Permissions also apply to search and tools
The assistant should only find content that the requesting user is allowed to read. This check is enforced technically, outside the free-text model response, and takes changed group permissions into account. Documents that are found are treated as data, not as instructions. If the assistant is to create tickets or change records, we limit the permitted tools, target systems and parameters. Steps with significant consequences require human approval. Logging is designed according to protection needs; confidential questions and answers do not always have to be stored in full.


