, over TLS. Disconnecting inside Vrge deletes the token from your machine; the permission itself stays granted at Microsoft until you withdraw it from your Microsoft account’s apps page, which you can do at any time. The full account of what does reach a server we operate is on What your CRM vendor can see.

What can leave the machine is the extraction step, and you decide that. With Ollama, nothing leaves. With your own Anthropic, OpenAI or Google key, the headers and body of each message Vrge extracts from go to your own provider account, under the redaction mode you set. With Managed AI the message is always redacted or summarised locally before it reaches Vrge’s proxy, which stores no content. Settings → AI & Intelligence shows a sample of what the mode in force would send.

Every AI call is logged — when, which provider, how many tokens, whether it was redacted — and the log never stores the content itself. One button, Pause AI, stops scanning and cancels any call in flight. No confirmation dialog.

token handling · Trust Center

How to connect Outlook

Settings → Connected Sources → Outlook / Microsoft 365 → Connect, in the desktop app. Your browser opens Microsoft’s own sign-in and lists the permissions; approve them and the first scan starts within a minute. That is the whole process for a personal Microsoft account. For a work or school account, plan on your administrator: because Vrge’s Microsoft app is unverified and asks for more than sign-in, Microsoft’s default setting blocks self-approval. You are told an administrator’s approval is needed — with a button to request it if your organisation has turned that workflow on, otherwise the message that the app “needs permission to access resources in your organization that only an admin can grant”. An administrator grants consent once, from Microsoft’s tenant-wide consent link using Vrge’s application ID 87d1a8d6-37ce-4fe4-a1a8-bd22215b8de3 or, once Vrge is listed under Enterprise apps in the Microsoft Entra admin center, from its Permissions page (Grant admin consent). After that no one else in the organisation is asked, unless Vrge ever requests a new permission. An IT team that would rather not approve a third-party publisher at all can register its own Entra app with the same two read permissions and paste its client ID into the dialog’s Advanced section instead; Vrge then never uses its public app.

Connecting a mailbox, step by step

Try it with your own Outlook

Download it and run it for 14 days free — no account, no card. Connect Outlook from Settings → Connected Sources and watch the inbox.

Solo licence $79, once. All 1.x updates forever. 14-day free trial, no card. Mac and Windows.