Permission correctness

Control Which Data AI Agents May Use

Permitted evidence is the resolved intersection of human authority, agent authority, workload identity, delegated scope, source ACL, task purpose, classification, and disclosure policy.

Reference policy model
01

ACL fidelity

Preserve source-system denies, group expansion, revocation state, and field-level restrictions.

02

Purpose binding

Prevent an agent from reusing accessible information for an unauthorized task.

03

Explainable denial

Record why an item was admitted, redacted, or excluded without leaking protected content.

Current limitationPermission fidelity is connector-specific and must be tested; no connector should claim parity without evidence.
Inspect a Bundle