How it works in a data room
When a user asks an assistant a question, the system first works out which documents that user can see, then retrieves and reads only from that set. Permission checks happen at query time, so a change made by the administrator a minute ago is respected. Summaries, citations and suggested answers should reference only visible files, and the system should avoid hinting that hidden material exists. Indexes built for AI search are tagged with the same access rules as the files, rather than being pooled across groups.
Why it matters in a deal
The whole value of a data room rests on granular permissions and bidder isolation. An assistant that answers from the full room would leak clean team material to the wrong people or show one bidder another bidder’s Q&A. Before switching on AI features, sellers should test them with low-privilege accounts and confirm in writing how the provider enforces access at retrieval time.
Example
A seller’s adviser logs in as a test bidder with access to the commercial folder only and asks, “What are the change of control terms in the key supply agreements?” The assistant answers from the two agreements in the commercial folder and says it found nothing else, even though a third agreement sits in a restricted legal folder. The test is repeated after every permission change.