Summary
"Pi Data Access" is a tenant-level security setting that caps what Pi can do with your data on behalf of any User
You - as a Planhat admin - can use it to keep Pi inside the limits you define. For example, this could be to stop Pi exporting records, or to keep Pi within each User's own Company portfolio
The limits defined by Pi permissions sit on top of each User's Role: Pi can do an action only if the User's Role and the Pi cap both allow it
You can navigate to Pi Data Access from the AI Governance Hub (from the Agents Module/Tool) or the Security part of the Settings Tool
Who is this article for?
Anyone who would like to understand how to limit what Pi can do with tenant data
It's particularly relevant for Planhat admins who govern security and AI use for their organization
Related articles
Other articles particularly relevant to this article are:
Article contents
Introduction
Pi acts on behalf of the person (User) chatting with it. Without a cap, Pi could do anything that person's Role allows - including actions you might not want an AI assistant to perform automatically.
"Pi Data Access" lets you (as an admin in your Planhat tenant) define Pi permissions to set limits that apply to everyone in your tenant, in addition to the limits set by each User's Role.
The Pi Data Access settings only ever narrow what Pi can do. These Pi permissions never give Pi more access than the User already has from their Role. They are a security feature that gives you additional control over Pi.
📌 Definitions
"Pi Data Access" is where you can configure Pi permissions, to determine the maximum data Pi can read, create, or change on behalf of any User in your tenant
A "Role" is the Planhat version of a profile or a permission set, and is applied to each User to define their level of access within the tenant
"Admin" - a User who configures/manages their Planhat tenant for their organization; typically this refers to Users with the "Administrator" Role, including the "Admin Access" workflow permission
"Tenant" - your organization's copy of Planhat; also sometimes referred to as a workspace or environment
"Pi" - Planhat's main AI agent, built into Planhat OS
"Sessions" - where you chat with Pi and/or colleagues (other Users)
"User" (with a capital) - the Planhat data model for users of Planhat (as opposed to users of your product, which are called End Users)
"Data model" (or sometimes simply called "model") - how data is organized within Planhat; similar to the concept of objects in other Tools. "Company" is the data model for organizations that are your customers or prospects (sometimes called accounts)
What is Pi Data Access?
"Pi Data Access" is one of the security features in your Planhat OS tenant.
"Pi Data Access" is where you set Pi permissions - these are made up of data model permissions (including field permissions) and portfolio permissions, like those you may be familiar with from User Roles.
The Pi permissions you (as a Planhat admin) set within Pi Data Access apply a cap/limit to what Pi can do within your tenant. Each individual User within your tenant will only be able to use Pi to carry out actions allowed by their own Role permissions, and then the Pi permissions apply as a cap over the top - the Pi permissions can limit access, but not provide extra access.
To summarize: Pi can only carry out an action when the User's Role and the Pi Data Access settings (i.e. Pi permissions) both allow it.
Further details
User permissions are set in Planhat via Roles. Role permissions are divided into three categories: portfolio permissions, data model permissions, and workflow permissions.
Pi permissions within "Pi Data Access" have equivalents for two of those categories: portfolio permissions and data model permissions. We summarize these two below; for further details on these permissions, you can refer to the main permissions articles linked to above.
Portfolio permissions define which Companies can be viewed and interacted with. This is a single dropdown with four options, covered in the "How" section below
Data model permissions
Data model permissions cover the standard Planhat data models such as Company and End User, but also other features/aspects such as Snippets and Sections
You can separately enable/disable Create, View, Update, Remove and Export permissions for the different data models
You also have granular control over individual properties/fields of the models
📌 Important to note
When Pi Data Access has never been set, Pi runs at each User's full Role - there is no extra cap. The limits start to apply as soon as you (as a Planhat admin) turn off a permission or choose a portfolio limit.
Why use Pi Data Access?
Pi Data Access is for organizations that want a clear, tenant-wide limit on what Pi can do. It is an extra layer of security and control, applied over the top of the Pi restrictions already in place for each User from their Role.
Typical use cases:
Keep Pi from touching certain fields or models, even for Users whose Role allows it
Keep Pi within each User's own accounts (Companies), so it never reads Companies the User does not own
Hide sensitive fields from Pi, while still letting Pi help with everyday work
How to configure Pi Data Access
📌 Important to note
To see/access the "Governance" part of the Agents Module (Agents Tool), sometimes referred to as the "AI Governance Hub", your Role needs the "Admin Access" workflow permission
The Pi permissions set in Pi Data Access apply to all Users in your Planhat tenant - you are not just applying a limit to your own personal use of Pi
Go to the Agents Module, also called the Agents Tool
You may already have this pinned to your sidebar, or otherwise click "More" in the Tools area of your sidebar to access the main Tools menu
Mouse over the "Governance" part near the top, and click "More", to open up the "AI Governance Hub"
Open "Pi Data Access"
Use the "Portfolio" dropdown menu at the top if you want to apply a limit to Company access when Users in your tenant use Pi. The dropdown menu options are:
Only the User's own portfolio
No portfolio limit
Only the User's Team portfolio
Only Companies matching a filter
If you select this, you then configure a filter here
For more on portfolio permissions, you can refer to our Role portfolio permissions article here
To cap what Pi can do with records of a data model, adjust the data model permissions
Models are organized in two main categories: "Business models" at the top, and "System models" at the bottom
Depending on the model, you will be able to configure some or all of: Create, View, Update, Remove and Export
You can click into models to open up their nested properties (fields) and edit those permissions too - you have granular control
For more on data model permissions, you can refer to our Role data model permissions article here
That's it! Your changes automatically save, and will apply the next time a User chats with Pi in your tenant.
🚀 Tip
As well as going via the AI Governance Hub in the Agents Module/Tool as described above, you can alternatively navigate to Pi Data Access by going to the Settings Tool, and clicking on "Pi Data Access" under the "Security" heading.
📌 Important to note
At time of writing, Pi cannot delete records, despite what the Pi Data Access may imply - although it's expected that this functionality will be added in future.
Frequently asked questions (FAQs)
Q: Why can Pi not do something that I can do myself in Planhat?
A: Pi is limited by both your Role permissions and the tenant-wide limits set in "Pi Data Access", so a tenant admin may have disabled an action for Pi that your own Role allows when you're working manually. (Also check Pi's general limitations here - there are certain actions that Pi won't do, regardless of what's set in Pi Data Access)
Q: Does Pi Data Access give Pi extra access - e.g. can I do something via Pi that my Role does not have permission for?
A: No. Pi Data Access only narrows what Pi can do. Pi can never do more than the User it is helping
Q: Does turning a permission off in Pi Data Access affect admins too?
A: Yes. A permission turned off in Pi Data Access is disabled for everyone
Q: Who can change Pi Data Access?
A: Only Planhat Users with the "Admin Access" workflow permission enabled in their Role (typically the Administrator Role) can access the Pi Data Access area
Q: Does Pi Data Access include workflow permissions like those in Roles?
A: No - Pi Data Access consists of portfolio permissions and data model permissions, but not workflow permissions
Q: Is there a record of changes made to Pi Data Access?
A: Yes - every change is recorded in the tenant security log
Q: How will I know if Pi Data Access limits are preventing me from carrying out an action using Pi?
A: When the Pi permissions cap (rather than the User's own Role) blocks a Pi action, Pi tells you it was blocked by the tenant's Pi permissions and points you to an admin







