Permissions & governance
The right context. For the right person. Before AI begins.
Every request carries identity, source access, policy, and purpose. What the person may not see is decided first — and is absent from the context, never shown behind a lock.
Enterprise-wide understanding does not require enterprise-wide access.
Authorized context for this request
- Full matter history and strategy record
- Client communications and commitments
- Settlement decision log with sources
- Billing and engagement terms
- Prior firm experience with counterparty
- Privileged work product
Why this view? Matter partners hold source permissions across the full engagement, so the assembled context includes strategy, billing, and privileged material.
Illustrative example
Decided per request
One question. Five checks. One record.
The decision Percidian makes before any context is delivered — what each check confirms, what it keeps out, and the line it writes.
Priya Raman · Associate“What are our obligations under the Northwind agreement?”
Stage 01 of 06
Identity resolved
Who is asking is settled first, against your identity provider — not inferred from the prompt.
Confirms
- Priya Raman · signed in through Okta
- Associate on the Northwind matter team
- Purpose: work on the Northwind matter
Kept out
An identity that cannot be resolved receives no sensitive context. The request stops here.
- who
- Priya Raman · Associate
- sources
- —
- context
- —
- evidence
- —
- destination
- —
- logged
- —
Illustrative example
Source-aware access
The decision reads access from the source, at request time.
Permissions do not disappear when information enters AI.
Files and records
Access follows the governing source, not a separate, stale copy of its rules.
Groups and roles
Identity, group membership, and delegated authority stay part of the decision.
Shared resources
Shared drives, sites, mailboxes, and team spaces keep their own boundaries.
Changes and deletions
Revoked access and deleted material stop being available to future requests.
One standard across every AI surface
Govern the knowledge once — not separately inside every application.
A third-party assistant, internal agent, embedded feature, and automated workflow should not implement separate interpretations of enterprise access. Percidian gives each approved surface one consistent way to request governed business context.
Consistency
The same identity and policy logic applies across approved AI surfaces.
Control
Security teams govern which context classes can reach which destinations.
Portability
Changing models does not require rebuilding the permission layer.
Visibility
Requests remain traceable to the identity, purpose, policy, and evidence involved.
The audit trail
Who asked, what governed it, where it went.
Every request leaves a record that security and compliance can review — without reopening the sources.
Every answer can show its record.
Each record keeps its source citations and lineage, the access decision that applied, the destination that received the context, and the current and superseded source state, for as long as your retention policy requires.
Encryption, isolation, retention, and model routing are set by the deployment. Request security materials
“What are our obligations under the Northwind agreement?”
- who
- Priya Raman · Associate
- sources
- 3 permitted
- context
- scoped to the task
- evidence
- every fact linked to source
- destination
- Microsoft Copilot · approved
- logged
- 09:42:07 · reviewable
Reviewable by security and compliance from one control point.
Illustrative example
Bring your business into every AI decision
Give every approved AI system the context to do its best work.
Connect the knowledge your organization already has. Preserve what it learns. Apply the permissions it already trusts. Make that understanding available wherever people and agents work.