Qubit Docs العربية

What the AI can and cannot access

Security teams often ask what the Assistant can see and where that information goes. This page explains it.

How the Assistant answers a question

When you ask a question such as "What was our revenue last quarter?", the Assistant:

  1. Reads the workspace's data model: table and column names, their descriptions, and the definitions in the semantic layer and metrics.
  2. Writes a SQL query.
  3. Runs the query against your data connection, with your access.
  4. Reads the rows the query returns and writes the answer.

The query results can include individual records, such as customer or order rows, as well as totals. Whatever the query returns, the Assistant can read.

The Assistant works with your access

The Assistant runs queries as the person who asked. Data permissions and row restrictions apply to its queries in the same way they apply to yours. If you cannot query a table, the Assistant cannot query it for you, and row restrictions filter its results the same way they filter yours. See Access Control.

What the Assistant can create or change for you is limited by your capability switches. See Personal agent settings.

What is sent to the language model

To produce an answer, Qubit sends the language model:

  • Your question and the earlier messages in the conversation.
  • The workspace's organization context and your personal agent instructions.
  • The parts of the data model that are relevant to the question.
  • The results of the queries the Assistant runs.
  • Passages from any documents you attach.

Other AI features, such as generated dashboards, reports, and insights, send the data they work with in the same way. Some automatic steps, such as drafting descriptions for tables and columns, can include small samples of column values.

Uploaded documents

Documents you upload to the Data Catalog are split into passages and indexed for search. When you attach documents to a question, the Assistant searches them and uses the most relevant passages in its answer. Document permissions apply, so the Assistant searches only documents you can access.

AI runs are recorded

While audit recording is on, which is the default, each AI run is recorded in the workspace audit log, including the request, the answer, the model used, the SQL statements run, and the person's access at the time. Owners and admins can review these records. See Audit Logs.