Field report 1 · AI governance
Who may know what: need-to-know enforced in code, not by discipline
How an AI function sees only the data that role and tenant allow, even when a developer forgets a check.
- Status
- In trial Design in trial, not yet in production.
- Published
- Publisher
- SIMO GmbH, Aschaffenburg, Germany
Starting questionHow do we make sure an AI function only sees the data its role and tenant allow, even if a developer forgets a check?
What we trialled
Until now, authorisation hung on one middleware line per route. If that line is missing, the endpoint is open.
We designed a model in which every call to an AI component has to carry a signed permission object. Without it, the code does not even compile. Only a central policy authority may issue these objects. The design is in trial and not yet in production.
What it means for business architecture
Need-to-know becomes a property of the architecture rather than something code review has to catch. For regulated organisations that is exactly what matters: you can show that data access without approval cannot happen technically. Showing that it rarely happens is not enough.
Learnings
- A forgotten line is the typical data leak. Structural guarantees beat checklists.
- When components call each other, the risk multiplies. The check belongs at every hand-over.
- Permissions need an expiry and a narrow scope, otherwise they turn into a master key.
- need-to-know
- authorisation
- AI governance
- tenant isolation