Xmatix Sense — the AI capability of the Xmatix platform — is designed around a simple rule: AI may only ever see and do what the human it acts for is allowed to see and do. This statement describes the commitments behind that rule.
1. Permission-aware by design
Sense executes under the identity of the signed-in user. Every answer is produced through the platform's own data services, so record-level and field-level permissions, team and role boundaries, and tenant isolation apply to AI exactly as they apply to that user in the application. There is no privileged AI service account with broad data access.
2. Human approval for actions
Sense can propose actions, but consequential operations — data changes, destructive steps, publishing — execute only with the user's explicit approval, and only within that user's permissions. Autonomous and scheduled agent runs operate under an explicitly assigned identity with least-privilege defaults.
3. Auditability
AI activity is logged: tool invocations, approval decisions (both grants and refusals), and resulting changes are recorded with user and conversation context, so administrators can always answer who asked what, and what the AI did.
4. Customer data protection
We do not use Customer Content to train AI models. Prompts and retrieved context are processed to answer the request, scoped to the tenant, and handled under the Privacy Policy and Data Processing Addendum. Knowledge sources for retrieval are configured and owned per tenant.
5. Model choice and transparency
Customers can choose the AI models behind their tenant — including bringing their own model keys — and administrators control which AI capabilities are enabled for which users. Model credentials are stored encrypted.
6. Governed consumption
AI usage is licensed, metered, and capped: seats, credit allocations, per-model rates, and per-tenant and per-user quotas are enforced before requests reach the model, so AI spend stays predictable and under the customer's control.
7. Limitations and human oversight
Generative AI can produce inaccurate, incomplete, or outdated output. Sense is built to assist decisions, not to make them unattended: outputs should be reviewed before being relied upon, and workflows that matter should keep a human in the loop. We design the product to make review easy — citations to records, drafts instead of silent writes, and approval gates.
8. Feedback
Concerns about AI behaviour in Xmatix — including suspected permission issues, harmful outputs, or misuse — should be reported to info@xmatix.com. We investigate and correct.
