Evo Workflow Automation connects to a wide range of third-party services, databases, and Access products through credentials and connectors. This article explains the types of integrations available, how to set up and manage credentials, and how to connect to Microsoft 365 services.
What integrations are available
Workflow Automation supports connections to over 30 external services, grouped into the following categories.
Microsoft 365
Connect to the Microsoft 365 suite to read and send emails, manage files, post Teams messages, and look up directory information.
Service | What you can do |
Microsoft Outlook | Send and reply to emails, manage folders, contacts, and calendar events. |
Microsoft Teams | Send messages, create channels, manage members, and schedule meetings. |
Microsoft SharePoint | Manage sites, lists, files, and folders. |
Microsoft OneDrive | Upload, download, copy, and manage files and folders. |
Microsoft Entra ID | Look up users and groups in your organisation's directory. |
⚠️ Important: Microsoft 365 integrations require a one-time Azure app registration on your organisation's tenant before you can connect.
Databases
Connect directly to your organisation's databases to query, insert, update, and delete records.
Database | Supported operations |
Microsoft SQL Server | Execute queries, insert, update, delete, create and manage tables. |
MySQL | Execute queries, insert, update, delete, create and manage tables. |
PostgreSQL | Execute queries, insert, update, delete, create and manage tables. |
MongoDB | Find, insert, update, delete, aggregate, and manage collections. |
Redis | Get, set, delete, and manage key-value data with caching support. |
Elasticsearch | Search, index, and manage documents. |
Databricks | Execute SQL queries on your data lakehouse. |
Turso | Execute queries on Turso (libSQL) databases. |
Service | What you can do |
Send SMTP Email | Send emails via any SMTP-compatible mail server. |
SendGrid | Send emails via SendGrid using an API key. |
Productivity and project management
Service | What you can do |
Asana | Manage tasks, projects, subtasks, comments, tags, and users. |
File storage
Service | What you can do |
Azure Blob Storage | Store and manage files in Azure Blob Storage containers. |
FTP / SFTP | Access and manage files on FTP and SFTP servers. |
Access and Evo products
Workflow Automation connects natively to other Access and Evo products through your Evo identity. No credential setup is required for these integrations.
Service | What you can do |
Evo Data Engine | Query, manage, and refresh data in Access Data Engine tables, data flows, and views. |
Evo Data Spaces | Create and manage user-owned data spaces, query and insert records, and upload files. |
Evo Feed | Send, update, and delete items in Evo Feed. |
Evo Researcher | Manage projects, upload files, stream chat responses, and retrieve artefacts. |
Evo Assistant | Chat with an Evo Assistant and list available assistants. |
🤓 Tip: Evo Connector and Evo Tool nodes also appear in the palette at runtime, one entry per connector your environment exposes. These run under your Evo identity and do not require a stored credential.
Credentials
Most integrations require a credential before a node can connect to an external service. A credential stores the authentication details - such as an API key, username and password, or OAuth token - so you do not need to enter them each time you build a workflow.
Credential types
Workflow Automation supports the following general credential types.
Type | When to use |
API Key | For services that authenticate with a single key passed in a header or query parameter. |
Basic Auth | For services that use a username and password. |
Bearer Token | For services that use a token passed in the authorisation header. |
Header Auth | For services that use a custom header name and value. |
JWT | For services that require a JSON Web Token. |
For AI and LLM integrations, Workflow Automation supports credentials for OpenAI, Anthropic Claude, Azure OpenAI, Google Gemini, and Groq.
Adding a credential
Open Evo Workflow Automation from the Evo menu.
Select Credentials from the left-hand navigation.
Select Add credential.
Choose the credential type from the list.
Complete the required fields - for example, your API key or username and password.
Select Save.
Once saved, the credential is available to select on any node that uses that credential type.
Picking a credential in a node
When you add a node that requires a credential, a credential dropdown appears in the node's configuration panel. The dropdown shows credentials of the matching type that you own or that have been shared with you. Workflow Automation defaults to the last-used credential for that type.
Updating and rotating credentials
To update a credential - for example, when an API key is rotated - open the credential from the Credentials page and update the relevant fields. The masked secret field stays masked unless you replace it. Any workflow that uses the credential picks up the new value on its next execution.
For OAuth2 credentials, you may need to re-authorise the connection if the token expires. Open the credential and select Authorise to go through the consent screen again.
Sharing credentials
By default, a credential is private to the person who created it. You can share a credential with named users or with a team so that others can use it in their workflows.
Sharing a credential grants execution access only — the recipient can use the credential in a workflow but cannot view the underlying secret values.
How credential access is resolved
When a workflow runs, Workflow Automation resolves credentials in the following order.
The workflow owner's own credentials.
Credentials shared directly with the workflow owner.
Credentials shared with a team the workflow owner belongs to.
Credentials shared via a share link.
System credentials - managed by Access and available to all users automatically.
📌 Note: Workflows always run as the workflow owner, regardless of who triggers them. If the workflow owner does not have access to a required credential, the workflow will fail.
Setting up Microsoft connectors
Microsoft 365 integrations - Outlook, Teams, SharePoint, OneDrive, and Entra ID — require a one-time Azure app registration on your organisation's Microsoft tenant. This is typically completed by your IT team.
What your IT team needs to do
Your IT team needs to register an application in the Azure portal and grant the required permissions for each Microsoft service you want to connect to.
The permissions required for each service are listed below.
Service | Permissions required |
Microsoft Outlook | Mail.Read, Mail.Send, Mail.ReadWrite |
Microsoft Teams | ChannelMessage.Read.All, ChannelMessage.Send, Chat.ReadWrite |
Microsoft SharePoint | Sites.Read.All, Sites.ReadWrite.All |
Microsoft OneDrive | Files.Read.All, Files.ReadWrite.All |
Microsoft Entra ID | User.Read.All, Group.Read.All |
Once the app registration is complete, your IT team provides you with three values: the Tenant ID, the Client ID, and the Client Secret.
Adding a Microsoft credential
Open Credentials in Evo Workflow Automation.
Select Add credential and choose the Microsoft service — for example, Microsoft Outlook OAuth2.
Enter the Tenant ID, Client ID, and Client Secret provided by your IT team.
Select Authorise to open the Microsoft consent screen and grant access.
Select Save.
The credential is now ready to use in any node for that Microsoft service.
📌 Note: Each Microsoft service requires its own credential. If you need to connect to both Outlook and Teams, you add two separate credentials — one for each service.
Common issues
Issue | What to check |
A node reports that the credential is not authorised. | Check that the credential has been shared with the workflow owner, or that the workflow owner created the credential themselves. |
A Microsoft node fails to authenticate. | Check that the Azure app registration has been completed and that the correct permissions have been granted for that service. |
An OAuth2 token has expired. | Open the credential from the Credentials page and select Authorise to re-authorise the connection. |
A webhook node rejects incoming requests. | Check that the authentication mode set on the Webhook trigger matches the authentication method used by the sending service. |
Two credentials of the same type behave differently. | If you need different permission scopes for the same service, create a second credential with a different name and select the correct one on each node. |
