View Full Video Script
2:53 min
View Full Video Script
-
There, what we do is the agent does not get all the data access to all the
-
Board repository. First of all, we don't give the agent access to raw data.
-
Secondly, we don't even give access to Board cubes and procedures and screens.
-
We give the agent access to datasets, which is a very defined concept.
-
You need to configure it and decide exactly which data points and which dimension
-
the agent has access to. For the technical people in the audience, it's the concept
-
of quick layout that is very familiar to everyone that has worked with Board.
-
On top of that, though, anytime the agent executes an operation and talks with the
-
LLM, sends data over to the LLM, it's always using the entitlement of the user in
-
front of the agent. So if I'm chatting with the agent, the LLM will effectively
-
receive the prompt I typed and the data that the agent will need to
-
answer my prompt or answer my question, but filtered on my entitlement.
-
So it will not be able to access data beyond the boundary that I make available,
-
that I'm able to access. So for example, if you have a cube with salary data, but
-
I'm not a top-level manager and I cannot see the salary of other divisions, if you
-
ask the agent, "Give me the total of salary for that division," it will say,
-
"Sorry, I don't have access to that slice of the data because you are entitled only
-
to see your department. You can't know the total of the salary for that other
-
person, that other executive department, because it's not on the entitlement." And
-
so the dataset API will answer, "Sorry, you don't have access to that data." So
-
this is really important to us. We build the architecture of the agents in a way
-
that does not allow to breach the confidentiality boundaries that are
-
configured in the platform. And this is another important differentiation compared
-
to building agents directly on top of raw data.
-
If you build an agent on top of Databricks or even on the data warehouse layer
-
without any product on top, in many, many cases, those entitlements are not
-
something that the system has in place because the purpose of the system is not
-
serving reports and dashboards to thousands of users.
-
This is typically an higher-level system like Board, like an EPM tool.
-
And so in those lower systems, yes, the agent might give you the correct answer,
-
but it might breach security and confidentiality in a huge number of occasions.
-
And that's one of the very important things that for a CIO, for a key
-
decision-maker, that person needs to keep that in mind because security will not
-
sign off on an agent that can access the entire data warehouse and anyone in the
-
company can see the salary of every person in the company and start a whole mess
-
internally. So that's a very key point that our customers appreciate about our
-
architecture.