Field report 1 · AI governance

Who may know what: need-to-know enforced in code, not by discipline

How an AI function sees only the data that role and tenant allow, even when a developer forgets a check.

Status
In trial Design in trial, not yet in production.
Published
Publisher
SIMO GmbH, Aschaffenburg, Germany

Starting questionHow do we make sure an AI function only sees the data its role and tenant allow, even if a developer forgets a check?

What we trialled

Until now, authorisation hung on one middleware line per route. If that line is missing, the endpoint is open.

We designed a model in which every call to an AI component has to carry a signed permission object. Without it, the code does not even compile. Only a central policy authority may issue these objects. The design is in trial and not yet in production.

What it means for business architecture

Need-to-know becomes a property of the architecture rather than something code review has to catch. For regulated organisations that is exactly what matters: you can show that data access without approval cannot happen technically. Showing that it rarely happens is not enough.

Learnings

  1. A forgotten line is the typical data leak. Structural guarantees beat checklists.
  2. When components call each other, the risk multiplies. The check belongs at every hand-over.
  3. Permissions need an expiry and a narrow scope, otherwise they turn into a master key.
  • need-to-know
  • authorisation
  • AI governance
  • tenant isolation

Matching consulting service

From the Lab into consulting.

What we trial in the Lab, SIMO GmbH puts into practice as consultants: Business Data Strategy & Architecture for AI, following the Zero Friction Data Flow principle. These services relate to this report:

45 minutes, free of charge, with the SIMO GmbH consultants. The form is on simo-online.com.

More reports on the same topic