Glossary
Permission-aware AI
Permission-aware AI refers to AI systems that take the access rights of the asking person into account on every request and draw only on sources that person has been granted access to. For small and medium-sized businesses this is essential: sensitive areas such as HR, finance, or management stay protected even when an AI can search the company's entire knowledge.
Last updated: 2026-08-03
Many AI assistants search everything they are connected to once access has been granted – regardless of who is asking. Permission-aware AI reverses that principle: the permission filter is applied inside the search itself, before a result even exists, rather than being bolted onto a finished answer afterwards. The foundation is source-level approvals – for the whole company, individual areas, roles, or specific people only. If the necessary context is missing, such a system returns nothing rather than something it shouldn't.
In everyday work, this means the same question can produce different answers for different people. When someone in sales asks about project documents, the AI draws only on files shared with their area – salary lists from HR or management documents appear neither in the answer nor in the cited sources. This becomes especially relevant when existing repositories with access structures grown over years are connected to an AI. A documented role and permission model is also a concrete technical and organizational measure in the sense of data protection law.
Chifty implements this principle in Chifty Knowledge, the knowledge base behind its chat and mailbox features. Knowledge can be shared with the whole company, individual areas, roles, or specific people only; the permission filter is applied directly in the search, at query time – the AI itself cannot influence it. The principle behind it: the AI must not bypass permissions. Answers rely only on approved sources and show citations, so it stays traceable what each statement is based on.
Connected sources such as Google Drive, OneDrive, SharePoint, or HubSpot, along with users and access rights, are managed by administrators in one central place. That keeps the permission logic manageable even as the connected knowledge grows.