Identity propagation path
01

Authenticate user and organization

02

Resolve roles and data scope

03

Expose only authorized schema

04

Enforce policy at execution

05

Preserve boundaries in output and logs

Enforce permissions at the data layer

A prompt that says “do not show other regions” is not a security boundary. Authenticate the user, calculate authorization scope, restrict the schema shown to the model, validate the generated query, and enforce policy again in the database or query proxy.

Separate role, row, and column controls

Roles govern administration and publication; row controls limit regions, stores, or customers; column controls protect cost, salary, or personal data. Test the same question as headquarters, regional, and store users, including exports and cached results.

Check before and after generation

Before generation, expose only authorized tables, fields, metrics, and documents. After generation, validate tables, columns, functions, and filters. AskTable.ai confirms organization, role, project, and data-scope controls; enterprise IAM and audit integrations require project confirmation.

Test revocation and secondary surfaces

Caches, logs, downloads, history, shared links, and scheduled reports can leak data after a valid query. Test prompt injection, cross-session access, export, role change, and account deactivation, and record the identity, policy version, plan, and returned scope.

Public references

Ready to help your team start?

Talk through a real scenario and see how AskTable.ai can fit your business.

Book a demo