Finance workflow | October 6, 2026

An approved connector is not an approved financial conclusion

Microsoft Copilot can now reach more financial-services sources. Finance still has to preserve source rights, retrieval time, units, periods, currency, internal-versus-external status, calculation logic, conflicts, and a named human release decision.

FP&AData provenanceDeterministic tie-outOne-click AI pack

One-click AI pack

Export the financial-data connector evidence workflow

Paste this read-only pack into ChatGPT, Claude, Gemini, Microsoft Copilot, or another enterprise-approved AI tool. It creates an evidence package from authorized sources; it does not approve access, perform authoritative accounting, or release a financial conclusion.

More connectors create more provenance work

Microsoft's September 2026 Copilot update added financial-services connectors and agents spanning company financials, risk analytics, estimates, credit analytics, market information, private-company data, payments, and other specialist sources. That can shorten the distance between a finance question and relevant evidence. It also creates a new failure mode: a polished answer can blend sources with different rights, timestamps, definitions, and economic meanings before the reviewer notices.

Microsoft's current connector gallery includes real-time federated sources such as D&B Finance Analytics and Fiscal.ai. Its architecture distinguishes federated connectors, which query an external source at runtime, from synced connectors, which ingest content into Microsoft Graph for indexing. Both can surface citations. Neither model tells Finance whether a cited value is comparable with internal actuals, licensed for redistribution, current for the decision date, or safe to publish.

Current FP&A discussions show the practical gap. Teams may have an approved Copilot license but no approved ERP connector; analysts report useful drafting and research tasks while warning against asking a language model to perform authoritative calculations. These are practitioner anecdotes, not adoption data. They are enough to show that “the company approved the tool” does not define an approved finance workflow.

Connector approval answers how data may travel. Finance approval answers whether a specific conclusion may leave the room.

The right control is an evidence contract. Every material statement in the draft should resolve to a source identity, authorized retrieval path, timestamp, definition, unit, period, currency, transformation, deterministic calculation where applicable, and named reviewer. The model can help assemble that package. It cannot approve its own sources or conclusions.

Know which connector path produced the answer

A synced connector copies external content into Microsoft Graph, where it can be semantically indexed and retrieved according to configured access controls. A federated connector queries the external provider at runtime; Microsoft documents that the content stays in the source system and citations refer to results returned through the provider's MCP server. These paths have different freshness, retention, investigation, and replay properties.

finance question + user identity
  -> approved Copilot tenant and agent
  -> connector router
       synced: external source -> Microsoft Graph index -> cited item
       federated: runtime query -> external provider -> cited response
  -> AI synthesis
  -> evidence register
  -> normalization + deterministic reperformance
  -> conflict and specialist review
  -> exact-version Finance release

For synced data, record the ingestion or refresh time and the external source date. A cited indexed item may be older than the user's question suggests. For federated data, record the exact query time and enough source context to replay or investigate the response. The same question can legitimately return a different value later because markets move, estimates change, a provider corrects data, or the runtime query produces a different result set.

Microsoft says Copilot respects the user's existing identity and permission boundaries, but that is not the same as least privilege. A source system or connector can be misconfigured. Microsoft specifically warns that a connector set to “visible to everyone” can overshare sensitive content, and current guidance says changing the access model may require deleting and recreating the connection. Finance should therefore preserve the permission mode, target groups, last review date, source-system ACL owner, and any temporary exception in the evidence pack.

QuestionSynced connectorFederated connector
Where is content queried?Microsoft Graph indexExternal source at runtime
Freshness evidenceSource date plus ingestion/refresh timeSource date plus exact runtime query time
Access evidenceGraph ACL mapping and source permissionsOAuth identity and provider authorization
Replay riskIndex may refresh or retain an older snapshotProvider result may change between runs
Release requirementPreserve cited item and index contextPreserve query, response evidence, and provider context

Build a source register before asking for analysis

The connector catalog should not be the source register. The catalog says what could be available; the register records what this decision actually used. Create one row for every internal system, external provider, public filing, human assumption, and model inference. Attach a stable evidence ID that can appear beside every material statement in the draft.

FieldExampleWhy it matters
Evidence IDEXT-REV-014Connects narrative, calculation, and approval
TypeLicensed external estimateSeparates it from internal actuals and public filings
Provider / connectorNamed source and federated connectorIdentifies rights, support, and failure owner
Entity and definitionCompany, segment, metric definitionPrevents false comparison of similar labels
Period / scenarioFY2027 consensus as of retrievalSeparates actual, budget, forecast, and estimate
Currency / unitsUSD millionsPrevents silent scaling and FX errors
Source and retrieval timePublished date plus UTC timestampSupports freshness and replay review
RightsInternal analysis only; no redistributionControls the deliverable and audience
Citation / record IDClickable item or provider identifierLets a reviewer inspect the exact basis
StatusVerified / conflict / stale / missingKeeps uncertainty visible

Freeze the query package too: exact question, filters, entity, segment, period, scenario, currency, units, time zone, model, connector, and retrieval timestamp. If an analyst changes the question after seeing the result, create a new version. Otherwise the team loses the ability to distinguish correction from outcome-driven prompt adjustment.

Licensing and contract terms belong in the register. Microsoft's connector terms state that customers remain responsible for third-party rights, licenses, and obligations. A user may be able to retrieve a number and still be prohibited from pasting it into a board deck, customer document, investor communication, or shared model. “Copilot showed it” is not a redistribution license.

Normalize definitions before comparing values

Many apparent disagreements are definition mismatches. Revenue may be reported, organic, constant currency, gross, net, recurring, recognized, booked, or estimated. Periods may be calendar, fiscal, trailing, year-to-date, or run-rate. A value may cover the consolidated entity, one segment, continuing operations, or a vendor-defined peer set. The AI should expose these dimensions, not smooth them away.

Use a transformation table approved before calculation. It should name the input evidence IDs, target definition, fiscal-calendar mapping, FX source and date, currency, unit scaling, sign convention, consolidation scope, eliminations, rounding, and formula owner. Preserve the raw values alongside normalized values.

calculation: peer_growth_gap/v1
inputs:
  internal_actual: INT-REV-021
  external_consensus: EXT-REV-014
normalization:
  period: FY2027
  currency: USD
  units: millions
  fx: not_applicable
  scope: continuing_operations
formula: (external_consensus / internal_actual) - 1
engine: approved-workbook-v42
expected: 0.083
tolerance: 0.0005
reviewer: fp-and-a-manager

Reperform every material calculation outside the language model. Use an approved workbook, SQL query, planning model, ERP report, or controlled analytics notebook. Store the formula, inputs, output, threshold, and tie-out. The model may explain the result after it ties, but should not be the only place the arithmetic exists.

Then separate statement types: retrieved fact, deterministic calculation, human assumption, model interpretation, or unresolved. This prevents an explanatory sentence from acquiring the status of a sourced number merely because both appear in one paragraph.

Worked example: a variance narrative with external context

Assume a Finance team is preparing a quarterly management review. Internal actual revenue is $920 million for the quarter, the approved plan is $950 million, and an external connector returns a peer-group growth estimate. The requested sentence is: “Revenue missed plan because market growth weakened.” The evidence does not support that sentence yet.

First, tie $920 million to the closed internal system of record and confirm entity, period, currency, unit, and close status. Reperform the plan variance: (920 / 950) - 1 = -3.16%. Next, register the external estimate with provider, retrieval time, peer definition, period, currency, and rights. Determine whether it measures the same market, period, and growth basis. If it is annual calendar-year consensus for a global peer set, it cannot directly explain one fiscal quarter for a different geography.

Claim componentEvidenceStatusAction
Revenue was $920mINT-REV-021, closed ERP/consolidationVerifiedTie to published management pack
Plan was $950mINT-PLAN-009, approved budget versionVerifiedConfirm latest approved plan
Variance was -3.16%CALC-004ReperformedLock formula and inputs
Market growth weakenedEXT-MKT-014Not comparableFind same-period same-market evidence or remove
Weak market caused the missNo causal evidenceUnresolvedRoute to commercial and Finance owners

A defensible draft might read: “Revenue was $920 million, $30 million or 3.16% below the approved plan [INT-REV-021, INT-PLAN-009, CALC-004]. External market evidence reviewed to date is not comparable on period and geography, so it does not support a causal market explanation [EXT-MKT-014]. Management is reviewing volume, price, mix, timing, and pipeline conversion.”

The AI added value by organizing evidence, exposing the unsupported causal jump, and drafting bounded language. It did not decide that the market caused the miss or turn an incomparable external estimate into support.

Release an exact artifact, not a floating answer

The final packet should identify the exact workbook, memo, deck, or narrative version being approved. Include its hash or stable version ID, source register, frozen query, connector configuration reference, deterministic calculation file, conflict log, reviewer decisions, unresolved limitations, approval time, audience, channel, retention location, and correction route.

Route specialist issues to specialist owners. The Controller owns accounting treatment and close status. FP&A owns plan and forecast interpretation. Treasury owns liquidity and market-risk assumptions. Tax owns tax positions. Legal/Compliance and data owners review contract rights and use restrictions. Investor Relations and disclosure owners control external communications. Internal Audit may test the control design and evidence but should not be made the operating approver.

Purpose and audienceThe requested use matches source rights, internal policy, and the named decision.
Permission evidenceConnector mode, ACLs, groups, owner, environment, and last review are recorded.
Source fitnessDefinitions, freshness, period, unit, currency, scope, and citation support each material statement.
Calculation tie-outMaterial figures were reperformed outside the model and reconcile within the approved threshold.
Conflict resolutionContradictory values and missing evidence have named dispositions, not silent averages.
Exact releaseThe named Finance owner approves one version, audience, channel, retention, and correction path.

If a source changes after approval, do not silently refresh the released artifact. Open a correction or update decision, rerun the deterministic calculations, and obtain approval for the new version. Runtime-connected data makes this especially important because a later reviewer may not see the same result.

Failure modes to test before launch

FailureMisleading appearanceControl
Stale synced contentCurrent question with an old indexed answerSource date plus ingestion/refresh timestamp
Federated result driftSame prompt appears reproducibleFreeze query, retrieval time, cited record, and raw response evidence
Visible-to-everyone connectorUser can access a convenient sourcePermission review, least privilege, recreate misconfigured connection
License mismatchData is retrievable and citableRights register and audience/output restriction
Period, currency, or unit mismatchNumbers look comparableApproved normalization table
Citation does not support exact valueLinked response looks groundedField-level source inspection and evidence ID
Model arithmeticFluent narrative includes plausible percentagesDeterministic reperformance and threshold
Contradiction suppressionOne coherent answerConflict log with named resolution owner
No correction pathApproved deck becomes permanent truthVersion, retention, withdrawal, and notification plan

Test the workflow with adversarial fixtures: stale source dates, swapped units, different fiscal calendars, a visible-to-everyone permission, expired rights, a citation that supports the topic but not the exact value, a restated filing, conflicting analyst estimates, and an internal actual that has not reached close status. The expected result is often a block or a narrower statement, not a prettier answer.

A 12-day controlled rollout

Days 1–2: inventory financial connectors, agents, data providers, tenants, environments, authentication, permissions, source owners, contracts, retention, and approved audiences. Identify whether each connector is synced or federated.

Days 3–4: select one low-risk use case, such as internal peer-context research for a management discussion. Exclude external communications, accounting entries, covenant decisions, trades, pricing, and tax positions from the first pilot.

Days 5–6: build the connector, rights, internal-source, and transformation registers. Create deterministic calculation templates and evidence IDs. Verify citations and permission boundaries with test users who should and should not see the source.

Days 7–8: run shadow cases. Finance completes the normal process while the AI prepares an evidence pack. Measure source-support rate, stale or incomparable evidence, calculation differences, conflicts, reviewer correction, time after review, and permission exceptions.

Days 9–10: run adversarial tests and a correction drill. Change a source value, withdraw a right, disable a connector, introduce a unit mismatch, and confirm the workflow blocks release or produces an attributable update.

Days 11–12: approve a narrow operating scope, train users on evidence types and stop conditions, assign access review and source owners, document the exact release gate, and set an expiry date. Expand only when retained evidence shows that the control works.

Release gate: no financial conclusion leaves the workflow until rights, permissions, source fitness, definitions, deterministic calculations, internal tie-out, conflicts, specialist review, exact version, and correction ownership are complete.

FAQ

Does an approved connector make its data approved for every Finance use?

No. It provides a configured access path. The purpose, user, audience, rights, data fitness, calculation, and release still require explicit review.

What is the difference between synced and federated connectors?

Synced connectors ingest content into Microsoft Graph for indexing. Federated connectors query the external provider at runtime and leave content in the source. Preserve the relevant refresh or query evidence for each.

Are Copilot citations sufficient evidence?

They are useful pointers, not the whole control. A reviewer must confirm that the cited record supports the exact value and definition, that access and use are authorized, and that transformations and calculations are reproducible.

Can Finance let Copilot calculate variances?

It can draft a calculation specification or explain a verified result. Material calculations should be reperformed in an approved deterministic tool and tied to frozen inputs.

Who signs off?

A named Finance owner approves the exact conclusion and artifact. Controller, Accounting, Treasury, Tax, Legal/Compliance, Investor Relations, data owners, and other specialists approve issues in their scope.

Sources and research notes

Current product and policy facts were checked October 6, 2026. Connector catalogs, licensing, terms, and permissions can change; verify the live tenant and source contract before use.

  1. Microsoft, What's New in Microsoft Copilot - September 2026 - current release catalyst and financial-services connector list.
  2. Microsoft-built connectors gallery - current connector descriptions, including finance sources.
  3. Microsoft 365 Copilot connectors overview - synced versus federated architecture and citations.
  4. Manage access permissions for connectors - ACL modes, oversharing warning, and current reconfiguration behavior.
  5. Microsoft 365 Copilot connectors terms of use - customer responsibility for third-party rights, licenses, and obligations.
  6. Data, privacy, and security for Copilot extensibility - identity boundaries, Graph data, DLP, retention, audit, and governance.
  7. Enterprise data protection in Microsoft Copilot - current organizational data protections and limitations.
  8. AICPA & CIMA, Ethics, accountancy, and AI-powered tools - professional responsibility and human judgment.
  9. r/FPandA, What do you even use AI for? - current practitioner discussion used as a pain signal, not prevalence evidence.
  10. r/FPandA, Company approved AI (Copilot) - current discussion of approved-tool constraints.

Signal boundary: the broad engine found 53 items and the focused Microsoft run found 67 across Reddit, Hacker News, and GitHub, but exact financial-connector discussion was thin. First-party Microsoft documentation controls feature claims. X and YouTube were unavailable in the local research environment. No adoption, accuracy, savings, or performance claim is made.