You copy an 87-message HelioPay vendor thread into grok.com while still logged in as your personal X account, on cafe Wi-Fi, because the Outlook window felt slow. Four attachments, 2.4 MB, including HelioPay_MSA_v3_redline.pdf. The summary returns in 40 seconds. So does the thought that Legal never approved that paste, and that the cafe router now sat on the path of a contract you have not signed.
This is Part 10 of the Grok series. Parts 8 and 9 named doors and models. This part is the work-mail version of the same map: install one office add-in, do one safe task, keep mail out of a personal toy account. Grok for Outlook, as of writing, is a Microsoft 365 add-in (Marketplace listing WA200011330, announced July 21, 2026) for paid X and SuperGrok users. Word, Excel, and PowerPoint have sibling add-ins. Google Workspace has an add-on for Docs, Sheets, and Slides (July 24, 2026 post). Labels and eligibility move. Re-check the Outlook announcement and x.ai/grok/outlook the week you install.
What you’ll learn
- The difference between an add-in, a grok.com connector, and a chat upload
- How to get the Outlook panel up from zero on a work account
- What Word, Excel, and PowerPoint are for, in one honest sentence each
- Where the Google Workspace add-on fits, as of writing
- Permission rules that keep a vendor thread out of a personal login
- One worked task: summarize a thread you own, and do not send
If your company blocks add-ins, this post still helps: you will know what you are asking IT for, and you will know what not to do in the cafe while you wait.
Add-in vs connector vs chat upload
Three ways Grok can see work files. They are not interchangeable, and they do not share a safety story.
An add-in lives inside the office app. Outlook, Word, Excel, PowerPoint, or the Google Workspace hosts. You open a thread or a file you already have permission to see. The panel talks to that item. Send stays on the Outlook Send button. That is the shape you want for mail.
A connector lives on grok.com. You OAuth a service so chat can search mail, calendar, or a drive without you attaching the file every time. The catalog as of writing includes Outlook Mail and Calendar, OneDrive, Gmail, Google Calendar, Drive, Teams, SharePoint, and others. Docs: Grok connectors. On Grok Business and Enterprise, a team admin must provision a connector before members see it. That admin step is the whole point. A personal grok.com login that you OAuth to work Outlook is a policy argument, not a productivity hack.
A chat upload is you, copying. Paste the thread. Attach the PDF. The model only sees what you threw over the wall. This is the HelioPay failure. It is fast. It also bypasses every mail retention, DLP, and “work account only” rule your company paid for. Use it for files you would forward to a vendor without blinking. Do not use it for redlines. Part 2 mapped grok.com as a chat app. That does not make it a mail client.

| Surface | What it can touch | Approval rule |
|---|---|---|
| Outlook / Office add-in | The item you have open in a work Microsoft 365 app | Work account. You click Send. The add-in does not |
| Google Workspace add-on | The Doc, Sheet, or Slide you have open | Work Google account. You accept changes in the file |
| grok.com connector | Mail, calendar, or drive you OAuth, within what admin enabled | IT / admin on Business and Enterprise. Personal OAuth to work mail is a no |
| Chat upload on grok.com | Exactly what you paste or attach | Treat it as a forward. If you would not send it to a stranger, do not upload it |
Rule of thumb: If the file is already in Outlook on a work account, summarize it in the Outlook panel. If you had to export it to upload it, stop and ask whether that export is allowed.
Outlook panel from zero
Goal: see Grok beside a thread you own, on a work Microsoft 365 mailbox. Not on a personal Hotmail you use for newsletters. Not on the X app.
- Confirm you are in the work Outlook (New Outlook or the Microsoft 365 web app, as of writing). Personal / consumer mail is the wrong tenant.
- Confirm your Grok plan is one the vendor currently lists for the add-in (paid X or SuperGrok on the July 21, 2026 post). If IT will assign a work-owned X or SuperGrok seat, wait for that. Do not mix a personal SuperGrok into a work mailbox to “just try it.”
- Open the listing from x.ai/grok/outlook or Microsoft Marketplace WA200011330. Get it / add it with the work account.
- If install fails, that is often admin policy, not a broken link. Screenshot the error. Ask IT whether Grok is an allowed add-in. Do not fall back to cafe paste while you wait.
- Open a thread you already own. Skip anything with Legal, HR, health, or a customer list in the subject. A scheduling thread you started is enough.
- Open the Grok panel from the add-ins entry. Ask: “List decisions, owners, and what is waiting on me. Do not draft a send.” Read the answer against the thread. Close the panel.
That is first run. You have not sent mail. You have not connected grok.com to the mailbox. You have not handed the intern a pattern of “dump the PST into chat.” The vendor’s own copy says Grok can draft replies in your voice and that nothing sends until you hit Send. Believe the second half. Make it a team rule even if the first half is true.
Attachments are in scope for the add-in as of the announcement (it can read them). That does not make every attachment fair game. A 2.4 MB redline is still a redline. Start with a thread whose attachments are a calendar .ics or a one-page agenda. Save HelioPay until counsel says the add-in is in policy.
Word, Excel, and PowerPoint in one sentence each
These are add-ins in the same family. They are not a second copy of grok.com hiding in the ribbon. One sentence each, then the wrinkle you will hit.
Word: Ask Grok to rewrite a section you already own, then paste or accept only the sentences you would say out loud in a meeting. The wrinkle: it will smooth hedges you meant to keep (“about 40 cases” becomes “we are fully stocked”) unless you tell it not to invent numbers.
Excel: Ask it to explain a formula or draft a helper column, then check the math on three rows by hand. The wrinkle: office-model demos look great on stage; a margin that divides by list price including tax will still be wrong by a few percent, and you will be the one in the forecast meeting.
PowerPoint: Ask for a five-slide arc from a bullet outline, then replace every chart number from the sheet of record. The wrinkle: native shapes and tidy layouts do not make a 6.4% figure true. If the figure is not in your outline, it is a guess with clip art.
Grok 4.5 and 4.6 launch posts both talk up Excel models, Word, and PowerPoint. Treat that as “it can try.” You still own formulas, citations, and the deck that goes to a customer. Part 9’s model chooser applies in the ribbon too: a short rewrite does not need a ritual about 4.6. A messy 12-tab book might. Either way, the add-in does not become the file of record.
Google Workspace add-on
If your work lives in Google, not Microsoft, the parallel as of writing is a Workspace add-on that covers Docs, Sheets, and Slides (July 24, 2026). Same grain: open the file on a work account, ask for a draft or an explanation, accept in the file yourself. Same refusal: do not export a confidential Doc to upload it into a personal grok.com thread because “we don’t have Outlook.”
Connectors on grok.com can also reach Gmail, Calendar, and Drive. That is the other door, and it is the one admins care about. For a first week, prefer the add-on inside the file you already have open. OAuth from a personal Grok login to a work Drive is how you recreate the cafe paste with better branding.
Parity between Microsoft add-ins and the Google add-on will drift. Do not write a 40-row comparison. Pick the host your company already pays for. Install one. Do one task. Then stop installing.
Permissions and work accounts
Two accounts, two brains. Your personal SuperGrok on a phone is a consumer product. Your work Microsoft 365 or Google workspace is a company system. Crossing them is the HelioPay story. IT can allow the add-in in the work tenant without ever blessing grok.com as a dump zone. Ask for the first. Do not freelance the second.

Connectors add a third identity: the OAuth grant. On Business and Enterprise, admin provisions first. On a consumer Grok login, you can still click through an OAuth screen that looks official. “Looks official” is not “is allowed.” If you do not know whether your company has Grok Business, assume it does not, and keep work mail in Outlook.
Data handling still follows Part 6. Public platforms, training toggles, and retention are not identical across chat, add-ins, and API. This post will not invent a DPA. It will say: work content stays on work accounts, in the add-in, with a human on Send. If Legal needs a paper trail, they need the vendor’s current terms, not a screenshot of a cute summary.
Minimum ask for IT, if you need a ticket:
- Allow the Grok Outlook add-in (WA200011330) for a named pilot group on the work tenant
- Do not enable work Outlook connectors on personal grok.com logins
- Block, or at least warn on, forwarding vendor PDFs to consumer AI sites if you already have DLP for that
- Name an owner who will revoke the add-in if the vendor changes training or retention language
Worked task (summarize, don’t send)
Elena owns vendor ops. The HelioPay thread is 87 messages, four people, subject HelioPay MSA v3. She is allowed to read it. She is not allowed to park it on a personal laptop in a cafe. After IT enables the add-in on her work mailbox, this is the task.
- Open the thread in work Outlook. Leave the redline PDF where it is. Do not download-to-upload.
- Open the Grok panel. Prompt: “Summarize decisions, owners, dates, and open questions. Quote a short phrase when you name a number. Do not draft a reply. Do not invent a deadline.”
- Read the summary against the last 15 messages. On Elena’s run, the panel said finance sign-off is Friday. The thread said “Friday if Legal is done, else it slips.” She writes the “if Legal is done” clause back in by hand.
- Copy four bullets into a note she owns: decision, owner, date, open question. The note is hers. The model does not get a Send.
- If she needs a reply, she types it. She may ask the panel to tighten two sentences she wrote. She hits Send herself. She does not click anything that looks like “send this draft.”
Time: about 12 minutes once the add-in is installed. The cafe paste was 40 seconds and a policy incident. The 12 minutes is the work. The 40 seconds was the shortcut that created the 2.4 MB problem.
What Elena does not ask on first run: archive my mailbox, junk the noise, write the counter-redline, search the web for HelioPay’s SOC 2 and drop it in the thread. Those are later, under policy, with a human still on Send. First run is summarize a thread you own.
Common mistakes
- Pasting work mail into personal grok.com because the add-in is not installed yet. Wait, or summarize by hand.
- OAuthing work Outlook to a personal Grok login and calling it “the connector.” On Business/Enterprise, admin goes first.
- Letting a draft send. If you cannot find the Send button with your own finger, you are not done reviewing.
- Starting on the 87-message legal thread. Start on a scheduling thread you created.
- Trusting Excel or Sheets output without three-row arithmetic. Add-ins draft. You check.
- Installing Word, Excel, PowerPoint, Outlook, and the Google add-on on day one. Pick the host you live in.
- Assuming SuperGrok on your phone is the same permission as a work Microsoft tenant. It is not.
How to practice / next step
Install one add-in on a work account, or file the IT ticket with the listing id. Then run Elena’s five steps on a thread you own that has no Legal in the subject. Write down one factual miss the panel made. That miss is the training. If you cannot install, do not practice on cafe Wi-Fi. Practice writing the prompt you will use later, on a fake thread you compose yourself.
Next in this series: xAI Console and API: only if you build apps. That is the last product-map door. If you only wanted inbox summaries, you can skip a key forever. If your next sentence is “we should wire Grok into Slack for the whole company,” read Part 11 before you mint anything. Hub: analyticsmadesimple.com/series/grok. Everyday writing, without the inbox, starts in Part 12 after the map.
Quick recap
- Add-in: inside Outlook or the office file. Connector: grok.com OAuth. Upload: you pasted it
- Install Outlook on a work Microsoft 365 account. Marketplace WA200011330 as of writing
- Word rewrites sections, Excel explains formulas, PowerPoint outlines slides. You still own numbers
- Google Workspace add-on is the Docs/Sheets/Slides parallel. Same work-account rule
- Business/Enterprise connectors need admin. Personal OAuth to work mail is out
- First task: summarize a thread you own. Do not send. Check one date by hand
- If the add-in is blocked, wait. Cafe paste is not a fallback
Sources
Research and further reading used for this article:
- xAI: Grok for Outlook (July 21, 2026 announcement, eligibility as of that post, Send stays with you)
- xAI: Grok Outlook product page (current install path; re-check before you ticket IT)
- xAI docs: Connectors (OAuth connectors, admin provision on Business/Enterprise)
- Grok FAQ (plan questions that move)
- xAI: Introducing Grok 4.5 (office add-in mentions for Word, Excel, PowerPoint; treat as “it can try”)
- grok.com (the chat upload surface this post tells you not to use for vendor redlines)
- Analytics Made Simple: Learn (related paths on this site)
