Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
First Recon AI runs alongside the security and productivity stack you already operate. It exports evidence to your tools and governs the AI path; it does not replace what already works.
First Recon logs decisions, not content: sealed, metadata-only evidence, exported to your existing SIEM. Enforcement stays in the runtime; your SIEM gains full visibility into DLP events, detections, policy actions, and agent activity.
First Recon builds RAG over your enterprise content through a permission-aware connector: SharePoint, Google Drive, Confluence, and others. Content is discovered, ingested under explicit include and exclude scoping per site and drive, indexed, and retrieved, with source-system permissions enforced at both index time and retrieval time. Answers are screened by the runtime before they reach the model or the user.
Copilot is a family of products, and the answer differs by surface. The matrix below states, per surface, how First Recon integrates and where enforcement happens.
| Copilot surface | How First Recon integrates | Where enforcement happens | Status |
|---|---|---|---|
| Direct integration: one-time admin consent for the organization, then each user connects their own Microsoft identity. Copilot becomes a governed model in the workspace; every send passes runtime policy first. | In the governed path, before anything reaches Copilot | Available | |
| Governed at the endpoint by the Endpoint Security, with visibility into use and allow, warn, or block policy by app and team. | At the endpoint | Endpoint Security | |
| Coding-assistant traffic is governed where it crosses First Recon surfaces: on managed devices via the Endpoint Security, and on the gateway path for workspace usage. | Device and gateway | Via governed surfaces | |
| No direct integration today. Studio-built agents are covered where their interactions traverse governed surfaces; direct integration is a roadmap conversation with your team. | Governed surfaces only | Via governed surfaces |
A workspace administrator grants org-wide consent once; the connection is tracked with clear status.
Each user connects their own Microsoft identity before Copilot activates for them.
Admins see integration status and active versus expired user connections at a glance.
Copilot traffic passes the same residency and data-protection enforcement as every provider before anything is sent.
Tokens refresh automatically; anything that cannot refresh is flagged for re-authorization instead of failing silently.
MCP-based tools, CLI and coding-agent traffic, and third-party orchestration are governed where they cross First Recon surfaces.
First Recon integrates with your identity provider for authentication and group or role mapping, so access follows the identity model you already run rather than a separate one to maintain.
Every connector First Recon ships, at security-review depth, browsable per connector.