SECURITY & GOVERNANCE

AI Uses Each Employee’s Permissions—Never a Super Account

Every AI request maps to a real employee and remains subject to the source system’s functional and data access. Queries and validation may run automatically, while create, update, delete and approval actions require employee confirmation by default.

View the Audit Interface
  • Real Employee Identity
  • Source-system Access
  • Human Confirmation
  • End-to-end Traceability
ONE GOVERNED AI BUSINESS REQUESTTWO-LAYER ACCESS CONTROL
IDWHO AI REPRESENTSReal Employee

Employee personal account

NEBULA PLUSAI Business Pass
Capability AuthorizedKey Action Confirmed
TARGET SYSTEM MAKES FINAL DECISION
ERPCRMMESWMSOA

Existing functional and data access

  1. 01Identity
  2. 02Access Check
  3. 03Confirmation
  4. 04Audit

AI BUSINESS PASS

AI Can Only Do What the Employee Can Do

Nebula PLUS combines connector capability authorization with the target system’s existing permission decision. Functional and data access remain subject to the target system—never a shared super account.

ID
AI BUSINESS PASSDemo Employee · Supply Chain
IDENTITY VERIFIED
  1. 01
    Real EmployeeWho is using AI
  2. 02
    Functional AccessWhat they can use
  3. 03
    Data AccessWhat they can see
  4. 04
    Human ConfirmationWhether key actions submit
  5. 05
    Action RecordEvery step is traceable
  6. 06
    Immediate RevocationRole changes apply at once
AI uses each employee’s own business permissions—not a super account with access to everything.

EMPLOYEE IDENTITY MAPPING

First Establish Which Real Employee AI Represents

Map the user in WorkBuddy or another AI entry point to the employee’s personal business-system account. Custom authentication is supported and every subsequent request has a clear accountable identity.

  • Use the employee’s personal account
  • Support custom authentication and mapping
  • Stop access when a mapping is disabled
Nebula PLUS employee identity mapping interface connecting AI users to business employees
BASED ON THE REAL PRODUCT · DEMO DATA

FUNCTIONAL & DATA ACCESS

Control Both the Actions and the Data Scope

AI receives no access beyond the employee. The target system remains the final authority.

WHAT THEY CAN DO

Functional Access

Determines which business actions the employee may query, create, update or approve.

  • Query orders
  • Create shipment tasks
  • Submit approvals
WHAT THEY CAN SEE

Data Access

Determines which organizations, regions and business records the employee may see or process.

  • Assigned company
  • Responsible region
  • Authorized order scope
AI effective access = connector authorization ∩ target functional access ∩ target data access
WorkBuddy validates business information and prepares a campaign order page for employee confirmation
BASED ON THE REAL PRODUCT · DEMO DATA

KEY ACTION CONFIRMATION

AI Prepares the Work. The Employee Confirms Submission.

Create, update, delete and approval actions require human confirmation by default. Each capability can require confirmation or allow automatic execution; employees confirm in the business page or AI workspace before the connector makes the final API submission.

  1. 1Configure confirmation per capability
  2. 2Confirm in the page or AI workspace
  3. 3Connector makes the final submission

INVOCATION AUDIT

Review Who Did What, When and With Which Result

Invocation records retain input parameters, output results or summaries. They can be queried and exported by employee, system, capability, time and result; retention is customer-configured and sensitive fields can be masked.

Nebula PLUS invocation audit interface showing employee, business capability, target system, time and result
BASED ON THE REAL PRODUCT · DEMO DATA
  • Employee & System
  • Capability & Time
  • Input/Output Summary
  • Result
  • Query & Export

ACCESS CHANGES & REVOCATION

Role, Account and Access Changes Apply to the Next Request

Nebula PLUS does not permanently cache employee business permissions. Target-system changes apply from the next invocation; revoking an employee, group or organization grant in the connector blocks future calls immediately and stops in-progress calls.

  1. 01

    Access Changes

    Role transfer, departure, account disablement or business-scope update

  2. 02

    Identity and Access Are Re-evaluated

    The next invocation reads the employee’s currently valid scope

  3. 03

    Revocation Applies Immediately

    Future calls are blocked and incomplete calls are stopped

FAQ

Common Security Evaluation Questions

Can AI bypass source-system permissions?

No. Each request maps to a real employee, and the target system’s functional and data access determine the effective scope.

Does AI automatically submit every action?

No. Create, update, delete and approval actions require confirmation by default. Each capability may require confirmation or allow automatic execution.

What does the audit record include?

Input parameters, output results or summaries can be queried and exported by employee, system, capability, time and result. Retention is configured by the enterprise and sensitive fields can be masked.

When do employee access changes take effect?

Target-system changes apply on the next call. Connector authorization revocation blocks future calls immediately and stops incomplete calls.

Must we change existing deployment boundaries?

No redesign is required as a prerequisite. The assessment determines a connection approach based on current architecture, security requirements and the target scenario.

Start With One Real Scenario and Define the Security Boundary

Align employee identity, target systems, functional and data scope, confirmation points and audit requirements.