Same person. Same access.
Choose an example person. Their assistant works through their accounts; it does not get a new company-wide identity.
This person has CRM and Drive access. Their assistant uses those same accounts.
Their own logins
brain
Existing access rules
Illustrative profiles, not a live access audit. Bank is an example, not a confirmed integration. Connections show account use, not passwords sent to the model.
What we did need to divide.
We needed somewhere to keep what we learned, including skills: written procedures an assistant can run. A repository is a shared home for those files, with its own access list.
Department A
Standard knowledge + skills
Procedures, working notes, a reporting skill.
Readers: people with access to this department repository.
Strategic knowledge + skills
Strategy, management decisions, confidential material.
Readers: owners and directors granted access to this repository.
Department B
Standard knowledge + skills
The same structure, with this department’s own access list.
Strategic knowledge + skills
A separate repository with a shorter reader list.
My private repository
Personal notes + skills → only me.
Being someone’s director does not give their assistant access to that person’s private notes.
A colleague improves a shared skill → saves it in the department repository → colleagues with access receive it after sync. Each runs it using their own logins, without inheriting the author’s permissions. Credentials stay out of shared knowledge.
Illustrative structure, based on the owner’s description; not a live access audit. The rule is two repositories per department, plus one private repository per person. Our September 2026 inventory had strategic repositories in 6 of 15 departments. Job titles alone do not grant access.
Knowledge, skills and the person’s own logins.
The folders above, by access.
Opened with the person’s logins.
Model providerGets the question and the text the assistant chose to send.
Where things live. The assistant runs on the laptop, the knowledge arrives from the repositories above, and the only thing that leaves is the text sent to the model provider.
The old part of the problem.
Who should have access, and who no longer should, was a problem long before AI. An assistant inherits it.
Is this safe?
Is it safe? It uses your own logins, nothing more.
Does my data go to external servers? Only the question and the text the assistant picks go to the model provider. The rest stays on your laptop.
Do I keep my access? Yes. Nobody gets access through the assistant that they did not have before, and removing someone’s access in a tool removes it for their assistant too.
Do I need to anonymise? Decide what can go to the model before you send it. Reading is not permission to redistribute: an answer may reach someone who could not read its sources, so shared knowledge is checked before it is saved. How we decide what may go there.
For how the assistant finds the right knowledge, see how it reads the index first.

