Zellis Intelligent Assistant Arrives in Microsoft Copilot, Teams and Outlook
Zellis announced the launch in a press release from Bristol distributed by PR Newswire. The company said Zellis Intelligent Assistant, the AI assistant built into its ZellisONE platform, is now available via Microsoft Copilot. According to Zellis, users can ask their questions wherever they already work – whether that is ZellisONE, Copilot, Teams or Outlook. Technology Record covered the launch a day later with the same framing: users stay in Microsoft's apps instead of switching to a separate HR portal.
Zellis sells mainly to UK and Irish employers. It describes itself as a provider of AI-enabled HR, workforce management (WFM), payroll and benefits software, and says its products help pay one in seven people in that region. In 2025 the company merged Zellis, elementsuite and Hastee into a single platform, ZellisONE. It describes ZellisONE as covering HR, workforce management, pay, talent and benefits, with the Intelligent Assistant at its centre.
Availability is limited to that customer base. Zellis states that the Intelligent Assistant with Copilot integration is available with ZellisONE. There is no implementation or migration project required: it arrives as an upgrade to the platform customers already run. The announcement gives no rollout schedule, pricing, supported ZellisONE tiers or required Microsoft Copilot licence. Customers should ask Zellis for those details before planning a deployment. The vendor is steering prospects to demonstrations.
One small discrepancy between the two write-ups: the Zellis release identifies Microsoft's Ruthy Kaidar as EMEA Regional Director at Microsoft, while Technology Record calls her a managing director for Europe, the Middle East and Africa. Her supporting quote is the same in both. She said the integration lets organisations give staff easier access to workforce insights and actions while maintaining appropriate security and governance controls.
Pay Queries, Overtime Totals and Right-to-Work Checks Move Into Copilot Chat
Zellis offers four example requests, each tied to a different role:
- An employee asks why this month's take-home pay is different from last month's and gets the change explained.
- A manager building next year's budget asks for overtime across their team for the current quarter.
- An HR business partner asks which departments have outstanding right-to-work checks, instead of running a report.
- A store manager asks who is available for a Saturday shift.
In Technology Record's summary, the assistant responds to queries about salary changes, overtime, right-to-work checks, employee availability and other questions workers might have. These are the requests that usually end up as HR tickets, emails to payroll, or manual report pulls. Zellis pitches the integration at frontline settings such as shop floors, hospital wards, distribution centres and sites, where staff may already use Teams but rarely log into an HR portal.
The more consequential claim is about actions. Zellis says the assistant can act as well as answer, and that approvals for leave, contract amendments and pay adjustments are governed by the same permission and audit model as its answers. The company adds that customers control which capabilities are switched on and when. Technology Record describes the assistant as able to sign leave approvals and make contract amendments and pay adjustments.
Neither account explains how those actions work in practice. There's no detail on whether the assistant drafts a change for a human to confirm, sends it into an existing ZellisONE approval workflow, or commits it directly. Because Zellis makes action capabilities something customers switch on, a given deployment may be read-only until an administrator chooses otherwise. Organisations should settle how pay and contract changes are confirmed before enabling them.
Model Context Protocol Carries ZellisONE Permissions Into Copilot
Zellis says the integration runs on the Model Context Protocol (MCP), which it describes as an open standard for securely connecting AI assistants to external systems. It makes several security claims:
- Every request is authenticated against the user's existing ZellisONE permissions.
- Security is inherited from ZellisONE, not rebuilt inside Copilot.
- Answers come only from governed data.
- Every interaction is logged and auditable.
It gives two examples of the boundary. A manager can't see another team's data, and an employee can't see a colleague's. The release sums it up this way: the permissions, governance and audit trail that apply in the ZellisONE platform apply to every response.
That design choice matters. Microsoft's Copilot connector documentation describes two broad ways to bring outside data into Microsoft 365 Copilot. Synced connectors crawl external content and index it into Microsoft Graph, with each item carrying an access control list. Federated connectors use an MCP model to fetch data live, without indexing content into Microsoft 365. Microsoft says federated connectors suit "live, dynamic, or sensitive data sources that shouldn't be indexed," with the data staying in the source system and access respecting source permissions and OAuth 2.0 authentication.
Payroll and HR records clearly fall into the "sensitive, shouldn't be indexed" category. A live, permission-checked lookup against ZellisONE means salary data doesn't have to be copied into the tenant's search index to be answerable in Copilot. That reading follows from Zellis's MCP claim, though Zellis hasn't said whether it uses Microsoft's federated connector framework, a Copilot agent or plugin, or another MCP arrangement. The vendor's description is all that's available: no independent security review or technical specification has been published.
Microsoft's Copilot Connector Rules Show Where the Integration Needs Checking
Microsoft's documentation also shows why the actions deserve separate scrutiny. Its connector overview says federated connectors are currently read-only: they can search and fetch content but can't write data back. A note on the same page says write actions become available from early October 2026. Microsoft also says Copilot Chat is read-only by default and can't write to external systems unless extended with action connectors or plugins. Agents can take actions through Power Platform connectors or API plugins, and administrators control which connectors and actions each agent may use.
So Zellis's leave approvals, contract amendments and pay adjustments are running on something beyond a plain read-only data connector. Zellis hasn't said what. It could be an agent, a plugin, or a write-capable MCP arrangement. For administrators, the practical point is that the answer determines where actions are controlled: in Zellis's own capability switches, in the Microsoft 365 admin centre's agent and connector controls, or in both.
Microsoft's guidance on connector permissions also explains why "inherited security" needs checking in each tenant. On connectors that index content, Microsoft warns that permission settings such as granting access to Everyone can overshare sensitive content. It says administrators can review each connection under Copilot > Connectors > Your Connections in the Microsoft 365 admin center. There, a connector shows either "Only people with access to this data source" or "Visible to everyone." Microsoft notes that you can't change permissions after a connection is created. The fix is to delete the connection and recreate it with explicit permissions.
That procedure is for Microsoft 365 Copilot connectors in general. Nothing confirms that Zellis's integration appears there, so treat it as a model for questions to ask, not a documented Zellis setup step. The principle carries over, though. When HR data can be queried from Copilot, the identity mapping between a user's Microsoft Entra sign-in and their ZellisONE role becomes the security boundary. A misconfigured role in ZellisONE now shows up in Teams and Outlook as well as the HR portal.
What This Means for ZellisONE Customers and Microsoft 365 Admins
Only organisations already running ZellisONE with Microsoft 365 Copilot need to act. Everyone else is watching a sign of where HR software is heading. For ZellisONE customers, Zellis says there's no implementation project, but IT and HR should still decide together which users and which action capabilities to enable. They should also agree where the audit trail is reviewed before staff start asking pay questions in Teams.
A sensible sequence based on what's documented is to start with question-answering, check that role boundaries behave as Zellis describes, and only then turn on approvals and pay or contract changes. That's an inference from Zellis's statement that customers control which capabilities are switched on, not a vendor-published rollout plan. The questions to take to Zellis are the ones the announcement leaves open: required Copilot licensing, the integration architecture, the confirmation step for actions, and where logs live.
- The Copilot integration is available only to ZellisONE customers, and Zellis delivers it as an upgrade, not a migration.
- Users can query HR, workforce and pay data from Microsoft Copilot, Teams and Outlook as well as ZellisONE itself.
- Zellis says every request is checked against the user's existing ZellisONE permissions and every interaction is logged, so the accuracy of ZellisONE roles now also governs what appears in Microsoft's apps.
- Leave approvals, contract amendments and pay adjustments are available but switched on by the customer, and the confirmation flow for them hasn't been published.
- Microsoft documents federated MCP connectors as read-only until write actions arrive in early October 2026, so ask Zellis which mechanism carries its actions and where they are controlled.
- Pricing, licence requirements and rollout timing aren't in the announcement and need to come directly from Zellis.
Zellis's launch is a small, specific integration, but it shows Copilot turning into a front end for systems of record that hold some of an organisation's most sensitive data. The vendor's approach is sound on paper: live, permission-checked MCP access with no indexing of payroll data into Microsoft 365. With Microsoft opening write actions on federated connectors in early October 2026, more HR and finance vendors are likely to follow. For ZellisONE customers, the pay and contract actions deserve the most care, and they shouldn't be switched on until the confirmation flow and audit trail are understood.