Generative AI can make reporting faster and more accessible, but it should never determine who can access sensitive data. This article explores how Visus combines AI-generated SQL with Row-Level Security and deterministic authorization to deliver flexible reporting while keeping enterprise data protected.

As organizations adopt generative AI to make data more accessible, they also face a critical question: How can users get useful answers from enterprise data without exposing information they are not authorized to see?

A SaaS provider serving multiple organizations engaged Visus to address this challenge. The platform managed sensitive member, event and operational data and supported multiple user roles, with each user receiving access to a specific subset of organizational records.

The client wanted to make reporting easier by allowing users to ask questions about their data in plain English instead of building reports or writing database queries.

For example, a user could ask, "Show me all pending tasks assigned to my team," or "Which users have no tasks assigned?"

The challenge was making that experience flexible without weakening the platform's existing security model.

AI-Powered Reporting Without Compromising Data Security

Traditional applications typically rely on predefined queries where developers control the data returned and explicitly define authorization rules. An AI reporting assistant changes that model because the SQL query can vary based on each user's request.

A user might ask a simple question, but the resulting SQL could involve joins, subqueries, aggregates or other operations that access more data than intended.

Prompt instructions such as "only return authorized records" can guide an AI model, but they cannot serve as a security control. An AI-generated query could still be technically valid while retrieving records outside the user's permitted data boundary.

Visus needed to ensure that authorization did not depend on the behavior of the AI model.

Deterministic Authorization Keeps AI-Generated Queries Secure

Visus designed the reporting workflow so the AI handled the interpretation of the user's request while the application's existing security model remained responsible for authorization.

The architecture combined natural-language requests, LLM-assisted SQL generation, deterministic authorization checks, Row-Level Security, user-context filtering and query validation before execution.

The key principle was simple: the LLM was never the security boundary.

Even if the AI generated a broad query such as:

SELECT * FROM Tasks

the database security layer would still determine which records the current user could access.

Row-Level Security provided a critical layer of protection by enforcing data access rules at the database level. Instead of relying on the AI to remember which records a user should see, the database applied the appropriate restrictions when the query executed.

This separation allowed the AI to remain flexible while keeping authorization deterministic.

Going Beyond Row-Level Security

During the implementation, Visus also identified an important distinction between row-level access and report-level authorization.

Some questions require broader visibility than an individual user possesses.

For example, a user might be authorized to view tasks assigned to their own team but not have permission to analyze task data across an entire organization. A query could technically comply with Row-Level Security while still producing an incomplete answer to a question that requires organization-wide visibility.

Returning a partial result in that situation could create a misleading report.

Visus therefore incorporated an additional authorization layer to identify requests that require broader permissions. When a report requires access beyond the user's authorization level, the application can reject the request instead of generating an incomplete or potentially misleading response.

This approach keeps the reporting experience useful while maintaining clear boundaries around sensitive data.

Flexible Reporting With Security Built In

The resulting architecture gave the client a more flexible way to interact with its data.

Users can ask business questions conversationally without needing to understand SQL or build a predefined report for every scenario. The AI interprets the request and generates the appropriate query, while deterministic security controls continue to govern which data the application can return.

The approach also reduces the need to encode every possible reporting scenario into custom application logic. New questions can be interpreted dynamically while authorization remains centralized and predictable.

Most importantly, the architecture provides a reusable pattern for organizations that want to introduce generative AI into applications containing multi-tenant or permission-sensitive data.

AI Decides How to Ask. Security Decides What to Return.

The project demonstrates an important principle for AI-enabled applications: an LLM should never be the authorization layer.

Prompt engineering can influence how an AI behaves, but it cannot provide the guarantees required for application security.

A safer architecture separates responsibilities clearly:

The AI decides how to ask for the data.

The security layer decides what data the user is allowed to see.

Row-Level Security provides a strong safeguard for dynamically generated queries, but organizations should also consider whether the user is authorized to ask the particular question in the first place.

When generative AI interacts with enterprise data, flexibility and security do not have to be competing goals. By combining AI-assisted query generation with deterministic authorization and database-level controls, organizations can create reporting experiences that are both conversational and secure.

Snapshot

Organization

A SaaS provider serving multiple organizations with sensitive member, event and operational data.

Challenge

Enable users to ask questions about organizational data in natural language while ensuring AI-generated SQL could not expose records outside each user's authorized data boundary.

Strategy

Combine LLM-assisted SQL generation with deterministic authorization, Row-Level Security, user-context filtering and query validation. Add report-level authorization checks for questions that require broader organizational visibility.

Results

The client gained a flexible conversational reporting experience while maintaining its existing data permissions. The architecture also established a reusable approach for introducing generative AI into multi-tenant applications without treating the AI model as a security boundary.