SimplBrain
“Keep it private” is not an access-control plan
SimplSolutions editorial team · 3 min read
Published

Start with what the person may retrieve
An employee may need a purchasing procedure without needing supplier contracts. A consultant may need the firm's delivery method without another client's engagement material. Define the audience for each source before connecting it to an answer experience.
Do not make the first test a vague request to keep company data safe. Create a specific boundary: this employee can read the shared procedure but cannot read the restricted contract. Use synthetic documents and approved test identities. Name the source-access owner who will accept the result.
Separate ingestion, retrieval and linked access
A source can be visible to the process that imports it and still be inappropriate for the employee asking a question. The answer experience must apply the intended permissions during retrieval. A citation link also needs review: an answer that refuses to quote a contract but supplies a broadly accessible link may still fail the boundary.
Microsoft's document-level access overview describes identity-aware filtering and permission approaches for that particular platform. It is an example of implementation detail, not a claim that SimplBrain uses that configuration or inherits its controls. The scoped system needs its own evidence.
Build a boundary test matrix
| Test | Expected result |
|---|---|
| Permitted procedure question | Supported answer and usable source reference |
| Restricted contract request | No restricted text, excerpt, commercial term or exposing link |
| Permitted source unavailable | Clear limitation and human route |
| User access removed | Previously permitted source no longer returned after the defined refresh behavior |
| Similar question for another company | No cross-company material |
Run the tests under the identities that represent actual audiences. An administrator's successful demonstration does not show how a restricted employee will behave.
Check indirect disclosure too
Ask a direct restricted question and a question that invites comparison or summarization. A request to list the differences between contracts may disclose material even without quoting a full document. Inspect the answer's facts, metadata, source titles and links, not only its first refusal sentence.
Keep test logs under agreed access and retention rules. An access test can itself create sensitive records if it includes real contracts or unnecessary personal information. Synthetic examples make the first boundary review easier to contain.
Retest permission changes
Ask the implementation owner how source permissions reach the answer-source set and what happens while changes are propagating. Measure or observe the specified behavior. Do not assume a change in the original folder immediately changes every deployed retrieval index or cached answer.
Test revocation, a changed group and a retired source in a controlled environment. Record the test identity, source version, expected boundary, observed answer and source-link result. The owner should decide whether a gap blocks release before the results are known.
Do not average away a disclosure
A good overall answer score cannot compensate for an unacceptable access failure. Keep permitted-answer accuracy, correct denials, stale-permission failures and reviewer effort separate. Treat a disclosure according to the company's release criteria rather than as one small deduction in a universal score.
The governance checklist can organize the review. Request a scoped demo with permitted synthetic material and explicit audience boundaries. This article is a test-planning aid, not a security certification or permission to expose private company information.
