← Other Athentra features
Athentra AI · Governance
Permission-Scoped AI Access
AI agents call each service's public API asserting the identity of the person they are acting for, so results are scoped to that individual's own permissions. There is no system-administrator back door and no internal read surface that bypasses access control. The assistant cannot become a route around the permission model.
- 01
Pain Point
What's the problem?
An assistant that queries with elevated rights becomes a way to read data the asker was never entitled to see.
- 02
Remedy
How do we attack it?
Have agents call each service as the person asking, with that person's own permissions
- 03
Your Value
What do you get out of it?
An answer can never reveal more than the person asking could have found themselves
