Permissions hold through AI
NO SIDE DOOR
The AI runs under your permissions. A field hidden from you never enters AI context — not in answers, not in summaries, not in search. The Ask page lists exactly which fields are hidden from the AI for you, by name, so the guarantee is readable, not asserted.
An outside agent is still a person
MCP
RowFold is an MCP server, so Claude Code, Claude Desktop or Cursor can work your workspace directly. A connection is bound to one member and sees exactly what that person sees: hidden fields stay hidden, no-access tables stay invisible, and there is no separate integration-permissions model to configure or get wrong. Writes are off until you allow them, and land in the audit log as MCP · connection (as person).
AI changes are signed
AUDIT TRAIL
Everything the AI creates or changes appears in the audit log as its own actor — AI · Ask (for you) — exactly like API · token and Automation · name. "Who changed this?" has one consistent answer, and an AI write is never dressed up as a human one.
One click walks it back
UNDO
Records the AI creates come with an Undo on the confirmation — they move to the Trash, restorable like anything else. Schema changes are confirm-to-apply before they happen: the AI proposes, you approve, nothing lands silently.
Honest when it can't
FAILURE POSTURE
Ask answers from your records, never from recall — and when your data can't answer the question, it says exactly what's missing instead of producing a confident number from nowhere. Fair-use limits fail open — a metering hiccup never blocks a paying customer. And when a verification check can't re-run, the receipt says so instead of quietly shrinking the denominator.