In software, a connector is a ready-made link that lets one system read from, or act in, another without custom code. There are two common kinds, and the difference matters.
Connectors that copy
Data integration tools use connectors to copy data from a source system into a warehouse or data platform on a schedule. Fivetran describes its connectors as "pre-built ELT pipelines that extract data from a connector source like Salesforce or SAP and replicate it into your connector destination of choice like a data warehouse or lake", and advertises connectors for "750+ sources". Once copied, the data is protected only as well as the destination protects it. Licence and retention terms from the source don't travel with it unless someone carries them across.
Connectors that give an AI live access
AI assistants now use connectors to reach a user's tools directly. Anthropic's help centre explains that "Connectors let Claude access your apps and services, retrieve your data, and take actions within connected services." Many use the open Model Context Protocol. Nothing is copied in advance. The assistant reads what it needs, when it needs it. What it reads does land in the conversation and its logs, a copy of a kind.
The key safeguard is permissions. The same page states: "If someone can't access a specific file, channel, or record in the source system, the connector can't reach it from Claude either." Not every connector works this way. Microsoft's Copilot Studio documentation offers two settings. "User authentication" is for data "that only the user has access to". "Agent author authentication" is for cases where access "is implicit, or for low-risk use cases", and the tool then runs with its builder's sign-in. A live connector should act as the user, with the user's access, and no more. Some don't, which is why you check.
Permissions are half the question. The other half is what the assistant can be steered into doing with them. The OWASP GenAI project warns that "indirect prompt injections occur when an LLM accepts input from external sources, such as websites or files". An email or document the assistant reads can carry instructions of its own.
In a timber business
Both kinds are useful. Copying connectors bring ERP, scale and production data together for reporting. Live connectors let an assistant check a contract, a load or an invoice on request. The risks differ: a copying connector can leak data into a less protected store, and a live one can take actions if it is allowed to.
What to check
Ask which kind a connector is. Ask whose permissions it uses, and whether it can write as well as read. And ask where its activity is logged, so you can see what it accessed and when.
Quarri's security page sets out how customer data is isolated, encrypted and audited.
Sources
- Anthropic, "Use connectors to extend Claude's capabilities", Claude Help Center: support.claude.com
- Microsoft Learn, "Configure user authentication for tools", Copilot Studio, last updated 7 April 2026: learn.microsoft.com
- Fivetran, connector directory: fivetran.com
- OWASP GenAI Security Project, "LLM01:2025 Prompt Injection": genai.owasp.org
Quarri is an AI-native data platform for the timber supply chain. It connects buying, production, sales and inventory for forest management, sawmill, wood products and pulp, paper and packaging operators.