Hyran Data

Microsoft 365 Copilot

Hyran Data

Security and data handling

Identity and tenant checks happen before every data read.

The Microsoft agent is another governed client of Hyran Data. It does not receive database credentials and it cannot choose an organization from a prompt, URL, or request field.

Request path

One user, one approved organization, one bounded request.

  1. 01

    Microsoft 365 Copilot

  2. 02

    WorkOS and customer Entra sign-in

  3. 03

    Hyran access checks

  4. 04

    Tenant-scoped Hyran Data transaction

  5. 05

    Bounded result with provenance

Controls

Access fails closed when any required fact is missing.

Token

Exact issuer and audience

Hyran validates expiry, subject, issuer, and the exact Hyran MCP resource before accepting an OAuth token.

Tenant

Current membership

WorkOS organization membership, active Hyran Data entitlement, region, role, client, and scope must all agree.

Database

Forced row-level security

The verified organization enters transaction-local database context. Missing tenant context rejects the request.

Tools

Role-aware catalog

Microsoft users discover only the Hyran tools approved for their client, role, products, datasets, and organization.

Limits

Rows, bytes, rate, and concurrency

Per-user and organization limits protect data volume, database capacity, and operating cost.

Rollback

Client and tenant kill switches

Hyran can disable one tool, client, organization, or all OAuth MCP access without disabling API-token clients.

Data handling

What moves, what Hyran records, and what stays out.

Sent to Microsoft

The user's question and the bounded tool result needed to answer it are processed in the customer's Microsoft 365 Copilot environment under that customer's Microsoft policies.

Recorded by Hyran

Hyran records operational metadata such as organization, user, client, tool, outcome, duration, rows, bytes, quota decision, and correlation ID.

Excluded from Hyran telemetry

Hyran's MCP telemetry does not store prompts, credentials, access tokens, or returned customer row values.

Customer agreements and an approved data-processing schedule control final retention, residency, subprocessors, support, and incident obligations. Request the current enterprise security packet before production approval.