NEWPromptev MCP Server: one URL for every tool, every agent and your team’s knowledge. Connect Claude Code, Cursor, or any MCP client.→

Permission-aware answers

Every answer respects who is asking.

Permission-aware AI agents answer each person using only the documents that person is allowed to open, so one agent can serve your finance team, your contractors, your customers and your partners without leaking between them.

NadiaFinance director

What did we pay Northwind in Q2, and is the renewal signed?

TomContractor

What did we pay Northwind in Q2, and is the renewal signed?

Promptev agentsearches as the person asking
  • invoices-q2.xlsxSpreadsheet · DriveNadia: readTom: never fetched
  • Northwind MSA.pdfContract · SharePointNadia: readTom: never fetched
  • #financeSlack channelNadia: readTom: read
  • Project wikiConfluenceNadia: readTom: read

Nadia gets

You paid Northwind $184,200 across four invoices in Q2. The renewal was countersigned on 12 June at a 6% uplift, effective 1 July.

invoices-q2.xlsxNorthwind MSA.pdf#finance

Tom gets

I can’t see payment records for Northwind. #finance announced the renewal as signed on 12 June. For amounts, please ask the finance team.

#financeProject wiki

One agent, one question, two people. The agent searches with each person’s own access, so for Tom the two finance files are never fetched and cannot leak into his answer.

How it works

Three steps, start to finish.

  1. Step 1

    Permissions come with the content

    When Promptev syncs Google Drive, Microsoft 365 or Dropbox, each file keeps its sharing settings. For files you upload, you choose who may see them.

    No second permission system to set up or keep in sync.

    Then every question is searched as the person who asked it.

  2. Step 2

    The search runs as the person

    Every question is searched with the asker’s identity and groups built into the search itself, so a file they cannot open is never fetched.

    A file someone may not open never reaches the AI model.

    What comes back is an answer they can check.

  3. Step 3

    The answer names its sources

    The agent answers from what it found and lists the documents it used. If it could not see something, it says so instead of guessing.

    Every answer can be traced to its source.

Why it matters

Filtering afterwards is not the same.

Many AI tools search everything first and hide what the person should not see just before they show the answer. By then the model has already read the document. Its content can slip into a summary, a “related” suggestion or the next reply in the conversation.

Permission-aware RAG in Promptev works the other way round. The person’s access is part of the search, so the wrong document is never retrieved in the first place. That is what makes it safe to open one agent to people with very different access.

Example

One agent for the whole company.

A company connects its Google Drive, its SharePoint sites and its Confluence space to one agent. The finance director asks about a supplier and gets the amounts and the contract terms. A contractor on the same project asks the same question and gets the project status, with a note that payment records are outside his access. A customer on the website asks about the product and gets an answer from the public documentation.

Nobody set up three agents or copied files into three places. The permissions each person already had decided what each of them could get.

Questions

Plain answers.

What is permission-aware RAG?

RAG (retrieval-augmented generation) means an AI model answers from documents it looks up first. Permission-aware RAG means that lookup only returns documents the person asking is allowed to open. Promptev applies the person’s access during the search, not afterwards, so a document they may not see is never fetched and never reaches the model.

Which permissions does Promptev follow?

The sharing settings already in Google Drive, Microsoft 365 (including SharePoint and OneDrive) and Dropbox, plus the audiences you set on documents in Promptev. You do not rebuild your permissions in a second place.

Does the AI model ever see a document the person cannot open?

No. The document is never fetched for that person, so it is never part of what the model reads. Nothing is fetched and then hidden.

Can the same agent serve customers and partners?

Yes. An agent on your website answers visitors from public knowledge only. Partners and other people you give access to get answers from what is shared with them, and nothing from the rest of your company.

Try it on your own documents.

2,500 free credits to start. No card, no seats.

2,500 free credits · No card required · No subscription