Security

Know what data can be accessed, where it goes, and who is responsible.

Each engagement documents the source systems, users, identity path, permitted tools, AI assistant provider, returned results, logging, monitoring, retention choices, incident responsibilities, and exit plan for the actual environment.

Data Flow

The AI assistant provider is part of the processing path.

Questions, tool requests, and approved results may be processed by the selected provider under the customer’s plan, settings, terms, retention choices, and regional availability. The exact path depends on the chosen products and configuration.

The provider, identity, access, network, hosting, logging, retention, and exit arrangements are reviewed for the selected option before launch.

Access Controls

Start read-only and permit only the users, data, and operations the use case needs.

Read-only protects source records from change. It works alongside identity checks, purpose-built tools, result limits, and settings for the selected AI assistant.

Users and identity

Named users or roles and the authentication path available in the source and assistant environment.

Sources and fields

Approved interfaces, datasets, measures, dimensions, exclusions, and dates.

Permitted operations

Purpose-built read operations are preferred to unrestricted model-generated SQL or broad database authority.

Returned results

Results are shaped for the approved analysis and limited to what the user needs.

Visible failures

Denied access, unavailable sources, incomplete data, and unsupported questions should fail clearly.

Roles and Responsibilities

Systems Place operates the agreed service. The customer and providers keep their own authority.

The split is documented for the selected source, AI assistant, hosting, network, and identity design.

Systems Place

Managed service

  • Implement the approved tools and service controls
  • Maintain the answer tests and operating checks
  • Monitor the agreed service and investigate its incidents
  • Assess and test changes to the managed components

Customer and providers

Business authority and product controls

  • Approve users, sources, definitions, and business purposes
  • Configure source and AI provider accounts and policies
  • Own decisions made using the returned analysis
  • Operate infrastructure and terms outside the managed service

Retention and Exit

Decide what is kept, for how long, and what happens when the service ends.

Managed service records

The service scope defines why logs, cached data, test results, and support records are kept and for how long.

Provider retention

AI assistant and infrastructure provider settings and terms are reviewed for the selected plan and region.

Handover

Agreed documentation, dependencies, definitions, and operational records can be handed over at exit.

Removal

Access is revoked, managed components are removed, and agreed records are retained or deleted under the exit plan.

Common questions

Common security and data questions.

Does data stay inside our source system?

Not necessarily. The selected AI assistant provider may process the conversation, tool requests, and approved results. The exact data flow is documented for the chosen option.

Does read-only remove all risk?

No. Read-only prevents source-system writes, but sensitive results can still be returned, retained, copied, or shared. Identity, permissions, result limits, provider settings, and user behaviour still matter.

Do source-system permissions automatically apply?

It depends on the interface and identity design. Some options use end-user identity; others use a service identity and need tool-level enforcement. The design is verified for the actual source and assistant.

What is logged?

The agreed design may record service calls, tool selection, outcomes, authentication events, failures, and evaluation runs. Sensitive content and retention are deliberately scoped.

Review a real data path

Start with the question and the systems it would need to use.

The assessment records the source, provider, identity, tools, answer checks, retention, responsibilities, and exit requirements for the proposed option.