GOVERNANCE & RBAC
Security enforced before any answer returns.
Roles, groups, per-asset grants, tag permissions, and deny scopes apply to humans, Ask Lex, and every agent on the API. One permission model, no side doors.
PERMISSIONS FIRST
Permission-aware AI starts with the permission model.
A useful answer must respect the same access boundaries as the underlying records. That check happens before the answer returns.
Apply access to people and agents
Use the same model whether the request comes through the UI, Ask Lex, or an API connection.
Keep the source record authoritative
The answer inherits the boundary from the knowledge it uses.
Avoid side doors
Do not create a separate permission system just to make AI feel convenient.
THE MODEL
When rules conflict, deny wins.
Build access from explicit roles, groups, grants, and the boundaries required by your clients and team.
Roles and groups
Give people the access their work requires without exposing every client record.
Per-asset and tag controls
Scope sensitive operational knowledge where it belongs.
Deny scopes
Make the restrictive rule win when access rules conflict.
IDENTITY & AUDIT
Your identity provider stays in charge.
Single sign-on
Microsoft Entra ID and Google Workspace. Accounts provision automatically from your identity provider.
MFA and IP allowlists
MFA rides your identity policies; lock access to approved networks when you need to.
Immutable audit trail
Every login, view, reveal, and edit. Retained at least one year, exportable to your SIEM.
Client Viewer, free
Client end users get read-only access, and RBAC decides exactly what they see.
One permission model. Zero side doors.
Bring your co-managed edge cases; we'll map them live.