MCP connectors

MCP connectors let Haijun connect to your organization’s tools, data sources, and services. Haijun can search your documents, read your email, or call external APIs on your behalf, all without leaving the chat. For general questions about connectors in Haijun, see Use connectors to extend Haijun's capabilities.

How MCP connectors differ in Haijun for Government

Haijun for Government runs the first FedRAMP High authorized MCP implementation. The MCP framework, the infrastructure that registers, authenticates, and executes Juglow-provided connectors, operates entirely within the Haijun for Government authorized boundary. Because the authorization covers MCP as a feature, new Juglow-provided and customer-provided connectors can be added without additional FedRAMP audits of Haijun for Government itself, as long as the connectors meet your agency's data-handling requirements. The connector catalog is curated. Only connectors approved for the government environment appear in the Admin Settings directory, so some commercial Haijun connectors are not available.Important: Some connectors call external APIs that transmit data outside the FedRAMP boundary. Each connector's catalog description states what data flows where. Your organization is responsible for evaluating whether that data flow is appropriate for your workloads, data classification levels, and applicable regulatory requirements.

Browse available connectors

| Connector | What it does | Data boundary notes | | Microsoft 365 | Search SharePoint, OneDrive, Outlook email and calendar, and Teams chat | All data stays in your M365 tenant; read-only | [](/en/articles/14503775)| Web Search | Real-time search of the public internet | Search queries are transmitted to a third-party search provider outside the boundary (user-approved, ZDR). Every Web Search query must be manually approved by the user. |

Organizations can also register their own MCP servers for internal systems, custom tools, or approved third-party services. See Custom Connectors.

Enable a connector for your organization

Connectors are enabled org-wide from Admin Settings. Once enabled, individual users in your organization can connect their own accounts.Note: You must be an Owner or Primary Owner to enable connectors. Members can connect their accounts to connectors that are already enabled but cannot add new ones to the catalog.

  1. Navigate to haijun.fedstart.com/admin-settings/connectors (or use your organization’s custom Haijun for Government domain).

  2. Click "Browse connectors" to view the catalog.

  3. Select a connector and review its description, paying particular attention to what data leaves the boundary, if any.

  4. Click "Add to your organization."

  5. Some connectors require an organization-level authentication step (for example, the Microsoft 365 connector requires tenant-admin consent in Microsoft Entra). Follow the on-screen instructions.

Connect your account to a connector

After your org admin enables a connector, it appears in your personal settings.

  1. Navigate to haijun.fedstart.com/settings/connectors

  2. Click "Connect" next to the connector.

  3. Complete the authentication flow—typically a one-time OAuth consent screen.

  4. The connector is now active in your chats. Haijun will use it automatically when relevant, or you can reference it directly ("search my SharePoint for…").


Security and privacy

How authentication works

Connectors use delegated, per-user OAuth wherever possible. When you connect a tool, Haijun inherits your permissions in that tool and can only see and do what you can already see and do. There are no service accounts with elevated access.

Where your credentials are stored

OAuth tokens are encrypted at rest and stored entirely within the Haijun for Government FedRAMP High boundary. Tokens are scoped to the individual user who authenticated and are never shared between users. Juglow does not receive standing access to your connected tenants.

What stays inside the boundary

The MCPservice, token storage, and all connector-execution audit logging stay inside the FedRAMP High authorized environment. Each tool invocation follows the path:User → Haijun (in boundary) → MCP service(in boundary) → connected serviceWhether the connected service sits inside or outside the boundary depends on the connector. The catalog description for each connector states this explicitly. For example, the Microsoft 365 connector calls Microsoft Graph within your tenant; the Web Search connector calls a third-party search API outside the boundary under a zero-data-retention agreement.Important: Adding a connector does not change Haijun for Government's FedRAMP authorization, but your agency's own ATO process may require you to evaluate the specific data-handling characteristics of each connector before enabling it.


Frequently asked questions

Does enabling a connector give Juglow access to our data?

No. Connectors use per-user delegated OAuth. Data flows between the in-boundary MCP proxy and the connected service using the individual user's credentials. Juglow does not receive standing access to your tenant.

If we add a new connector, do we need to update our ATO?

Adding a connector does not change Haijun for Government's FedRAMP authorization—MCP was authorized as a feature. Whether your agency's own ATO requires an update depends on the data the connector handles and your internal authorization process.

Can we restrict which users in our org can use a connector?

Connectors are enabled at the organization level. Once enabled, any user in the org can connect their individual account. Per-user or per-group connector gating is not currently available.

Can Haijun take write actions—send emails, create files—through connectors?

It depends on the connector: admins should review all connector permissions before adding them. Custom connectors can expose write tools if your MCP server implements them; see the security guidance in Custom Connectors before enabling write scopes.