This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.

How Do You Protect Data While Enabling AI?

AI agents need access to data, but not all data. In this video, discover how Board protects sensitive information by giving agents access only to carefully defined datasets, while enforcing each user’s existing permissions and entitlements. Learn why this controlled architecture helps organisations unlock AI without compromising confidentiality, security, or trust.

View Full Video Script

2:53 min
  1. There, what we do is the agent does not get all the data access to all the

  2. Board repository. First of all, we don't give the agent access to raw data.

  3. Secondly, we don't even give access to Board cubes and procedures and screens.

  4. We give the agent access to datasets, which is a very defined concept.

  5. You need to configure it and decide exactly which data points and which dimension

  6. the agent has access to. For the technical people in the audience, it's the concept

  7. of quick layout that is very familiar to everyone that has worked with Board.

  8. On top of that, though, anytime the agent executes an operation and talks with the

  9. LLM, sends data over to the LLM, it's always using the entitlement of the user in

  10. front of the agent. So if I'm chatting with the agent, the LLM will effectively

  11. receive the prompt I typed and the data that the agent will need to

  12. answer my prompt or answer my question, but filtered on my entitlement.

  13. So it will not be able to access data beyond the boundary that I make available,

  14. that I'm able to access. So for example, if you have a cube with salary data, but

  15. I'm not a top-level manager and I cannot see the salary of other divisions, if you

  16. ask the agent, "Give me the total of salary for that division," it will say,

  17. "Sorry, I don't have access to that slice of the data because you are entitled only

  18. to see your department. You can't know the total of the salary for that other

  19. person, that other executive department, because it's not on the entitlement." And

  20. so the dataset API will answer, "Sorry, you don't have access to that data." So

  21. this is really important to us. We build the architecture of the agents in a way

  22. that does not allow to breach the confidentiality boundaries that are

  23. configured in the platform. And this is another important differentiation compared

  24. to building agents directly on top of raw data.

  25. If you build an agent on top of Databricks or even on the data warehouse layer

  26. without any product on top, in many, many cases, those entitlements are not

  27. something that the system has in place because the purpose of the system is not

  28. serving reports and dashboards to thousands of users.

  29. This is typically an higher-level system like Board, like an EPM tool.

  30. And so in those lower systems, yes, the agent might give you the correct answer,

  31. but it might breach security and confidentiality in a huge number of occasions.

  32. And that's one of the very important things that for a CIO, for a key

  33. decision-maker, that person needs to keep that in mind because security will not

  34. sign off on an agent that can access the entire data warehouse and anyone in the

  35. company can see the salary of every person in the company and start a whole mess

  36. internally. So that's a very key point that our customers appreciate about our

  37. architecture.

You may also be interested in