Insight
Permissions belong below the AI
If the model decides who sees what, you have built the wrong thing.
It is tempting to let a capable model handle access: tell it the rules and trust it to apply them. It is also wrong. A model can be persuaded, confused, or simply mistaken, and access control that can be argued with is not access control.
FactSmith enforces permissions beneath the AI, at the row and the column, before the model sees anything. The model writes the question. The data it is allowed to touch has already been decided. A regional manager gets their region because the rest never arrives, not because the model chose to be discreet.