New in v1.1.0The mobile app is out of Beta and included in every edition — iOS and Android, signed in to your own instance.Read the announcement

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Product

Connecting your sources is the easy part. Deciding what to connect isn't.

SharePoint, Slack, Confluence, Google Drive and Notion now connect to RAGSuite in the open Community Edition, under Apache 2.0. Wiring one up takes minutes — which moves the hard part to where it always belonged: who is allowed to see what.

PRODUCT SharePointSlackConfluenceGoogle DriveNotionyour infrastructurenothing leaves itcited answer ragsuite.de
Jürgen Pietschmann
Jürgen Pietschmann AI Consultant
Published3 September 2026 Read9 min Product

SharePoint, Slack, Confluence, Google Drive and Notion now connect to RAGSuite directly — in the open Community Edition, under Apache 2.0. Point one at a source, authenticate, choose what to index. It takes minutes.

That sentence is the whole product announcement. The more useful half of this post is what it changes about the conversation — because when the wiring stops being the hard part, the hard part turns out to have been somewhere else all along.

The gap that made self-hosted AI theoretical

For the last year the sovereignty argument has had a practical hole in it.

You can agree entirely that your company’s knowledge should not be processed on someone else’s infrastructure. You can have the servers, the budget and the mandate. And then you look at where that knowledge actually is: a decade of process documents in SharePoint, the decisions that never made it into a document sitting in Slack threads, specifications in Confluence, and a shared drive that everyone is slightly afraid of.

An AI platform that cannot read those is an AI platform for a pilot project. It answers questions about the documents somebody had time to upload, which is not the same thing as answering questions about how your organisation works.

So the practical objection to self-hosting was rarely about sovereignty. It was: the convenient product already reads our SharePoint, and yours doesn’t.

That objection is now closed.

What a pilot indexes, and where the knowledge actually is What a pilot indexes versus where the knowledge actually livesTHE PILOTOne folder of documentsuploaded once, by handeverything currentworks beautifullynot where the knowledge livesTHE ORGANISATIONHandbook in SharePointDecisions in a chat threadSpecifications in ConfluenceA shared drive nobody ownsPricing rules in a mailboxTHE GAP IS THE PROJECT
The pilot is not wrong — it is just answering questions about a folder. The gap between the two columns is the reason so many projects stall after the demo.

What actually shipped

Five in-house connectors, alongside the ones that were already there:

  • SharePoint — the document estate most DACH enterprises actually run on
  • Slack — where the reasoning behind decisions tends to live
  • Confluence — specifications, runbooks, internal documentation
  • Google Drive — the shared-drive layer
  • Notion — increasingly the wiki of choice for younger teams

Plus what was already in place: Gmail, website crawling with job monitoring, direct document upload, an open Model Context Protocol server and client — that is the emerging open standard for attaching AI systems to tools — and the n8n automation integration.

All of it is Community Edition. Apache 2.0, unlimited users, no connector reserved for the paid edition. We have been explicit that connectors would never be a paywall, and this is the release where that stops being a promise and becomes a property of shipped code you can read.

The same release refreshed the product interface to match the RAGSuite design system — quieter, more consistent, and considerably less like three products that grew next to each other.

Connectors, open standards and the things not built yet What connects today, what is standards-based, and what is not builtSHIPPED · COMMUNITY EDITIONSharePoint · Slack · Confluence · Google Drive · Notion · Gmailwebsite crawl · document uploadOPEN STANDARDS · COMMUNITY EDITIONMCP server & client · REST API · webhooksn8nNOT SHIPPEDConnector Marketplace · packaged Teams / Slack apps
Three tiers, kept apart on purpose. The right-hand column is the one worth reading: an ingestion connector and a packaged app are different products, and only one of them exists.

The part nobody puts in a launch post

Here is the thing we would rather say plainly than have you discover in week three.

A connector reads what the account it authenticates with is allowed to read. That is the correct behaviour — an AI system that could bypass your permission model would be a security incident, not a feature. But it has a consequence that catches people out.

Most organisations’ access permissions are not a designed system. They are sediment. A site opened up for a project in 2021 and never closed. A channel that was private until someone needed to add a contractor. A shared drive where the folder structure encodes an org chart from two reorganisations ago. None of that caused visible harm, because finding something you were not meant to see required knowing it existed and going looking.

A search box that answers questions in natural language removes both of those requirements.

The answer surface is the service account's read scope What a connector can see is set by the account it authenticates withTHE SOURCE SYSTEMTeam sitePolicies libraryProject site — open since 2021Restricted HR sitereads asWHAT THE ASSISTANT CAN ANSWER FROMTeam sitePolicies libraryProject sitethe one nobody remembered
The assistant is not deciding what to reveal. It is answering from whatever the connecting account could already open — which is why the account you connect with is the security decision, not the model.

This is not an argument against connecting your systems. It is an argument for connecting them deliberately — and for treating the first index as what it genuinely is: the most thorough permissions audit your organisation has ever run. Most teams find something. Better to find it this way.

Three questions worth answering before you connect anything

  • What is the smallest useful scope? One SharePoint site, one Confluence space. Breadth is easy to add later and awkward to walk back.
  • Whose permissions is it running as? A service account inherits its own access. Give it the access the answer should have, not the access that makes setup easiest.
  • Who owns the decision to add a source? In a German company with a works council, this is a conversation to have early rather than retroactively — connecting a system where employees communicate is a different category of decision from indexing a document library.

None of those are technical questions. That is the point: the technical part is now genuinely short, so the governance part is the project.

Why this is a sovereignty story, not a features story

It would be easy to file this under integrations and move on. But the reason it matters is narrower than “more connectors is better”.

The trade every convenient AI product offers is: give us access to your knowledge and we will make it searchable. The access is the price. Once your SharePoint is being read by a service you do not run, the location of your data has been decided by a contract rather than by architecture, and the exit question — what happens to all this if the vendor changes terms, gets acquired, or simply stops — is no longer yours to answer.

What changed here is that you can now take the same convenience without the trade. The connector runs inside your deployment, reading your systems, producing answers with citations back to the source document, on hardware you control. And because the code is public, “nothing leaves your network” is something you can check rather than something you have to be told.

Where to start

If you already run RAGSuite, the connectors are in the Community Edition — update and they are there.

If you do not, the Community Edition is public on GitHub under Apache 2.0 and installs from npm. There is no account, no trial key and no form in front of it; the connectors page lists what attaches today, and the changelog records what shipped and when.

Start with one source. Preferably a boring one. The interesting part will not be the technology.

Frequently asked questions

Which connectors can I use, and do they cost anything?

SharePoint, Slack, Confluence, Google Drive, Notion and Gmail, plus website crawling and direct document upload. All of them are in the Community Edition under Apache 2.0 — free, unlimited users, no connector held back for the paid edition. What you pay for in the Enterprise Edition is the governance layer: single sign-on, role-based access control, full audit and compliance exports.

Does connecting SharePoint mean my documents leave my network?

No. RAGSuite runs on your own infrastructure, so the connector pulls content from your SharePoint into your own deployment. Nothing is routed through us — there is no telemetry and no licence-server call, and since the source is public you can verify that rather than take our word for it.

Will the assistant leak documents to people who shouldn't see them?

That depends on what you point it at, which is the honest answer and the reason this post exists. A connector reads what the account it authenticates with is allowed to read. If a SharePoint site is open to all staff but everyone assumed it was not, an AI search box will surface that far faster than a human browsing folders ever did. Scope the connection deliberately, and treat the first index as a permissions audit.

Can I put RAGSuite inside Microsoft Teams or Slack as an app?

Not yet — and we want to be precise about the difference. What shipped is an ingestion connector that reads content out of those systems. A packaged app that answers questions inside Teams or Slack is a separate piece of work and is not built. If someone tells you otherwise, they are reading the announcement too generously.

What about a source you don't support?

Two routes today. RAGSuite speaks the Model Context Protocol — an open standard for connecting AI systems to tools — as both a server and a client, so anything that speaks it can be attached. Or you can build against the open REST API. A marketplace for custom and community-built connectors is on the roadmap; it is not shipped, and we would rather say so than imply it.

Sources & further reading

  1. AI Connectors & MCP — what connects today
  2. Changelog — what shipped, when
  3. RAGSuite on GitHub — the Community Edition source, Apache 2.0
  4. Pricing — Community and Enterprise Edition

← All posts