The AI assistant inherits the caller in all three policy columns. It has no grants of its own, so nothing had to be reasoned about twice and nothing can drift apart.
The same is true of every channel: JDBC, REST, GraphQL and MCP read the same grants. A policy is written once, at the integration layer, and enforced everywhere.
The platform SRE row is deliberately empty of customer data. Running the platform does not require seeing what is in it.
How row policy is expressed
As a predicate over the enterprise customer, derived from the caller's claims — region for agents, account book for relationship managers, case scope for the privacy officer.
Aggregate-only access for BI developers means detail rows are unavailable but counts and sums are not, which is what lets a report be built before access to the detail is granted.
Risks
The steward role can see everything unmasked. It is the highest-privilege role in the platform, requires a recorded reason per access, and is reviewed monthly.