Permissions travel with every answer
Bring in content from Confluence, Notion, Google Drive, and direct uploads through permission-aware connectors. Explicit include and exclude scoping, set per site or per drive, controls exactly which locations feed the library.
Vector search and retrieval-augmented generation (RAG) bring the right approved knowledge into chat and agent runs at scale. People and agents work from the organization's own sources, in the same governed workspace where the rest of their AI work happens.
The source system's sharing permissions are carried into the index and preserved at answer time, so a person or agent is answered only from knowledge the source would let them see. Context flows to the model without data leaking past it.
Common questions
Do source permissions carry into answers?
Yes. Content is synced through permission-aware connectors rather than pulled in bulk, so the source system's access controls travel with the content into the index. At answer time those permissions are preserved: an answer can draw only on knowledge the asker could already open in the source system.
Which sources connect?
Confluence, Notion, Google Drive, and direct uploads are the examples shown here, and the connector model extends to additional enterprise knowledge sources through the same permission-aware sync pattern. Each source is onboarded under explicit scoping, so the library holds only the locations you chose.
Is knowledge content retained as evidence?
No. The evidence trail seals each decision as a metadata-only receipt; it records decisions, not content. Your knowledge itself lives inside the trust boundary in a tenant-isolated data plane, under your tenant's controls.
AI Security Runtime™ secures every query
Company Knowledge answers through AI Security Runtime™. Whether a person asks in chat or an agent retrieves context mid-run, the query and the content it returns are checked before data moves toward a model.
| OBSERVE | Every knowledge query on the record: who asked, what was retrieved, where it went |
| DETECT | The Semantic Security Engine™ reads the query and the retrieved content for meaning and intent, in real time |
| ENFORCE | Source permissions applied at answer time; allow, redact, hold for human review, or block before data reaches a model |
| TRACE | Audit-ready evidence for every decision; the trail records decisions, not content |