neesh Inc.
AI SecurityEnterprise AIAccess Control

Permission-Aware AI

An AI that answers from your company documents has to answer each person only from what that person is allowed to see. The filter belongs where the documents are fetched, before the AI reads anything.

An AI that answers from your company’s documents has to know who is asking. A support agent who asks “what was our revenue last quarter?” should not get the answer the CEO gets.


Why the demo version is a liability

The usual demo is simple: load your documents, ask a question, get an answer. It impresses in a boardroom because everyone in the demo is the same person.

Give that tool every file in the company (HR records, financial reports, client contracts, legal memos) and any employee can ask about any of it. Your drives have permissions for a reason, and an AI that reads everything on everyone’s behalf removes them.


How the filter works

1

A person asks

Signed in, so the system knows who is asking

2

Look up their groups

From the access groups you already manage

3

Search only what they may see

The database filters by group before any passage is fetched

4

Write the answer

From the permitted passages only

5

Cite the sources

Links to documents the person can already open

The filter is part of the database query that finds the relevant passages (for your IT team: the permission check is a join inside the same SQL statement). Documents the person may not see are never fetched, so there is nothing in front of the AI for a clever question to reach.

AskBase, our knowledge engine, works this way and is available now. Every answer also reports how many matches the asker’s permissions removed.


How the AI says no

A careless refusal does more damage than no AI at all.

The wrong refusal
"I don't know." This suggests the information does not exist. The person leaves with a false picture of what the firm knows, and may stop trusting the tool or assume the documentation is missing.
The right refusal
"I can't answer that from the documents you have access to. Someone with the right access can help." This is honest about the boundary, suggests the information exists, and tells the person what to do next.

AskBase keeps the cases apart: an answer, nothing relevant found, an empty knowledge base and a permission refusal each get their own response, and when it finds nothing it says what it searched.


One question, four people


Why it matters to the business

Privacy law and audit standards such as GDPR and SOC 2 expect you to show who can see personal and sensitive data. An AI that answers questions is one more way to see it, and needs the same control, documented and tested. If an employee reads salary data or client pricing through an AI tool without authorization, the liability is yours.

Without permission-aware search, an AI tool over company documents has two settings: locked down to what everyone may see, which is safe and of little use, or open to everything, which is useful and dangerous. Filtering at search time is what lets it be both safe and useful.

Which of your documents should only some of your people see?

Book Free Assessment