Setting up and using Keegi.
A sentence in, up to three colleagues out, each with one line of evidence from work they shipped. If nobody here has done it, Keegi says so.
LoadingSetting up and using Keegi.
A sentence in, up to three colleagues out, each with one line of evidence from work they shipped. If nobody here has done it, Keegi says so.
LoadingA sentence in, up to three colleagues out, each with one line of evidence from work they shipped. If nobody here has done it, Keegi says so.
Keegi reads Word, Markdown and text files in the SharePoint sites you add, and builds cards from what people wrote. It attaches beside whatever else the workspace reads.
It does not read anybody's OneDrive, Teams chats, mail, PDFs, slides, spreadsheets or OneNote. A site nobody granted to Keegi is out of reach, whatever the Keegi admin does.
On /app/[org]/sources, press Connect Microsoft 365. Microsoft asks for an admin of your organisation, ticks Consent on behalf of your organization, and sends you back with the row in place.
It has to be a Microsoft admin, usually a Global or Application Administrator. Anyone else sees Microsoft's own page saying the app needs admin approval. If the Keegi admin is not a Microsoft admin, ask the person who is to press the button.
A Microsoft tenant can be connected to one Keegi workspace. If it is already connected somewhere else, disconnect it there first.
Approving Keegi does not let it read any site. Each one is granted on its own, by a SharePoint admin, with one command per site. This is deliberate: Keegi asks for the permission that covers named sites rather than every site in the tenant.
In PnP PowerShell, with the site's address:
Grant-PnPAzureADAppSitePermission -AppId 5baa4aab-45e2-4fd1-9512-f40234f1a9cc -DisplayName Keegi -Site <site address> -Permissions Read
Or through Graph, with the site's id:
POST https://graph.microsoft.com/v1.0/sites/<site-id>/permissions
{
"roles": ["read"],
"grantedToIdentities": [
{ "application": { "id": "5baa4aab-45e2-4fd1-9512-f40234f1a9cc", "displayName": "Keegi" } }
]
}Read is the only role Keegi needs. It never writes to a site.
On the Microsoft 365 row, paste a site's address into SharePoint site and press Add site. A link to a library or a page inside the site works too. Keegi checks it can read the site, and adds it turned off.
Turn on the sites Keegi may read and press Save. Nothing is read until you do.
Press Read Microsoft 365 now. The row then says when it was last read. Later reads only open files that changed.
Whoever created it, and only them. The last person to save it is not credited: fixing a typo in somebody else's runbook is not writing it.
By the address in your directory. Keegi looks each author up in your Microsoft directory and uses their mail address, or their sign-in name when they have no mailbox. Invite people on /app/[org]/people by the same address and their SharePoint work lands on the same card as everything else.
Disconnect makes Keegi forget the sites and everything it read from them. The approval itself stays in your Microsoft tenant until a Microsoft admin removes Keegi under Enterprise apps, because only they can.