Enterprise Social | Connector for Microsoft Viva Engage
What Is the Shield Connector for Viva Engage?
Microsoft Viva Engage — the evolution of Yammer, now fully integrated within Microsoft 365 as part of the Viva employee experience platform — is Microsoft’s enterprise social networking and community communication tool. Used across large regulated organisations to facilitate company-wide conversations, leadership communications, community discussions, and cross-functional knowledge sharing, Viva Engage enables employees to post updates, respond in threaded discussions, exchange direct messages, and collaborate within the Microsoft 365 environment they already use for email, Teams, and document management.
Shield’s connector for Viva Engage ingests posts, threads, direct messages, and associated metadata directly into Shield’s compliance platform via Microsoft’s native data export and compliance API, preserving the full fidelity of every community post, conversation thread, and direct message interaction. From the moment data enters Shield, it is available for surveillance, investigation, and eDiscovery, all within a single platform.
Viva Engage data does not exist in isolation. Where regulated employees use Viva Engage to discuss client matters, securities, market activity, or business decisions, those communications are directly adjacent to the regulated conversations happening simultaneously on Bloomberg IB, email, Teams, and voice. Shield ensures that Viva Engage is captured in the same compliance environment as every other channel — making the complete picture of internal communications available when it matters.
Why Viva Engage Compliance Is Complex
Viva Engage is not a straightforward channel to scope or surveil at the fidelity required for financial services compliance. Several specific challenges arise consistently across regulated firms:
- Scoping regulated business communications within internal social content. Viva Engage generates high volumes of internal communications across diverse topics — not all of which are in scope for regulatory recordkeeping. The compliance challenge is identifying and capturing the subset that constitutes regulated business communication: discussions about securities, market views, client matters, deal activity, and internal decisions with regulatory implications, while applying appropriate policies to general social content outside the perimeter. Undifferentiated capture of all Viva Engage activity produces unmanageable archive volumes; the absence of any capture leaves a material gap.
- Distinct communication types with different compliance profiles. Viva Engage generates several distinct communication types — community feed posts and threaded replies, direct messages between individuals, leadership communications, and file shares — each with different visibility, metadata structures, and compliance characteristics. Solutions that capture community posts while omitting direct messages, or that strip threading and reply context during ingestion, produce incomplete and difficult-to-interpret records.
- Microsoft 365 integration and data accessibility. As Viva Engage is integrated within Microsoft 365, its data is theoretically accessible through Microsoft Purview retention and eDiscovery tools. However, native Purview tooling is not purpose-built for the AI-powered misconduct surveillance and cross-channel correlation that financial services compliance frameworks require. A dedicated compliance connector is required to surface Viva Engage data within Shield’s surveillance environment alongside Teams, email, and Bloomberg.
- Enterprise social as a channel, employees may assume is unmonitored. Unlike email and Bloomberg IB — where employees are broadly aware of compliance capture obligations — enterprise social platforms are sometimes perceived as informal spaces outside the compliance archive. Where regulated employees discuss client matters, investment views, or business decisions on Viva Engage in the belief that the channel is unmonitored, the platform becomes a specific conduct risk that an unmonitored archive cannot address.
Key Features of the Shield Viva Engage Connector
Complete Multi-Format Capture. Shield captures all Viva Engage communication types within compliance scope: community feed posts and threaded replies, direct messages, leadership broadcasts, file shares, and associated engagement activity. All post content, message content, file attachments, and metadata are ingested in full, with zero data loss across all Viva Engage communication formats.
Full Metadata Preservation. Shield retains and enriches the complete Viva Engage metadata layer, including community and network identifiers, post and message IDs, thread and reply structure, sender and recipient identifiers, timestamps, file attachment metadata, and direct message conversation identifiers. This metadata is not stripped during processing — it is preserved and made fully searchable, ensuring that Viva Engage records are complete, accurately threaded, and legally defensible.
Granular Compliance Scope Configuration. Shield supports the application of granular, community-specific and communication-type-specific compliance policies to Viva Engage data — enabling firms to define which communities, groups, and message types are within compliance scope, and to apply differentiated retention and access policies to regulated content versus general internal social activity. This ensures the compliance archive contains the Viva Engage records that are genuinely relevant to regulatory obligations, without capturing the entire enterprise social estate indiscriminately.
Immutable, Audit-Ready Archive. All Viva Engage data captured by Shield is stored in an immutable, tamper-evident archive with a full audit trail of every access and action taken on the record. Records are indexed for rapid search and retrieval, supporting eDiscovery, regulatory examination responses, and internal investigations. Retention periods are configurable to meet jurisdiction-specific requirements, including the six-year standard under SEC Rules 17a-3 and 17a-4 and the five-to-seven-year requirements under MiFID II and MAR.
Out-of-the-Box AI Surveillance Models. Shield ships with pre-configured AI surveillance models for Viva Engage, targeting behaviours including market manipulation, information leakage, MNPI sharing, conflicts of interest, and personal misconduct — calibrated to the specific language patterns of internal enterprise social communications in financial services contexts. Models can be customised to reflect a firm’s specific risk appetite, restricted securities lists, and internal social media policy requirements.
Unified Cross-Channel Surveillance. Viva Engage does not sit in isolation from the rest of the communications estate. The same employees posting on Viva Engage are also communicating over Teams, email, Bloomberg IB, and other channels — often about the same clients, deals, and decisions. Shield ingests Viva Engage data into the same unified compliance platform as every other channel, enabling compliance teams to correlate internal social communications with trading and client-facing communications from all other sources. This cross-channel context is essential for accurate misconduct detection and defensible regulatory responses.
Regulatory Coverage
Viva Engage communications that relate to regulated business activity are classified as business records subject to capture, retention, and surveillance requirements under applicable regulatory frameworks:
- SEC Rules 17a-3 and 17a-4 — Broker-dealers are required to capture, preserve, and produce records of all communications related to their business, stored in WORM-compliant, non-rewriteable format with an audit trail, for a minimum of six years. Viva Engage posts and messages by regulated employees about securities, client matters, and business decisions are within scope.
- FINRA Rules 4511 and 3110 — Member firms are required to archive all communications relating to their business as such, with written supervisory procedures and full audit trail capability. Viva Engage communications between regulated employees about regulated business fall within this requirement.
- MiFID II Article 16(7) and Market Abuse Regulation (MAR) — Investment firms are required to retain electronic communications related to regulated activity for a minimum of five years and to monitor communications for indicators of market abuse — applicable to Viva Engage communications where regulated employees discuss securities, investments, or market activity in connection with regulated business.
- FCA Rules (SYSC 10A and MAR) — FCA-regulated firms are required to retain relevant electronic communications and to implement effective surveillance arrangements to detect and prevent market abuse. Viva Engage communications by regulated employees in connection with regulated business are within scope.
- GDPR and applicable data privacy regulations — Shield’s architecture supports data residency requirements and privacy-compliant data handling across jurisdictions, enabling firms to meet GDPR and equivalent obligations for Viva Engage data alongside their financial services recordkeeping requirements.
Other Related Connectors
Shield’s connector portfolio spans the full range of eComms channels and trading platforms used across regulated financial institutions. All connectors feed into a single unified compliance platform, so Viva Engage data is always reviewed in the context of every other channel your organisation uses.
- Microsoft Teams
- Microsoft Teams Chat
- Microsoft Exchange
- Slack
- Bloomberg IB and Bloomberg Mail
- Symphony
- Voice and Turret
- Mobile (SMS/MMS)
- Gmail
- Zoom
Frequently Asked Questions
Does the Shield Viva Engage connector cover direct messages as well as community posts?
Yes. Shield captures both Viva Engage community posts and threaded replies and Viva Engage direct messages from in-scope accounts — alongside file shares and associated metadata. Both communication types are potentially in scope where they relate to regulated business activity, and solutions that capture only community posts while omitting direct messages produce incomplete Viva Engage compliance records.
Which regulations does the Shield Viva Engage connector help firms comply with?
The Shield Viva Engage connector supports compliance with SEC Rules 17a-3 and 17a-4, FINRA Rules 4511 and 3110, MiFID II, Market Abuse Regulation (MAR), FCA SYSC 10A, and applicable data privacy regulations including GDPR — to the extent that Viva Engage communications relate to regulated business activity or fall within the firm’s defined compliance scope.
Can Viva Engage data be reviewed alongside Microsoft Teams and Bloomberg IB during an investigation?
Yes. Shield ingests Viva Engage data into the same unified compliance archive as Microsoft Teams, email, Bloomberg IB, and every other channel. Internal investigations or regulatory examinations that require access to internal communications surrounding a specific event can draw on Viva Engage records alongside Teams messages and Bloomberg conversations in a single unified workflow — without switching between separate archive systems.