Ask my agent "what's the open pipeline for Acme Corp?" as an admin and it answers $125,000 across two deals, with a table. Ask the exact same question as a support agent and it says, politely and correctly, that it can't see pipeline data and suggests who to ask instead.
The model didn't decide that. It never gets the chance to. That's the whole project.
The problem
Give an AI agent tool access to company data and you get two questions you can't dodge:
Who is the agent acting as? A support rep must not get answers the human behind the keyboard isn't allowed to see.






