Permissions before the prompt
Access by role, company, record and field. Authorisation is checked by the application before retrieving data or invoking tools.
Data governance · AI with context
Unify your sources and the meaning of your metrics. Decide who can access what and which information reaches each LLM. A shared foundation for your business, your teams and your AI.
For CTOs, CIOs and CEOs bringing AI to their business data.
01A shared business language
02Access according to the task
03Traceability from source to answer
The foundation of your decisions
NextScenario connects banks, ERPs and sales channels to understand cash, profitability and growth. The semantic layer brings that shared view to your analysis and assistants: what each data point means, where it comes from and how it can be used.
Sales − returns − discounts
Source, period, currency and calculation rules defined before querying the model.
01 / Architecture
Banks, ERP, CRM, ecommerce and internal databases. We start with your stack and validate the connections each use case needs.
Shared entities, relationships and metrics. Agree how to calculate margin, revenue or churn and resolve differences between sources.
Define permissions by role, company and field. Filter records and transform sensitive data before building query context.
Select metrics, aggregate results and limit detail. The model receives authorised context for the task and its response is validated before use.
02 / What reaches the model
Explore two examples of how context changes with the task. Values are fictional and illustrate a possible policy, not a connection to your systems.
Illustrative example · fictional data
03 / Governance by design
We design controls with you and validate how they apply to each source, user and use case.
Access by role, company, record and field. Authorisation is checked by the application before retrieving data or invoking tools.
Field allowlists, filters and aggregation. A task that can be answered with totals does not need complete records or entire documents.
Remove or mask identifiers. When relationships must be preserved, consider tokens or HMAC with keys managed outside the model.
Link metrics to sources and calculation rules. Define access and transformation logs, including retention and permissions for the logs themselves.
Agree which models may receive each data category and review the provider’s residency, retention and usage terms.
Separate queries from execution. Define allowed tools and human approval for sensitive operations; validate outputs before acting.
04 / Technology and leadership
Centralise definitions and policies to avoid a different integration for every assistant.
Define owners, access and destinations to introduce AI with a shared policy.
Connect AI initiatives to the metrics that drive cash, margin and growth.
Technical questions
A semantic layer defines what data means: shared entities, relationships and calculation rules. Integrated with access controls, it lets teams and AI assistants query consistent metrics using only the information authorised for each task.
The semantic layer defines entities, metrics, relationships and rules over your sources. It can build on your existing data infrastructure. Whether information needs to be copied or stored depends on the architecture and use case.
The design starts with minimum access: first authorise the query, then select and transform the data it needs. A permission in a prompt does not replace the controls that must be enforced in infrastructure and the application.
Not necessarily. A deterministic hash can enable comparisons or dictionary attacks. Depending on the use case, consider removal, aggregation, tokenisation or HMAC with key management. Keeping pseudonymous identifiers does not by itself eliminate reidentification risk.
That depends on the provider, service and contract. Before enabling a destination, its training and retention terms must be verified and configured. The same policy should not be assumed for every LLM.
Choose a business question, identify its sources and define the metric, permissions and allowed context. Validate the flow with your team before expanding to new data or automations. Specific connections and controls are agreed in the technical scope.
Your next scenario
Let’s review your stack, one business question and the information the model actually needs to answer it.
Let’s talk about your dataSources · Metrics · Permissions · Context