Authenticate user and organization
Resolve roles and data scope
Expose only authorized schema
Enforce policy at execution
Preserve boundaries in output and logs
Enforce permissions at the data layer
A prompt that says “do not show other regions” is not a security boundary. Authenticate the user, calculate authorization scope, restrict the schema shown to the model, validate the generated query, and enforce policy again in the database or query proxy.
Separate role, row, and column controls
Roles govern administration and publication; row controls limit regions, stores, or customers; column controls protect cost, salary, or personal data. Test the same question as headquarters, regional, and store users, including exports and cached results.
Check before and after generation
Before generation, expose only authorized tables, fields, metrics, and documents. After generation, validate tables, columns, functions, and filters. AskTable.ai confirms organization, role, project, and data-scope controls; enterprise IAM and audit integrations require project confirmation.
Test revocation and secondary surfaces
Caches, logs, downloads, history, shared links, and scheduled reports can leak data after a valid query. Test prompt injection, cross-session access, export, role change, and account deactivation, and record the identity, policy version, plan, and returned scope.
Public references
Ready to help your team start?
Talk through a real scenario and see how AskTable.ai can fit your business.
Book a demo