SECURITY & TRUST
The fear isn't that AI is useless on financial data — it's that one prompt exposes executive comp, an unreleased number, or another entity's books. Accounting systems can't prevent that: they have no row-level security, no column masking, no gate to enforce who sees what on every query. The risk isn't the model — it's the ledger underneath it.
Organization-scoped datasets and access checks establish the tenant boundary. Server-owned paths must enforce that organization scope explicitly.
Governed delivery resolves eligible, approved published data and rejects retracted, superseded, expired, or unpublished versions.
MCP, REST, and CLI use the shared query-policy boundary. Configured BI sources receive separately sanitized published datasets.