AI security
AI security and access design should make identity, permitted purpose, context, permissions, tool actions, human oversight, audit evidence, and exceptions explicit.
Record the user, service identity, business purpose, owner, approved scope, and action boundary.
The AI governance and risk controls route provides an internal path for connecting security decisions with governance.
Pass only necessary context and grant only permissions required for the defined task. Define sensitive fields, masking, retention, external actions, and prohibited access.
Distinguish drafting, retrieval, recommendation, and a change to external state. Require a defined reviewer where consequence or uncertainty makes direct execution unsuitable.
Retain approvals, role changes, denied actions, exceptions, challenged outputs, and control decisions.
Review access when the model, prompt, tool, data source, user group, integration, purpose, or consequence changes.
Authentication identifies a caller; authorization, purpose, context, and oversight determine what the workflow may do.
Bring the identity, permission, or exception question that needs a clearer security boundary.
Discuss AI access design