GOVERNANCE & RBAC

Security enforced before any answer returns.

Roles, groups, per-asset grants, tag permissions, and deny scopes apply to humans, Ask Lex, and every agent on the API. One permission model, no side doors.

PERMISSIONS FIRST

Permission-aware AI starts with the permission model.

A useful answer must respect the same access boundaries as the underlying records. That check happens before the answer returns.

Apply access to people and agents

Use the same model whether the request comes through the UI, Ask Lex, or an API connection.

Keep the source record authoritative

The answer inherits the boundary from the knowledge it uses.

Avoid side doors

Do not create a separate permission system just to make AI feel convenient.

THE MODEL

When rules conflict, deny wins.

Build access from explicit roles, groups, grants, and the boundaries required by your clients and team.

Roles and groups

Give people the access their work requires without exposing every client record.

Per-asset and tag controls

Scope sensitive operational knowledge where it belongs.

Deny scopes

Make the restrictive rule win when access rules conflict.

IDENTITY & AUDIT

Your identity provider stays in charge.

Single sign-on

Microsoft Entra ID and Google Workspace. Accounts provision automatically from your identity provider.

MFA and IP allowlists

MFA rides your identity policies; lock access to approved networks when you need to.

Immutable audit trail

Every login, view, reveal, and edit. Retained at least one year, exportable to your SIEM.

Client Viewer, free

Client end users get read-only access, and RBAC decides exactly what they see.

One permission model. Zero side doors.

Bring your co-managed edge cases; we'll map them live.