What the AI employees can read
Twenty data sources across every module, each gated by the same workspace rules that gate a screen.
The employees read from a registry of data sources rather than having open access to the database. Access is decided in one place, so an AI answer obeys exactly the same permission ladder as a screen.
Accounting — chart of accounts, general ledger, invoices and bills, payments, customers, vendors, items, projects, bank feed, time.
CRM — accounts, contacts, opportunities, cases, activities, leads.
Marketing — campaigns, email sends, content.
Their own history — the task log, so they can answer questions about their own work.
Each source names the workspace that owns it. A CRM-only user asking what was billed to a customer gets a refusal with a reason, not a number they were never meant to see.
Field and filter names are validated against the registry before any query is built, so a natural-language question can never become an injection point.
Settings → AI shows exactly which sources are readable for you and which are withheld.