Before you start
- A verified Cygnetree account
- Owner or admin access for workspace/shared profiles
Connecting your business tools
Open Settings → Integrations to connect the tools your business already uses. Microsoft 365 and Google Workspace can be connected as a suite, but you choose each tool independently. You can connect only a calendar, for example, without granting mail or file access.
Understand the two sides of a connection
Your workspace supplies its own provider application registration. Cygnetree supplies the connector and setup flow, but does not host a shared Google, Microsoft, Zoom, or Box application. Your workspace profile is the separate authorization that names the external account, selected tools, granted provider permissions, health, and workspace defaults.
A Cygnetree administrator can see safe adoption and connection-health metadata. Administrators cannot reveal your application credentials, provider tokens, or SMTP password.
Cygnetree is usable without assembling external services. Managed email delivery, private file storage, native scheduling, and provider-neutral meeting locations are available as product defaults. A connection you deliberately select replaces or augments only its named capability. If that selected provider later fails, Cygnetree shows the failure instead of silently changing your sender, meeting host, storage location, or cost owner.
Choose a profile type
- Workspace is a business-owned account used as a shared default.
- My account belongs to the signed-in member and can be selected for that person's sending, calendar, or meeting identity. Tenant file storage is intentionally not attached to a personal profile.
- Shared account is a team mailbox, calendar, drive, or other jointly managed resource.
You may connect more than one profile from the same provider. Connecting another profile does not silently replace an existing default.
Connect Microsoft 365
Select Outlook, Outlook Calendar, Microsoft Teams, OneDrive, and/or SharePoint. The page shows the exact Microsoft permissions required by each selection. Cygnetree combines compatible selections into one Microsoft consent screen and stores an independent grant for every selected tool.
Outlook can send client correspondence. Calendar can import busy time and create appointments. Teams can create private meeting links. OneDrive setup creates or reuses a visible Cygnetree folder only when OneDrive is selected.
SharePoint does not create a OneDrive folder. After consent, Cygnetree takes a workspace admin directly to Storage and migration. Enter the site URL, choose one of that site's document libraries, and confirm the dedicated Cygnetree folder. Cygnetree verifies that the selected library belongs to the selected site before creating anything.
What you have to set up first
Nothing. You do not register an application, create an app registration, or copy any client ID or secret. Cygnetree registers one application with Microsoft; you approve it for your own business.
What you will see when you connect
- You sign in with your work or school Microsoft account — the one your business email uses. Personal accounts (outlook.com, hotmail.com, live.com) cannot connect, because the permissions below only exist for business accounts.
- Microsoft shows a consent screen listing exactly the tools you selected and nothing else.
- You will be asked to approve on behalf of your organization. Microsoft requires an administrator to approve these permissions, and for most small businesses the owner is the administrator — so this is one extra checkbox, not a separate approval process. If your Microsoft account is managed by someone else's IT department, they approve it once and then everyone in your business can connect.
- That is the whole setup.
Where your permission lives afterwards
When you approve, Microsoft records Cygnetree in your own Microsoft account under Enterprise applications. You did not create that entry and you do not need to manage it — but it is where you or your administrator can review or withdraw access at any time, independently of Cygnetree. Disconnecting inside Cygnetree stops it from using the connection; removing it in Microsoft revokes the permission itself.
Connect Google Workspace
Select Gmail, Google Calendar, Google Meet, and/or Google Drive. Cygnetree requests only the scopes shown for those selections. Gmail can send from the connected mailbox. Calendar and Meet support availability and private meeting links.
Selecting Drive creates or reuses a visible Cygnetree folder and adds that destination to the portable storage control plane. If Drive is not selected, no Drive folder is created.
As with Microsoft, there is nothing to register or configure beforehand — you sign in, review the list of tools, and approve. Google shows the permissions as a single consent screen, and either a personal Gmail account or a Google Workspace account can connect. If your Google account belongs to an organization whose administrator restricts third-party apps, they approve Cygnetree once and then anyone in the organization can connect.
You can review or withdraw the permission at any time from your Google Account's Third-party apps with account access page, independently of Cygnetree.
Connect Zoom
Connect Zoom separately when a booking host prefers Zoom over Teams, Meet, or a reusable meeting link. Choose Workspace, My account, or Shared account just as you would for another meeting identity. A workspace owner can set a shared default, and the team identity policy can allow or require each booking host to use a personal Zoom profile.
Cygnetree creates a scheduled meeting only after a client books, stores the attendee join link, and cancels that meeting when the booking is cancelled or replaced. It never stores or sends Zoom's privileged host start link. If the provider is temporarily unavailable, the booking remains confirmed and the meeting link stays visibly retryable.
Connect an email server
SMTP provides outbound client email without requiring Google or Microsoft. Enter the public server hostname, port, username, SMTP password or key, sending address, and sender name. Cygnetree tests the login and TLS connection before encrypting and saving the credentials.
For safety, SMTP connections require TLS and a public endpoint on port 465, 587, or 2525. Cygnetree rejects local, private-network, link-local, cloud-metadata, and multicast destinations. Use a provider-issued app password or restricted SMTP key instead of a primary account password when your provider supports one.
SMTP is a sending connection, not an inbox connection. Cygnetree does not request IMAP credentials, host your mailbox, or claim that an SMTP login can synchronize incoming mail. Replies to a Cygnetree-generated client-message notification can return through its signed, contact-specific Reply-To address when that platform route is configured. For a shared inbox with incremental history, attachments, and sender review, connect the mailbox through Gmail or Outlook instead. If your provider offers only SMTP, keep general incoming correspondence in that provider's inbox; the Cygnetree portal remains the reliable in-product reply path.
Use managed email or connect Resend
Client correspondence can use Cygnetree-managed Resend delivery immediately. It is a sending service, not a hosted mailbox: replies use your configured reply address or the secure Cygnetree portal.
To send from a domain and Resend account your business controls, verify that domain in Resend, create a restricted sending API key, then open Settings → Integrations → Resend. Enter the key, verified sending address, sender name, and optional reply-to address. Choose whether the profile is for the workspace, a shared identity, or your account. Send test and save Resend must deliver a test to your signed-in address before Cygnetree encrypts and stores the profile.
Once selected, your Resend profile uses your provider allowance and sending reputation. Cygnetree does not silently use managed delivery if that profile is rejected. Fix or change the selected profile, then retry the pending send.
To receive provider-native delivery and engagement evidence, expand the saved profile's
Delivery and engagement events section. Create a Resend webhook using the connection-specific
endpoint shown there, select email.delivered, email.failed, email.bounced, and
email.complained, then optionally add email.clicked and email.opened. Save its signing secret
in Cygnetree. Delivery outcomes update the exact message receipt. Clicks and opens are recorded
separately as low-confidence provider observations and never claim that a person read the
message; click evidence retains only the destination hostname, not the full URL or query. Do not
select inbound receiving: a workspace-owned Resend profile sends mail but does not become a hosted
inbox. The secret belongs only to that connection, and replacing it immediately invalidates the
old one.
Connect an inbound webhook
An owner or admin can create an independently signed inbound endpoint under Settings → Integrations → Inbound webhook. Use it with Zapier, Make, a website, or another system that can send an HTTP request. Cygnetree shows the signing secret once. Copy it to the sender before leaving the page; only an encrypted copy remains in Cygnetree.
Every request must include:
x-cygnetree-event-id: a unique ID for this exact delivery;x-cygnetree-event-type: a stable lowercase event name such aswebsite.lead_created;x-cygnetree-timestamp: the current Unix time in seconds; andx-cygnetree-signature:sha256=followed by the hex HMAC-SHA256 oftimestamp.raw_request_body, using the webhook secret.
Requests more than five minutes old, invalid signatures, oversized bodies, and reused event IDs with a different payload are rejected. An exact duplicate is acknowledged without starting the automation twice. Create an automation with A connected app sends an event and optionally enter one event type to react only to that kind of delivery.
The endpoint and secret belong to this workspace connection. They are not Cygnetree platform credentials and cannot affect another workspace. Rotate signing secret immediately invalidates the prior secret; update the sender before its next event. Disconnecting removes the encrypted secret and disables the endpoint. Cygnetree retains a hash and processing status for replay protection, not the arbitrary webhook body.
Register an outbound webhook
Under Settings → Integrations → Webhooks, add a destination name and its public HTTPS URL. Cygnetree resolves the hostname and rejects HTTP, embedded credentials, unusual ports, local names, and private, link-local, metadata, or multicast addresses. The verification secret is shown once; copy it to the receiving system so it can verify Cygnetree's signatures.
Automation recipes choose this registered destination by name. They cannot store or call an arbitrary URL. Every delivery includes the same event ID, event type, timestamp, and HMAC signature headers described above. The event ID is deterministic for the automation run and step, allowing the receiver to suppress a retry without guessing from the body.
Use Test connection to revalidate the encrypted credential and public destination. Confirmed secret rotation invalidates the old verification secret immediately but preserves the registered URL. Disconnecting removes the encrypted URL/secret and makes recipes that depend on it fail visibly until another registered destination is selected.
Choose workspace defaults
Each connected tool shows whether it is the current sending, calendar, meeting, or provider default. Select Make default to change the workspace behavior deliberately. Existing profiles remain connected. A personal profile cannot become the workspace default.
Storage destinations have an additional safety rule: connecting storage does not immediately move files or make it the upload destination. Test it and choose Use for new uploads under Storage and migration.
Choose calendars that block time
Open Settings → Integrations, find a connected Google Calendar or Outlook Calendar profile, and choose Availability calendars. Select every calendar whose busy windows should block that profile's booking availability. This is useful when one person separates client appointments, personal commitments, travel, or shared-team events across calendars.
The profile remains one identity and one workspace or personal default. Selecting additional calendars does not authorize another account, change another member's profile, or create duplicate appointments. Cygnetree combines identical busy windows and refreshes the selected calendars in bounded provider requests. If any selected calendar becomes inaccessible, the sync fails visibly instead of silently presenting time as available.
Choose team identity rules
Owners and admins can set a separate rule for client email, the primary calendar, and video meetings:
- Workspace only always uses the workspace or shared default.
- Personal optional lets each member select Use for me, then falls back to the workspace default when that personal profile is unavailable.
- Personal required refuses the operation until that member has a healthy personal profile. It never borrows another person's identity.
Members may connect, test, reconnect, select, and disconnect profiles they own. They cannot create or change workspace/shared profiles or another member's personal authorization. A member's manual client message uses that member's sending selection; unattended business workflows continue to use the workspace default unless their owning feature has an explicit host or assignee.
Understand email delivery
Ordinary client correspondence uses the selected tenant-owned Resend, Gmail, Outlook, or SMTP profile. If no tenant profile is selected, it uses clearly identified Cygnetree-managed Resend delivery so evaluation, onboarding, reminders, and automations work without mail-provider setup. Cygnetree does not host a tenant mailbox and does not silently use the managed sender after a selected tenant provider fails.
Client messages can include up to ten clean workspace-library or client-project files, totaling 2.5 MB. Cygnetree sends the files through the selected Resend, Gmail, Outlook, or SMTP profile—or managed Resend when no tenant profile is selected—and also keeps them with the message in the client portal. Larger files remain safely shareable through the portal instead of being silently dropped from email.
Gmail and Outlook reply synchronization and shared-inbox assignment are available when an administrator explicitly enables a workspace/shared inbox profile. A successful send proves that the provider accepted the message; it does not prove that a human received or read it. Cygnetree keeps that Accepted state until stronger provider evidence exists. Outgoing client messages carry a private Cygnetree tracking header, and an exact delivery-system notice that preserves that identifier can mark the matching message bounced or complained without guessing from an email address. Duplicate and stale events cannot regress the durable receipt. Provider-native final delivery and complaint evidence still depends on what that connected provider exposes.
Finish storage setup
One provider consent can add Drive, OneDrive, or SharePoint to the storage page. Malware scanning must be ready before an external destination can become the default for new uploads. SharePoint also requires its site and library selection.
Changing the storage default affects new uploads only. Use the migration planner to move existing files without changing their Cygnetree links. Suite-created storage cards are labeled Managed through Integrations. Cygnetree will not let you remove that storage tool or disconnect its provider profile while files still depend on it; migrate the files first.
Recover a connection
Use Test connection to verify an OAuth identity, Resend sender, or SMTP login immediately. Cygnetree also runs a bounded daily credential check and records the last healthy time, last failure, and safe error code. It never displays the saved token or password.
For Google or Microsoft, expand Reconnect or change connected tools, select the exact tools to keep, and continue to the provider. Sign in with the same external account; Cygnetree rejects a different account so it cannot silently replace a profile. Removing one tool clears only that tool's defaults. Disconnecting the entire profile removes the saved credential and all of its defaults, but does not delete provider data.
An active booking page that depends on a Meet or Teams default must be changed or paused before that tool can be removed. Publishing or resuming a booking page also checks that client email and the selected video-meeting provider are healthy.
Do not delete external folders or revoke provider access until Cygnetree shows another healthy default and any planned file migration is complete.