Back to Content
Putting an AI inside a company system without giving it the keys
The rule we build every assistant around: it may do exactly what the person asking could do, through the same doors, and nothing else.
The tempting design is to give a model a database connection and a good prompt. The safe design is to give it the same buttons a person has. Every action it takes is a typed action with a permission check, a risk class and an audit entry — the same ones the interface calls — so the assistant can never do something the person could not, and everything it does is written down.
Why it matters more for small companies
A large company has a security team to notice a leak. A small one finds out from a customer. Building the boundary into the architecture, rather than into a policy document, is what makes it hold when nobody is watching.