Somewhere, the answer to that question should exist in writing. Today it is scattered across ticked boxes in every tool, and nobody can read it in full. The only answer that holds is a rule per person, attached to their responsibility, with a known author, an approval and a history: a rule you can open and show.
The question nobody around the table can take
Three weeks after three assistants were rolled out to three teams, someone on the executive committee asks the simplest question in the world: “what does the intern’s assistant actually read?”. The silence that follows is not bad faith. Answering would mean opening the settings pages of five tools, working out what every box implies, then cross-checking the lot against the inherited shares on the drive. Nobody can do that from memory, and nobody will be able to redo it in six months to check that nothing has moved.
Yet there is nothing exotic about the question. It is the one a major customer will ask at the next tender, and the one an auditor will ask the day AI enters the scope of a review. An organisation that connects AIs without being able to answer it has a governance problem, before it has a tooling problem.
Where your access decisions live today
Take the inventory honestly. Document rights live in the drive’s sharing settings, folder by folder, with inheritances nobody re-reads. Sensitive conversations live in the private channels of the team messaging tool, where the member list stands in for a policy. Customer data lives behind CRM roles, configured once at installation. Mailboxes, meanwhile, get delegated between assistants and managers without anyone keeping a register.
Each of these settings is reasonable taken on its own. It is their combination that is unmanageable: four different access logics, four admin screens, and no single place to read the whole. That combination has no memory either. When a box changes, the previous state is gone; nobody knows what the intern’s assistant could read last month, or who had decided it should.
What a written access rule looks like
The alternative is not a sixth settings screen. It is a written rule, attached to each person’s responsibility: the marketing intern has access to the campaign materials and the editorial calendar, and has access neither to salaries nor to customer accounts, because their responsibility covers none of that. The rule has an author: the person who decides in that domain, usually the manager concerned. A change does not take effect because someone typed it: it is proposed, then approved by a human who sees the exact effect. And every decision is recorded, decision by decision: what the rule said three months ago is still readable today.
That is the whole difference between adjusting sharing settings and governing your context: the box says what is allowed right now, the rule says who allowed it, since when, and why. How that history is sealed and verified is described in our security posture.
So what does the intern’s assistant read?
Once the rule is written, the answer to the executive committee fits in one sentence: the intern’s assistant reads what the intern is allowed to read, nothing more, and here is the rule that says so. You decide what each AI is allowed to see, and that decision can be shown. The mechanism that applies the rule to every read, slice by slice, is detailed in can you connect an AI without exposing sensitive folders. And the day you have to demonstrate it to an outsider, the history of decisions is produced like an exhibit: that is the subject of proving to an auditor what an AI could read.
A claim like this is meant to be tested
Do not take this page on trust: put it to the test. The Kastel core is free and installs on your own server; describe two responsibilities, change an access rule, and watch what gets recorded: the author, the approval, the history. Your AI keys remain your own, and a full export of your context stays available at any time, without asking us for anything. If what you observe does not match what you have just read, then this page is the one that is wrong.