Glossary

Permission-aware AI

Permission-aware AI refers to AI systems that take the access rights of the asking person into account on every request and draw only on sources that person has been granted access to. For small and medium-sized businesses this is essential: sensitive areas such as HR, finance, or management stay protected even when an AI can search the company's entire knowledge.

Last updated: 2026-08-03

Many AI assistants search everything they are connected to once access has been granted – regardless of who is asking. Permission-aware AI reverses that principle: the permission filter is applied inside the search itself, before a result even exists, rather than being bolted onto a finished answer afterwards. The foundation is source-level approvals – for the whole company, individual areas, roles, or specific people only. If the necessary context is missing, such a system returns nothing rather than something it shouldn't.

In everyday work, this means the same question can produce different answers for different people. When someone in sales asks about project documents, the AI draws only on files shared with their area – salary lists from HR or management documents appear neither in the answer nor in the cited sources. This becomes especially relevant when existing repositories with access structures grown over years are connected to an AI. A documented role and permission model is also a concrete technical and organizational measure in the sense of data protection law.

Chifty implements this principle in Chifty Knowledge, the knowledge base behind its chat and mailbox features. Knowledge can be shared with the whole company, individual areas, roles, or specific people only; the permission filter is applied directly in the search, at query time – the AI itself cannot influence it. The principle behind it: the AI must not bypass permissions. Answers rely only on approved sources and show citations, so it stays traceable what each statement is based on.

Connected sources such as Google Drive, OneDrive, SharePoint, or HubSpot, along with users and access rights, are managed by administrators in one central place. That keeps the permission logic manageable even as the connected knowledge grows.

Frequently asked questions

What is permission-aware AI?
An AI system that checks on every request which sources the asking person is allowed to access, and uses only those for its answer. The permission filter is applied inside the search itself – not retroactively on a finished answer.
Why does permission-aware AI matter for businesses?
Once an AI can search a company's entire knowledge, the permission logic decides whether confidential content – from HR, finance, or management, for example – stays protected. Without it, any employee could surface information through a chat question that was deliberately restricted in the file system.
How does Chifty ensure the AI cannot bypass permissions?
The permission filter is applied directly in the search, before a result exists – the AI itself cannot influence it. If the organization or role context is missing, the system returns nothing rather than too much. Answers also show citations, so the basis of every statement stays visible.