Building to Microsoft's Copilot security and governance standard — and why it matters even if you use Claude
Microsoft defines a detailed security and governance standard for Copilot Studio, its agents and its connectors: identity and least privilege through Entra ID, data loss prevention and Advanced Connector Policies, data residency, auditing through Application Insights and Purview, action safety, and lifecycle governance.
We build Recursyv AI connectors to align with that standard for a simple reason: it is the most thorough model an enterprise security reviewer is likely to hold us against, and many of our prospects are mandated to use Copilot.
What alignment means in practice
- Identity — connectors authenticate via OAuth 2.1 through the customer’s own identity provider and request least-privilege, per-tool scopes. There is no parallel credential path.
- Action safety — read by default; write scopes kept separate; no delete or irreversible action is ever exposed as a tool.
- Data handling — zero customer business data at rest; processing pinned to a named Azure region per customer.
- Auditing — a per-call record (tool, tenant, user, timestamp, sanitised parameters, result) exportable to the customer’s SIEM.
Why it matters for non-Copilot customers
The controls above are properties of the connector, not the assistant. A Claude or ChatGPT customer gets exactly the same permission model, the same audit trail and the same zero-data-at-rest architecture. Aligning to Microsoft’s standard simply means we have designed to the most demanding published benchmark — and can show a security team the mapping.
Your AI already knows how to connect to your systems. The question is how well.
A year ago we had to explain that an LLM could reach into a service desk at all. Nobody needs that explanation now — so the conversation has moved to governance, permissions and the quality of the connector.
IntegrationWhy native ticket sync shortens mean time to resolution
Portals, shared mailboxes and phone lines all add latency to a ticket. Making the ticket appear natively in both systems removes it.
Talk to the people who wrote this.
Recursyv's engineers are a call away.
