The challenge
A US commercial bank wanted Microsoft 365 Copilot to answer questions over the data the business runs on: SQL Server, Cloudera CDP, Oracle, Teradata and MongoDB. Copilot reasons only over what has been indexed, so the value depended on getting that data into the Microsoft Graph index. The risk was never ingestion. It was access.
Every one of those sources answers "what may this person see?" at query time, from who is asking: row-level security, Oracle Virtual Private Database, Teradata security constraints, a redacting MongoDB view, Ranger policies over Hive and HDFS. A search index answers it once, at write time, then serves one copy to everyone entitled to it. Configuration cannot reconcile the two.
The mismatch fails silently, which is what makes it expensive. The crawl succeeds, the index looks complete, Copilot answers fluently, and somewhere in the corpus sits a row the reader was never entitled to see.
The solution
Five connectors run on one shared engine, with no source technology named anywhere in the shared code, so a sixth source is an adapter rather than a rewrite.
Every connector refuses a source that enforces access per user. Not warns, refuses, with a non-zero exit. Oracle stops on Virtual Private Database, Label Security, Real Application Security or Data Redaction; Teradata on row or column security constraints; MongoDB on views, which may redact on the caller’s roles without the driver knowing, and on encrypted fields, which index as ciphertext; Cloudera on Ranger security zones, on any policy carrying exceptions, conditions or validity schedules, and on a tag-service policy that denies or masks.
Access runs through one Active Directory group per source, under a condition stated rather than assumed: the group must be entitled to the least-accessible item in the corpus, because anything narrower is over-granted the moment it is indexed. That makes crawl scope, and the refusals that police it, the primary defence rather than a backstop. Revocation moves from the source to Active Directory, a cost accepted openly.
Guards fire on the dangerous direction only. Over-granting stops the run and under-granting is logged, because a guard that fires on the safe direction teaches operators to switch guards off.
The results
The SQL Server connector is deployed at the client and the rest is in progress. Cloudera CDP is not live: a tag-service policy on its QA cluster carries an item condition, so two controls fire and the run stops. That is the design working, with the blocker in code rather than in a document. Oracle, Teradata and MongoDB are built, tested and released, but have never run against a real instance.
One architectural limit belongs in the record because engineering does not remove it. A Microsoft Graph access list is a static snapshot with no validity window, so a time-conditioned source policy cannot be mirrored by any connector. Crawl cadence bounds the drift between index and source intent; nothing closes it.