Token
Exact issuer and audience
Hyran validates expiry, subject, issuer, and the exact Hyran MCP resource before accepting an OAuth token.
Microsoft 365 Copilot
Hyran Data
Security and data handling
The Microsoft agent is another governed client of Hyran Data. It does not receive database credentials and it cannot choose an organization from a prompt, URL, or request field.
Request path
Microsoft 365 Copilot
WorkOS and customer Entra sign-in
Hyran access checks
Tenant-scoped Hyran Data transaction
Bounded result with provenance
Controls
Token
Hyran validates expiry, subject, issuer, and the exact Hyran MCP resource before accepting an OAuth token.
Tenant
WorkOS organization membership, active Hyran Data entitlement, region, role, client, and scope must all agree.
Database
The verified organization enters transaction-local database context. Missing tenant context rejects the request.
Tools
Microsoft users discover only the Hyran tools approved for their client, role, products, datasets, and organization.
Limits
Per-user and organization limits protect data volume, database capacity, and operating cost.
Rollback
Hyran can disable one tool, client, organization, or all OAuth MCP access without disabling API-token clients.
Data handling
The user's question and the bounded tool result needed to answer it are processed in the customer's Microsoft 365 Copilot environment under that customer's Microsoft policies.
Hyran records operational metadata such as organization, user, client, tool, outcome, duration, rows, bytes, quota decision, and correlation ID.
Hyran's MCP telemetry does not store prompts, credentials, access tokens, or returned customer row values.
Cookies
We use essential cookies to run the site. With your OK, we also use analytics cookies (Vercel) to understand traffic — including how visitors arrive via campaign links. Privacy