Allows any collaborator to report a suspicious email with a single click, without leaving Outlook.
Automatically sends the reported email data to Whalemate for analysis.
Can forward the reported email to the configured incident response mailbox, without manual user action.
Turns every collaborator into an active participant in the organization's security.
Before installing the button in Microsoft, it is necessary to enable Whalemate's access to Microsoft services through Microsoft Graph.
Log in to the Whalemate platform
Navigate to General → Integrations → Microsoft Graph Access
Click on Grant Access
You will be redirected to the Microsoft permissions consent screen. Review and accept the requested permissions to authorize Whalemate
Once access has been granted successfully, you can continue with the installation of the report button for your organization
This step is mandatory and must be completed before installing the button. Without this access enabled, the add-in installation in Microsoft will not work correctly.
When installing the application, the following permissions will be requested:
Permission | What it's used for |
|---|---|
Sign in and read your profile | Authenticates the user and obtains basic information (name, email) to associate the reported email with the correct collaborator |
Read and write access to your mail | Allows access to the content of the reported email and, optionally, to move it to another folder (for example, Junk Email or Deleted Items) after reporting it |
Maintain access to granted data | Prevents the user from having to sign in every time, ensuring continuous operation |
Send mail on behalf of the user | Allows forwarding the reported email to the address configured in General → General → Incident notification email, only when that option is explicitly enabled |
The mail sending permission is used exclusively for automatic forwarding to the incident response mailbox, and only if that option is enabled. It is not used for any other purpose.
Log in to the Microsoft Admin Center with an administrator account
In the left side menu, go to Settings → Integrated Applications
Download this XML file
Click on Upload custom apps and follow the instructions to install the application as an Office Add-in
After installation, the button may take between 24 and 72 business hours to appear for all users in the organization.
Once the installation has propagated, the button appears in the top bar of Outlook when opening any email. If the shortcut does not appear, it can be found by clicking the Apps button within the same bar.
Can I install the button without configuring Microsoft Graph access first?
No. Configuring Microsoft Graph Access in Whalemate is a mandatory step prior to installing the add-in.
Can Whalemate send emails without my knowledge?
No. The email sending permission is used only to forward the reported email to the incident response mailbox, and only if that option was explicitly enabled by the administrator.
How long does it take for the button to appear after installing it?
Between 24 and 72 business hours to appear for all users in the organization.
I don't see the button in the Outlook bar, what should I do?
It can be found by clicking the Apps button within the same top bar.
Does this button automatically delete the email when reporting it?
It depends on the administrator's configuration in the report button settings screen (the "Delete email after reporting" option)
Do you have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap