SharePoint Connector - Architecture — Unique AI Documentation

SharePoint Connector - Architecture

High-Level Architecture

Key Components

In Short

Dynamic Site Configuration

The connector supports two configuration sources:

When using SharePoint list configuration:

Microsoft Graph (External SaaS)

SharePoint REST (External SaaS)

SharePoint Connector (Internal Service, Node.js)

Unique AI (Internal Service)

Unique IDP (Identity Provider)

Cluster-Internal Deployment

In cluster-internal mode:

Multi-Origin Support

Note: Multi-origin support is not available in the current release line.

Scenarios

Alias Scenario As of Version
Same Microsoft tenant / multiple SharePoints Client has multiple SharePoint instances to sync Not yet supported
Multiple Microsoft tenants / multiple SharePoints Connect different tenants to Unique Not yet supported

Multi-Origin Until Supported

Until native multi-origin support is available, clients can achieve the same functionality by deploying the connector multiple times, each configured for a different origin/SharePoint.

Container Platform

The connector runs on any container orchestrator. Unique provides a versioned Helm chart for Kubernetes deployment.

Clients desiring to run the connector outside Kubernetes can use the Helm chart as documentation and inspiration.

Connectivity

All external communication is encrypted via HTTPS (TCP:443).

Authentication Endpoint

https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token

Used to obtain OAuth2 tokens for Microsoft Graph and SharePoint REST APIs.

Microsoft Graph Endpoints

Endpoint Use Case
graph.microsoft.com/v1.0/sites/{siteId} Fetch site information
graph.microsoft.com/v1.0/sites/{siteId}/drives Fetch document libraries
graph.microsoft.com/v1.0/drives/{driveId}/items/{itemId}/children Fetch folder contents
graph.microsoft.com/v1.0/drives/{driveId}/items/{itemId}/content Download file content
graph.microsoft.com/v1.0/sites/{siteId}/lists Fetch site lists (for ASPX pages)
graph.microsoft.com/v1.0/sites/{siteId}/sites Discover child subsites (when subsitesScan enabled)
graph.microsoft.com/v1.0/drives/{driveId}/items/{itemId}/permissions Fetch item permissions
graph.microsoft.com/v1.0/groups/{groupId}/members Fetch group members

SharePoint REST Endpoints (Permission Sync Only)

Endpoint Use Case
`{tenant}.sharepoint.com/{sites teams}/{siteName}/_api/web/sitegroups/getById({groupId})`
`{tenant}.sharepoint.com/{sites teams}/{siteName}/_api/web/sitegroups/getById({groupId})/users`

Hosting Models

Self-Hosted (SH)

Aspect Responsibility
Connector hosting Client
Entra App Registration Client
Unique deliverable Container image, Helm chart, documentation

Single-Tenant: Client-Hosted

Client uses Unique Single Tenant but hosts the connector:

Single-Tenant: Unique-Hosted

Unique hosts the connector on behalf of the client:

System Scalability and Resource Sizing

The Node.js service operates with the following resource allocation:

These settings ensure the service has sufficient capacity for expected workloads.

Note: The connector is an IO-driven, low CPU workload. Unique AI ingestion services are typically the bottleneck, depending on embedding models used.

Standard References