Notate includes an optional set of AI features: an AI assistant for editing PDFs and notes, and live meeting transcription. They run on your organization's own Microsoft Foundry (Azure OpenAI) resource, so prompts, document content and meeting audio never leave your Microsoft tenant, and all AI usage is billed to your own Azure subscription. The features are off until you complete the one-time configuration below, and they are controlled by app policy.
What the AI can do
The assistant works inside the Notate PDF editor and the note editor. A user opens a document or note, taps the sparkles button in the top bar to open the chat pane, and asks in plain language. The same panel can record and transcribe a live meeting.
-
In a PDF: summarize and answer questions about a document, highlight text and add sticky-note comments, mark sensitive information for redaction, create new documents, and fill and sign forms. Redactions and signatures are applied only after the user confirms.
-
In a note: summarize, draft, rewrite and restructure text, and convert Apple Pencil handwriting to typed text. Every change is a normal editor edit that can be undone.
-
Meeting transcription: capture and transcribe a meeting live into a note or the chat panel, then optionally turn it into formatted notes with a summary, decisions and action items. Audio goes only to your tenant's Azure transcription service.
In the PDF editor, the assistant saves a checkpoint before every change, so almost anything it does can be rolled back. The two actions that cannot be undone, applying redactions and flattening, are always confirmed first.
How AI configuration works
Notate’s AI runs on your organization’s own Microsoft Foundry (Azure OpenAI) resource. There is no API key to manage or distribute. Each user authenticates with their own Microsoft Entra ID identity; Notate requests a short-lived token on their behalf, and your Azure resource decides what each user can do based on the role you assign them.
-
Access is controlled entirely by role assignment (remove a user's role and their AI access stops immediately);
-
Every request is attributable to an individual user in your Azure logs;
-
No standing secret is ever stored by Notate.
|
Capability |
What it does |
Azure model it needs |
|---|---|---|
|
AI Assistant |
Draft and edit PDFs and notes from plain-language requests; read scanned pages and handwriting. |
A chat model with tool or function calling; multimodal recommended. |
|
Meeting transcription |
Capture and transcribe a meeting live, then optionally format it into structured notes. |
A realtime transcription model ( |
You can enable either or both. They may run on the same Foundry resource or on separate resources and regions.
Prerequisites
-
An Azure subscription with a Microsoft Foundry (Azure AI Foundry or Azure OpenAI) resource, or permission to create one.
-
Permission to grant Microsoft Entra admin consent for your organization.
-
The Owner or User Access Administrator role on the Foundry resource, to assign Azure roles.
-
Notate licensing for the AI features. Confirm with your Notate representative at Shafer Systems.
Step 1: Create your Azure resource and deploy the models
-
In the Azure portal, create a Microsoft Foundry resource (also listed as Azure AI Foundry or Azure OpenAI), or use an existing one.
-
For the AI Assistant, deploy a multimodal chat model that supports tool or function calling, for example GPT-4o, GPT-4.1 or newer. Function calling is required for document editing, and vision is required to read scanned pages and convert handwriting.
-
For meeting transcription, deploy the realtime transcription model
gpt-4o-transcribe-diarizein a region that supports the Azure OpenAI realtime API. It can share the resource with the chat model or live on a separate resource or region. -
Record the endpoint, deployment name and API version for each capability you enabled. You will enter them as Notate application policies in Step 4.
Step 2: Grant Notate consent to sign users in
Notate needs your tenant's consent to request Azure AI tokens on behalf of your signed-in users. This grants Notate no standing access, only the ability to mint short-lived, per-user tokens. The same consent covers both chat and transcription.
-
Open the Microsoft Entra admin center and go to Enterprise applications.
-
Find Notate and open its Permissions page.
-
Select Grant admin consent for your organization and approve.
This consents to the delegated permission "Access Cognitive Services API as organization users". Your Notate representative can send a direct admin-consent link instead if you prefer.
Step 3: Give users access to the resource
-
Open your Foundry resource, go to Access control (IAM), Add, Add role assignment.
-
Select the role Cognitive Services User.
-
Add the users, or preferably a security group, as members.
-
Assign at the resource scope: the Foundry resource itself, not a sub-project inside it.
Choose Active, not Eligible. If your organization uses Microsoft Entra Privileged Identity Management, the role assignment has an Assignment type setting. Select Active with a Permanent (or your standard long-lived) duration. An Eligible assignment grants nothing until the user activates it and then expires, so AI fails with a permission error.
If chat and transcription are on separate resources, assign the role on both. Role assignments take up to about five minutes to take effect. Use Cognitive Services User; do not substitute Cognitive Services OpenAI Contributor, which also grants model-management rights your users do not need.
Step 4: Set the Notate AI application policies
Deliver the values from Step 1 to the app as Notate application policies in your MDM. Within each capability, both the endpoint and the deployment are required; if either is missing, that capability stays off.
|
Capability |
Policy key |
Value |
|---|---|---|
|
AI Assistant (chat) |
|
The chat endpoint from Step 1 |
|
AI Assistant (chat) |
|
The chat deployment name |
|
AI Assistant (chat) |
|
The chat API version |
|
Meeting transcription |
|
The transcription endpoint from Step 1 |
|
Meeting transcription |
|
The |
|
Meeting transcription |
|
The transcription API version |
On the "Whisper" name. The transcription policy keys are named Whisper for historical reasons. Point them at the current realtime model, gpt-4o-transcribe-diarize; the key name does not have to match the model.
Native AI Foundry resources. Most resources work with Notate's default token audience, https://cognitiveservices.azure.com. Newer "native" Azure AI Foundry resources, typically those provisioned in 2026 or later in regions such as Central US, instead require https://ai.azure.com and reject the default with a 401 ("audience is incorrect"). If yours is one of these, also set the policy key azureOpenAIAudience to https://ai.azure.com.
Once the policies reach the device, the features are available the next time the user signs in. The master switch allowAI must also be on.
Verifying it works
AI Assistant: have a user open a PDF or note, open the AI Assistant panel and send a message. A reply means chat is configured. Transcription: in the editor, tap Record meeting notes, accept the microphone prompt and speak; live text in the transcript means transcription is working.
|
Symptom |
Cause and fix |
|---|---|
|
AI Assistant shows "Not configured" |
The chat policy keys have not reached the device. Confirm |
|
Record meeting notes is grayed out |
No transcription deployment is configured. Confirm both |
|
"Principal does not have access" (401) |
The user lacks the Cognitive Services User role, the role is Eligible rather than Active, or it was assigned less than about five minutes ago. Re-check Step 3 on both resources if chat and transcription are separate. |
|
Error mentioning "audience is incorrect" (401) |
The resource is a native AI Foundry resource needing the |
|
Transcription never produces text |
The deployment is not |
|
Repeated sign-in or consent prompts |
Admin consent has not been granted. Complete Step 2. |
The full list of AI policies is in Notate MDM application policy configuration.