Meridian Financial Group
A Graph integration that passed enterprise security review first try
Compliance-grade Microsoft Graph integration syncing advisor calendars and correspondence into Meridian's record-keeping platform.
- Industry
- Finance
- Services
- Microsoft Graph · API integration · Cloud (Azure)
- Timeline
- 10 weeks
40k+
items synced daily
0
compliance incidents since launch
1st
pass on security review
The problem
Regulation required Meridian to retain advisor–client correspondence and meeting records. Advisors worked in Outlook; compliance worked in a records platform; the bridge between them was a nightly manual export that missed edits and deletions entirely.
Two previous vendor attempts had died in IT security review — over-broad Graph permissions, no tenant-level controls, unclear data flow.
The build
We built the sync on Graph change notifications and delta queries rather than polling — 40k+ items a day without touching rate limits. Permissions were scoped to the minimum application-level set, documented per-scope with justification, and access ran through a reviewed Entra ID app with certificate credentials in Key Vault.
The security-review documentation was a deliverable, not an afterthought: data-flow diagrams, retention behavior, failure modes. Meridian's IT team approved in a single round.
The result
In production for 18 months with zero compliance incidents. Deletions and edits are captured within minutes instead of never. The pattern was solid enough that Meridian commissioned a second integration — Teams meeting records — on the same foundation.
“Our IT security review usually takes vendors three rounds. CraftXo's Graph integration passed in one.”
James Okonkwo
Head of Engineering, Meridian Financial Group
Start a project
Have a similar problem?
Tell us about it. A senior engineer replies within one business day.