-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Admin - Connector Allowlist/Blocklist, SharePoint
-
None
Problem
When the Rovo–SharePoint connector is enabled, it automatically indexes both SharePoint documents and user profile data from Microsoft Entra ID (Azure AD). The user profile fields currently indexed include:
• Display Name
• Job Title
• Department
• Email Address
• Hire Date
There is currently no configuration option to index SharePoint documents only, while excluding user profile/people data. The existing admin controls (allowlists/blocklists) operate at the site, subsite, and document library level — they do not allow exclusion of user profile data as a data type.
Why This Matters
Many enterprise organisations — particularly those in regulated industries or subject to strong data privacy legislation (GDPR, Works Council agreements, internal HR data governance policies) — cannot legally or ethically allow personal employee data such as hire dates, job titles, and email addresses to be ingested into a third-party AI search platform without explicit consent or a clear legal basis.
This creates a hard adoption blocker: organisations want to use Rovo for SharePoint document search but are unable to proceed because of the bundled user profile indexing.
Requested Feature
Provide an admin-level configuration option to independently toggle user profile (Entra ID people data) indexing on or off, separately from document indexing.
For example:
• A toggle in the connector settings: "Index user profiles from Entra ID" — On/Off
• Or the ability to select which data types to index during the connector setup ("Choose content to include" step): Documents, People, or Both
When user profile indexing is disabled:
• Only document objects and their metadata should be indexed (name, URL, created date, collaborators, body)
• Permission-aware search should remain functional
• The connector should still use Entra ID permissions to enforce access control, without storing user profile attributes
Workarounds Available Today
None that fully address this use case:
• Site-level allowlists/blocklists — control which SharePoint sites are indexed, but not what data types are indexed from those sites
• Permission enforcement — Rovo respects existing SharePoint/Entra ID permissions, but user profile data is still indexed regardless
Expected Impact
• Unblocks enterprise customers with strict data privacy and compliance requirements from adopting the Rovo–SharePoint integration
• Particularly relevant for EMEA customers subject to GDPR and Works Council agreements
• Aligns Rovo with industry best practice for enterprise AI search tools, where granular data-type controls are increasingly expected
Related / References
• Public docs: https://support.atlassian.com/organization-administration/docs/connect-sharepoint-to-rovo/
• Allowlist/blocklist announcement: https://community.atlassian.com/forums/Atlassian-Intelligence-articles/The-Microsoft-SharePoint-Rovo-Connector-now-supports-allowlists/ba-p/3028651
• Rovo data privacy guidelines: https://support.atlassian.com/rovo/docs/rovo-data-privacy-and-usage-guidelines/
- resolves
-
CES-164893 Loading...