Microsoft Office add-ins
The Myra Office add-ins bring the gateway document AI into Microsoft Office as task panes. In Word, a user rewrites, fixes grammar, summarises, translates, drafts, and asks questions about the open document. In Excel, a user summarises, cleans data, writes a formula, and asks questions about the sheet. In Outlook, a user summarises a message and drafts or rewrites a reply. Every action runs on the model of the tenant through the gateway, and Microsoft single sign-on authenticates the user on each call.
This chapter is for the administrator who deploys the add-ins to users. Each add-in is a standard Office add-in described by a manifest file. Installation makes that manifest available to Office, and Office then loads the task pane from the Myra host.
The add-ins support the following capabilities and limitations:
| Capability | Limitation |
|---|---|
| Word, Excel, and Outlook task panes on Office on the web, Windows, and Mac | Office 2016 and 2019 are not supported. |
| Microsoft single sign-on on every request, with no separate password | A one-time tenant admin consent is required before first use. |
| Document AI served by the designated model of the tenant | The workspace of the user must be enabled for the direct document-AI lane. |
💡 Note: The add-ins load the task pane and call the gateway over HTTPS from the Myra host (
https://<GATEWAY_HOST>/). The Office client of each user reaches that host, and the host serves the add-in security headers configured by Myra. On the hosted service the host isai.myra.eu.
Prerequisites
Before you begin, ensure the following conditions are met:
- You hold the SharePoint Administrator role for the App Catalog procedure, or you reach the Integrated apps page in the Microsoft 365 admin center for the recommended procedure.
- You hold the Global Administrator or Application Administrator role for the single sign-on consent procedure.
- You have the add-in manifest file for each add-in you deploy. Myra provisions one manifest each for Word, Excel, and Outlook, carrying the Myra host and the Microsoft Entra application.
- The Office client of each user reaches the Myra host over HTTPS.
💡 Note: Microsoft recommends the Microsoft 365 admin center (Integrated apps) for every Office add-in. The SharePoint App Catalog serves the Word and Excel add-ins only, not the Outlook add-in.
Granting single sign-on consent
Office single sign-on calls the gateway with a token minted by a Microsoft Entra application. A tenant admin consents to the application once, so users are not prompted on every action.
Proceed as follows to grant single sign-on consent:
- Sign in to the Microsoft Entra admin center at
https://entra.microsoft.com. - Open App registrations.
- Select the Myra add-in application.
- Open the API permissions page.
- Click on the Grant admin consent button.
- A confirmation prompt opens.
- Click on the Yes button.
-> The permissions list shows the Granted status for the tenant.
Deploying with the Microsoft 365 admin center
The Microsoft 365 admin center deploys any of the three add-ins to selected users or to the whole organisation.
Proceed as follows to deploy an add-in with the Microsoft 365 admin center:
- Sign in to the Microsoft 365 admin center at
https://admin.microsoft.com. - Open Settings → Integrated apps.
- Click on the Upload custom apps button.
- The Upload custom apps panel opens.
- Select the Provide link to manifest file option.
- Enter the add-in manifest URL in the Link text field.
- The validated add-in details appear.
- Select the users who receive the add-in.
- Click on the Next button.
- Click on the Accept permissions button.
- Click on the Finish deployment button.
-> The add-in appears on the Office ribbon for the selected users. The first rollout takes up to 24 hours. Repeat this procedure for each add-in.
💡 Note: If required, select the Upload manifest file option in step 4 and select the manifest file instead of entering a link.
Deploying with the SharePoint App Catalog
The SharePoint App Catalog serves the Word and Excel add-ins to the whole organisation through the Apps for Office library.
Proceed as follows to deploy a Word or Excel add-in with the SharePoint App Catalog:
- Sign in to the SharePoint admin center at
https://<TENANT>-admin.sharepoint.com. - Open More features.
- Under Apps, click on the Open button.
- The Apps page opens.
- Open the App Catalog site.
- Open the Apps for Office library.
- Click on the Upload button.
- Select the add-in manifest file.
- Click on the OK button.
-> The add-in appears in the Apps for Office library with the enabled status. Repeat this procedure for the Word and Excel add-ins.
💡 Note: If no App Catalog site exists, open the App Catalog tile on the Apps page, select Create a new app catalog site, and complete the form before step 5.
Proceed as follows to add the deployed add-in in Word or Excel:
- Open Word or Excel with a work account.
- Open Insert → Add-ins.
- Open the My Add-ins tab.
- Open the Admin Managed tab.
- Select the Myra document AI add-in.
-> The Myra document AI task pane opens.
⚠️ Caution: The Outlook add-in does not deploy through the SharePoint App Catalog. Deploy the Outlook add-in with the Microsoft 365 admin center instead.
Sideloading an add-in
A sideload installs an add-in for your own account only, without an organisation-wide deployment. Use a sideload to test an add-in.
Proceed as follows to sideload an add-in in Word or Excel on the web:
- Open Word or Excel on the web.
- Open Insert → Add-ins.
- Click on the Upload My Add-in button.
- Click on the Browse button.
- Select the add-in manifest file.
- Click on the Upload button.
-> The task pane opens for the current session.
💡 Note: To sideload the Outlook add-in, open Settings → Add-ins → My add-ins → Custom add-ins in Outlook on the web, select Add a custom add-in, select Add from file, and select the manifest file.
Verifying the installation
Proceed as follows to verify the installation:
- Open the add-in task pane.
- Select text in the document.
- Click on the Summarize button.
-> The add-in returns a result from the model of the tenant.
If a sign-in or consent error appears, grant single sign-on consent as described above. If a 403 not provisioned for document AI error appears, the workspace of the user is not enabled for the direct document-AI lane — see Direct document AI.
Related topics
The following chapters cover the surfaces referenced here:
- Direct document AI — the API the add-ins call, the per-action request shapes, and the error codes.
- Entra single sign-on — configuration of the Microsoft identity side.