Access control

You decide who uses which agent, on what data.

We configure access against your real permission model during customization: by department, by role, by person. Enforced on your infrastructure, and every decision logged.

Granularity
Department, role, person
Permissions
Ask, act, manage
Directory
Entra ID, Keycloak, yours
Audit
Every decision logged

In short

AI access control decides which people can use which AI agents and what each agent may read or change. DeepVox enforces it per department, role and person, keeps customer-facing agents separate from internal ones, treats reading and changing records as separate permissions, and syncs roles from your existing directory.

Example configuration

One grid, every agent.

Roles and agents are set up to match your organisation.

WhoPolicy assistant (internal)Contract review (internal)Invoice automation (internal)Patient voice line (external)
FinanceAsk—Ask + act—
HRAsk———
LegalAskAsk + act——
Patient services leadAsk——Manage
Patients calling in———Ask · own records only

Principles

Four rules we build in.

By department, then by person

Assign agents to teams, then grant or restrict individuals within them.

Internal and external kept apart

Customer- and patient-facing agents run with a narrower scope and never reach internal knowledge they don’t need.

Asking is not acting

Reading an answer and changing a record are separate permissions, with approval gates where you want them.

Directory sync

Departments and roles come from Entra ID, Keycloak or your existing directory. Nothing to set up twice.

Evidence for auditors

What you can show.

  • Who asked what, when, and which sources were used.
  • Which actions an agent took and who approved them.
  • Which roles had access to which agents at any point in time.
  • Usage and model cost per department.

FAQ

Questions, answered.

Do connectors keep source permissions?

Yes. Each connector carries the source system’s permissions, so answers only draw on content the person could already open.

Can an agent read but not write?

Yes. “Ask” and “act” are separate permissions, and acting can require approval.

Where are access logs stored?

In your environment, alongside the rest of the audit trail.

Related

Start with two weeks of evidence, not a sales call.

A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.

Book a discovery sprint