Enterprise Generative Search — Azure and Open Source  ·  View 14 of 41  ·  Structure

Source Connector Matrix

How each of the six sources is read, authorised, refreshed and parsed.

Editable source SVG draw.io All views
Change detection Authorisation model Freshness class Parse path Microsoft 365 Graph delta query 8.1 M items Item ACL to Entra groups expanded at index 5 minutes P95 collaboration class Native text plus Tika OCR only when scanned Confluence and Jira CQL updated-since 1.4 M pages Space and page restrictions mapped to groups 15 minutes collaboration class Storage-format HTML macro-aware ServiceNow Knowledge sys_updated_on poll 220 k articles User criteria to groups role-derived 15 minutes support class HTML plus attachments article as one unit Document archive Blob change feed 26 M scanned pages Folder ACL, inherited coarse by design 24 hours archive class Document Intelligence layout and tables Databricks governed tables Not indexed at all queried live Unity Catalog grants caller passed through Query time no staleness No parse, rows are evidence adapter, not chunker Public web and regulators Sitemap and ETag crawl 40 domains Public, tenant-wide no ACL to carry 24 hours external class Readability plus Tika boilerplate stripped Source Connector Matrix — How Each Source Is Read, Authorised and Refreshed Databricks is deliberately not indexed. A number that can be computed correctly on demand should never be embedded and allowed to go stale. v 1.0 · owner Data and AI Global Practice

Decisions

  • Freshness is declared per source as a class, not tuned per connector. Collaboration content is five minutes; the archive is 24 hours; governed tables are query-time because they are not indexed at all.
  • Every source's native permission model is normalised to Entra object ids at ingest. A source whose permissions cannot be expressed that way is not onboarded until it can be.
  • The document archive keeps folder-level ACLs deliberately. Synthesising finer permissions than the source actually has would be inventing an authorisation model, not propagating one.

Numbers

  • 8.1 M Microsoft 365 items, 1.4 M Confluence and Jira pages, 220 k ServiceNow articles, 26 M scanned archive pages, 40 crawled external domains.
  • Steady-state change rate is about 240,000 items a day; a full rebuild is 14 hours and about 1,900 USD of GPU time.

Risks

  • Source throttling is the commonest cause of silent staleness. Each connector publishes its own lag against its class, and the lag — not the job status — is what alerts.
  • ServiceNow user criteria do not map cleanly onto groups in every case. Where the mapping is lossy the platform errs towards excluding content, and the exclusions are reported to the source owner.