One Enterprise Dashboard, one boundary through every tool.
You decide who reaches which sources, and the same boundary holds through every tool. Role-based access, governed scopes and SSO in one place, deployed in your cloud tenant or air-gapped on your own hardware.
- Add and remove members
- Create Knowledge Bases
- Set retention
- Export the audit log
Full scope, and the only role that can change anyone else’s.
- Ask across scoped sources
- Run packaged apps
- Upload to a Knowledge Base
Does the work. Cannot see commercial material or change who has access.
- Read an answer and its citations
- Open the audit trail for one matter
Sees the basis for a finding and nothing else. This is the role that makes an outside review safe to grant.
The tool was never the hard part.
Three things decide whether a knowledge platform reaches the people who need it, and none of them are about the answers.
The security review is where the evaluation goes to wait.
A questionnaire arrives, and the honest answers to half of it are on a page nobody has written. The engineers who wanted the tool now wait on a document instead of using it.
Everyone can see everything, or nobody can see anything.
Access ends up all-or-nothing because per-team scoping was too much work to maintain. Commercial terms sit in the same pool as the field manual, and the fix is to lock the pool.
You can show the policy. You cannot show it held.
An auditor does not want the permissions matrix. They want an instance: this person asked for that, and here is what the system did about it.
Four things you control, and can prove you controlled.
Each one is set once, against the source, and enforced across Chat, Citations and Agentic Apps. No tool is looser because it was set up later.
Which sources each role reaches
Set per Knowledge Base, down to a single document, and enforced everywhere.
Who gets in, and how
Single sign-on, users and organizations administered in one place.
What was asked, and what happened
Every question logged with who asked it, what was in scope, and the answer.
Where it runs
Your cloud tenant, or air-gapped on your own hardware.
Governance you can show an auditor.
Every question logged with who asked it, what was in scope, and what happened, including the ones that were refused.
A refusal is the part you can actually evidence.
Everyone will show you a permissions matrix. It is a promise about what would happen.
The interesting rows are the refusals
A request turned down because a role did not reach it, with a name and a time against it, is a control. A policy nobody ever tested is a document about a control.
The boundary belongs to the source
Access is decided against the Knowledge Base, so the same person meets the same boundary through Chat, an app or a tutor. No tool is looser because it was set up later.
Changing deployment does not restart the review
Cloud tenant or air-gapped on your own hardware, the governance model is the same. What your security team approved is not invalidated by where it ends up running.
Certifications, subprocessors and the Trust Center are on Security, the page to forward to a security team. Scope is set per Knowledge Base and enforced in every tool a person reaches it through.
One platform. Every governed tool.
The same roles and the same approved sources govern every tool on the platform.
Scope a governed deployment for your team.
Thirty minutes, your own documents, every answer cited to its source.