Skip to content
Crafto

Meridian Financial Group

A Graph integration that passed enterprise security review first try

Compliance-grade Microsoft Graph integration syncing advisor calendars and correspondence into Meridian's record-keeping platform.

Industry
Finance
Services
Microsoft Graph · API integration · Cloud (Azure)
Timeline
10 weeks
.NETMicrosoft GraphAzure FunctionsSQL Server

40k+

items synced daily

0

compliance incidents since launch

1st

pass on security review

The problem

Regulation required Meridian to retain advisor–client correspondence and meeting records. Advisors worked in Outlook; compliance worked in a records platform; the bridge between them was a nightly manual export that missed edits and deletions entirely.

Two previous vendor attempts had died in IT security review — over-broad Graph permissions, no tenant-level controls, unclear data flow.

The build

We built the sync on Graph change notifications and delta queries rather than polling — 40k+ items a day without touching rate limits. Permissions were scoped to the minimum application-level set, documented per-scope with justification, and access ran through a reviewed Entra ID app with certificate credentials in Key Vault.

The security-review documentation was a deliverable, not an afterthought: data-flow diagrams, retention behavior, failure modes. Meridian's IT team approved in a single round.

The result

In production for 18 months with zero compliance incidents. Deletions and edits are captured within minutes instead of never. The pattern was solid enough that Meridian commissioned a second integration — Teams meeting records — on the same foundation.

Our IT security review usually takes vendors three rounds. CraftXo's Graph integration passed in one.

James Okonkwo

Head of Engineering, Meridian Financial Group

Start a project

Have a similar problem?

Tell us about it. A senior engineer replies within one business day.