Embedded AI
Why
Giving a director, or a premium bank, conversational access to their own data has real usage value — but only if the language model can never write a free-form query nor cross a tenant, role, or access-type boundary. This process makes that access possible without ever opening it up to a data leak.
How, in the application
The conversational requêteur never lets the model generate SQL: it can only choose from a closed catalog of typed tools, one per access type (ERP and financing, financing only, or investor), with only one catalog loaded in memory for a given session. Every tool call passes through a single choke point that refuses any unknown tool name, rejects any scoping parameter the model might try to send itself (tenant identifier, user identifier, role), validates the rest against a strict schema, executes the query on a dedicated read-only connection, then verifies that every returned row genuinely belongs to the calling tenant — any foreign row fails the entire batch, not just the offending row. Every call is audited at this same choke point, never by the business code that processes the request.
The database connection dedicated to the requêteur holds only read rights, on a closed list of tables, with a strictly limited execution time — no sensitive table (users, payment configuration, signature, audit logs, KYB files) is ever accessible there.
The investor catalog continues to anonymize what it returns — supplier and buyer identity excluded, amounts and durations grouped by tier, sector anonymized by k-anonymity — even though the public market intended for investors has otherwise been closed: this catalog queries the historical data directly, independently of the closed screens, and therefore remains subject to this same anonymization.

Safeguards
- A platform administration role can never use the requêteur — access is explicitly blocked before an LLM call is even considered, as is a profile with conflicting roles.
- Access is subject to a premium-subscription check, verified before any spend on a model call — every refusal, whether by role or by subscription, is audited before the error is returned.
- The list of accessible tables exists twice, once at the database-role level and once at the application level — the two must match, and one acts before the other is even consulted.