Capability · Permission Management

Permissions you can prove, not promise.

This is the trust layer everything else sits on, and we designed Mimirio from the ground up to get it right. Every access decision is a deterministic rule, enforced the same way every time — not a judgment call an AI makes in the moment, and not something you have to take on faith.

GDPR-compliant · EU AI Act-ready

The rules we never break

An LLM never makes the call

Permission decisions happen entirely outside the model. The AI has no path to reason its way into access it wasn’t granted.

Deterministic, not probabilistic

Every access rule resolves the same way, every time — no temperature, no edge-case guessing, no drift between two runs of the same request.

Verified and audited, always

Every access path is logged and checkable after the fact, so trust in Mimirio doesn’t have to be blind.

Three layers, one path in

To reach a single piece of data, every user passes through all three gates — in order, every time.

Agent Layer

The first gate: does the user, or their group, have access to this agent at all?

Knowledge Pools

A pool groups sources together — often mirroring a department or a company — and pools can stack on top of each other for finer-grained control.

Source

The actual connected system. Agents authenticate through a service account; for a user’s own individual access, see Connected Services below.

How this looks in practice

Anna in Finance asks Mimirio to summarize last quarter’s departmental spending. She isn’t a member of the HR Knowledge Pool, so HR’s compensation data never enters the search space for her query — Mimirio doesn’t retrieve it and then decide to hide it, it never sees that the data exists in the first place.

That’s the distinction that matters. Many retrieval-based AI tools search broadly across everything and filter or redact results afterward. Mimirio scopes before retrieval, at the Knowledge Pool layer — so there’s nothing sensitive sitting in a context window waiting to be filtered out.

Shared access vs. your own access

Company-wide knowledge is reached through a shared service account, scoped by the layers above — the same access every authorized user gets. On top of that, you can individually authorize Mimirio to reach your own personal spaces — inbox, calendar, personal drive — through Connected Services, without changing what anyone else in the organization can see.

Built to hold up under scrutiny

These aren’t policy promises — they’re structural guarantees, built into how Mimirio is deployed and enforced.

GDPR-compliant EU AI Act-ready Deterministic by design Fully auditable

Common questions

What happens if someone’s access changes mid-conversation?

The next request re-checks all three layers. Nothing granted earlier in a conversation carries over as a standing exception.

Does this map to how we already organize users and groups?

Access is granted to users and groups, not re-invented as a parallel permission system you have to maintain separately.

Can I see exactly what an agent accessed, and when?

Yes — every access path is logged, so any decision can be reviewed and verified after the fact, not just trusted in the moment.

Who actually configures and owns these rules?

You do. Knowledge Pools, agent access, and source connections are set up and controlled by your own admins — Mimirio enforces the rules, it doesn’t own them.

See it running on your own data.

Book a 30-minute call and we will walk you through this feature with your own data — personally.

Free & non-binding · Clarity in 30 minutes · Pilot project on request