M365-004 / SOURCE CONTROLLED
Scribe8 technical specification
Scribe8 treats a meeting transcript as governed evidence. Summaries, decisions and proposed actions remain traceable to the words, participants and permissions that produced them.
● CONTROLLEDOWNER / SYSTEM 8REVIEW / MONTHLY
Service outcomes
- Capture speaker-attributed transcript segments and meeting context.
- Produce evidence-linked summaries, decisions, questions and action proposals.
- Respect Microsoft 365 identity and source permissions when retrieving or publishing information.
- Require accountable approval before actions change another system.
Processing flow
- Ingest an authorised transcript and meeting identity.
- Normalise timestamps, speakers and source references without overwriting the original.
- Generate structured candidate outputs with citations to transcript segments.
- Validate permissions, confidence and required approvers.
- Publish approved records to their controlled Microsoft 365 destinations.
- Retain the decision and action audit trail.
Authority boundaries
| STAGE | AUTHORITY |
|---|---|
| Observe | Read only explicitly authorised meeting and reference sources |
| Propose | Create draft summaries, decisions and actions |
| Approve | Named human accepts, edits or rejects a proposed output |
| Execute | Use a scoped identity to perform the approved action |
| Verify | Record outcome, failure and source evidence |
Microsoft 365 integration
- Entra ID for user, application and workload identity.
- Microsoft Graph for permission-aware retrieval and controlled publication.
- SharePoint or Dataverse for governed records, depending on the information model.
- Teams links and meeting identifiers preserved as source context.
- Purview controls applied according to the destination and record class.
Security and lifecycle
- No model provider receives broader tenant access than the processing task requires.
- Secrets and certificates have owners, rotation dates and revocation paths.
- Raw transcript, derived records and prompts have explicit retention rules.
- Outputs do not bypass source permissions through a global retrieval index.
- Deletion, legal hold and incident response can identify every derivative.
Acceptance tests
- Every material claim in a summary can resolve to source segments.
- A user cannot retrieve content they could not access at the source.
- No external action occurs without the configured approval condition.
- Failures are visible, retryable where safe and do not duplicate side effects.
- Meeting owners can correct the record without erasing provenance.