For IT administrators

What SearchFlow asks of your Microsoft 365 tenant, how to approve it, where the data goes, and how to remove it.

If an employee sees “Need admin approval” when signing in to SearchFlow, your tenant has not approved it yet: see Approval.

What it is

SearchFlow is a Windows desktop app by DomusFlow BV, Belgium. It indexes a person's Microsoft 365 mail, OneDrive, SharePoint team sites and the server folders they choose, on that person's own PC, and searches them there.

It signs in as that person through Microsoft and only reads: it never sends, changes or deletes mail or files. Server folders are read on the PC with the person's own Windows access and need no Microsoft permission.

Permissions

One app registration in Microsoft Entra ID: SearchFlow, multitenant, application (client) ID 19a659cd-b965-44e7-9465-3fbed07d7b21. Microsoft Graph, delegated permissions only, all read-only:

Mail.Read
Reads the user's own mailbox, to index it on the PC.
Files.Read.All
Reads the user's OneDrive and the team-site documents the user can open, to index their text on the PC.
Sites.Read.All
Lists the SharePoint sites and document libraries the user can open.
User.Read
Signs the user in and reads their name and address, to show the account.
offline_access
Keeps the user signed in, so the app keeps syncing without a new sign-in.

No application permissions and no client secret: SearchFlow can only act as a signed-in user. It reads only what that user can already open and widens no one's access.

Approval

Under Microsoft's default consent settings, employees cannot approve Mail.Read, Files.Read.All or Sites.Read.All for an app from outside the company. An administrator approves SearchFlow once, for the whole tenant; until then an employee without admin rights sees “Need admin approval” at sign-in.

  1. On your own PC, open this link and sign in as a Global Administrator, or another role that may grant tenant-wide consent:
  2. Check the permissions Microsoft lists and click Accept.
  3. The browser then goes to http://localhost/ and shows “This site can't be reached”. That is normal: the approval is done.

This one approval covers mail and files, for every user in the tenant. Employees then sign in without a consent screen, and their OneDrive and team-site documents appear by themselves.

Microsoft's page shows SearchFlow as unverified: DomusFlow BV's publisher verification with Microsoft is not done yet.

Do not approve on an employee's PC through “Have an admin account? Sign in with that account” on Microsoft's sign-in page: SearchFlow would then add your mailbox on that PC, and that route approves mail only.

To check the approval: Entra admin center → Enterprise applications → SearchFlow → Permissions.

Data

Stays on the PC

  • The index: mail, attachment and document text and file names, in %LOCALAPPDATA%\DomusSearch in the user's profile. There is no central copy.
  • The Microsoft sign-in tokens, in the same folder. They are used only with Microsoft and never sent to us.
  • Searches: typed search runs on the PC and sends nothing.

Mail and files come straight from Microsoft to the PC; they do not pass through our server.

Sent to our server (searchflow-server.vercel.app)

  • The app's log, every 5 minutes: the install id (a random id the app makes at first start), the app version, the signed-in accounts and the new log lines: what synced when (folder, library and server-folder names, counts) and errors. Lines can also name a file or show a user's display name. Our server cuts every e-mail address to its domain on receipt and keeps the log 14 days.
  • The licence check, at start and every 10 minutes: the install id and the app's language.
  • Questions (Ask), only when a user asks one: the question and the mail and document text the model reads to answer it go through our server to OpenAI's API. Our server stores none of that text, only a monthly count of questions and tokens per install. OpenAI gets it with storage turned off, may hold it up to 30 days for abuse monitoring, and does not train on it.

Nothing is sold or shared with anyone else. Privacy statement: searchflow.be/privacy.

Revoking

  • For everyone: Entra admin center → Enterprise applications → SearchFlow → Properties → Delete. To block it but keep the entry, set “Enabled for users to sign-in?” to No instead.
  • For some people only: in the same Properties, set “Assignment required?” to Yes and add the people who may use it under Users and groups; removing someone there ends their access.

SearchFlow reads nothing more once its current access token expires. What it already indexed stays on the PC until the user removes the account in SearchFlow's Settings or deletes the data folder.

On a PC: Windows Settings → Apps → SearchFlow → Uninstall removes the program. The data folder %LOCALAPPDATA%\DomusSearch (index, sign-in tokens, logs) stays until it is deleted by hand.

Installer

  • Windows 10 or 11. Download: searchflow.be/start.
  • Per user, no administrator rights: it installs to %LOCALAPPDATA%\Programs\SearchFlow. No service, no scheduled task, no startup entry.
  • The installer is not code-signed yet, so the browser and Windows SmartScreen warn before it runs. Signing in DomusFlow BV's name is planned.
  • It updates itself: at start and every 10 minutes it checks one fixed address (domussearch.vercel.app) for a newer version, downloads it in the background and installs it silently, per user, at the next start.
  • Its window shows a local page served on 127.0.0.1:8790; nothing listens on the network.

Contact

Questions: sales@domusflow.io.

DomusFlow BV, Knokke-Heist, Belgium, VAT BE 0750792272.