Roles and groups
Existing organisations can be mapped through AD/LDAP or managed in the hub.
PaulinAI checks users, roles and groups before content is searched or passed to a model. Blocked data never enters the answer context.
Redacting information afterwards is too late. PaulinAI places the security boundary before search and AI processing: unauthorised folders, databases, mailboxes and websites are excluded from the request.
Existing organisations can be mapped through AD/LDAP or managed in the hub.
Approvals apply specifically to folders, databases, mailboxes, websites and other sources.
Unauthorised content is neither retrieved nor passed to the AI.
Specialised agents receive only the tools and data required for their task.
Cloud models and web search can be disabled by data class and process.
Permissions and responsible roles can be maintained under control.
Users, groups and roles are imported from existing structures or managed in the hub.
Every source receives an owner, protection class and permitted groups.
Permitted and blocked questions are tested systematically with different roles.
Role changes, new sources and changed processes are reflected in permissions.
Unauthorised sources never enter the answer context, so rephrasing a question cannot retrieve data the user did not technically receive.
Yes. Users and groups can be connected through existing directory services without storing the AD password in PaulinAI.
Yes. Agents, P-Apps and users operate with defined source and tool approvals.
We assess identities, sources, roles and agent permissions for an accountable pilot area.