{
  "title": "Calendar Sync Setup",
  "images": [],
  "text": "<p>Calendar Sync lets EnRep push Surveyor Diary appointments, holidays, and meetings into each connected surveyor or administrator Microsoft Outlook or Google Calendar. EnRep stays as the master diary, so entries should still be created, moved, and removed in EnRep.</p><div class=\"alert alert-info\"><strong>Set this up once:</strong> this card is for the organisation-level connection details. Surveyors and administrators connect their own calendar afterwards from their profile.</div><h3>Redirect URL</h3><p>Copy the Redirect URL exactly as shown in the Calendar Sync card.</p><p>Add that exact value as a <strong>Web</strong> redirect URI in Microsoft Entra and as an authorised redirect URI in Google Cloud.</p><h3>Microsoft Outlook setup</h3><ol><li>Open Microsoft Entra admin centre.</li><li>Go to <strong>Applications</strong>, then <strong>App registrations</strong>, and create a new registration for EnRep Calendar Sync.</li><li>Set the supported account type required by the organisation. For most work accounts, use accounts in this organisational directory only.</li><li>Add the Redirect URL from this card as a <strong>Web</strong> redirect URI.</li><li>Go to <strong>Certificates &amp; secrets</strong> and create a new client secret. Copy the secret value immediately.</li><li>Go to <strong>API permissions</strong>, choose <strong>Microsoft Graph</strong>, then <strong>Delegated permissions</strong>.</li><li>Add <strong>Calendars.ReadWrite</strong>, <strong>MailboxSettings.ReadWrite</strong>, <strong>offline_access</strong>, and <strong>User.Read</strong>.</li><li>If the organisation blocks user consent, an Entra administrator must grant admin consent for these delegated permissions.</li><li>Copy the Directory tenant id, Application client id, and client secret into this card.</li><li>Switch on Microsoft calendar sync and save.</li></ol><div class=\"alert alert-info\"><strong>Calendar colours:</strong> MailboxSettings.ReadWrite lets EnRep create three Outlook categories for appointments, holidays, and meetings. After adding this permission, reconnect each Microsoft calendar once so the new permission is granted.</div><div class=\"alert alert-warning\"><strong>Security note:</strong> use delegated permissions for this feature. Do not use Microsoft application permission Calendars.ReadWrite unless a separate organisation-wide design has been approved.</div><h3>Google Calendar setup</h3><ol><li>Open Google Cloud Console.</li><li>Create or select a project for EnRep Calendar Sync.</li><li>Enable the <strong>Google Calendar API</strong>.</li><li>Configure the OAuth consent screen for the organisation.</li><li>Create an OAuth client id for a <strong>Web application</strong>.</li><li>Add the Redirect URL from this card to the authorised redirect URIs.</li><li>Copy the OAuth client id and client secret into this card.</li><li>Switch on Google calendar sync and save.</li></ol><div class=\"alert alert-warning\"><strong>Google verification:</strong> Google Calendar access uses sensitive OAuth permissions. While the Google app is in testing, each surveyor Google account must be added as a test user. If the app is published but not verified, Google may show an unverified app warning. For normal client rollout, submit the Google OAuth app for verification with a privacy policy, verified domain, scope justification, and a short demo of the EnRep calendar connection flow.</div><p>EnRep requests access to create, update, and remove events in each connected calendar. Surveyors and administrators connect their own account from their profile.</p><h3>After setup</h3><p>Open each surveyor or administrator profile, choose Microsoft or Google, then use <strong>Connect calendar</strong>. Once connected, new and changed diary entries are processed automatically.</p><div class=\"alert alert-warning\"><strong>Important:</strong> do not ask users to edit EnRep diary entries in Outlook or Google. External calendars are a one-way view of the EnRep diary.</div>"
}
