Back to InspirationData

    Governance for AI agents using company data: keys, limits and audit trails

    September 10, 20269 min read
    Governance for AI agents using company data: keys, limits and audit trails

    Agent programmes rarely die from bad models. They die from an unscoped key, a runaway loop, an unexplainable answer or a data-use question nobody can answer. Governance is the boring layer that keeps the interesting layer alive.

    Keys, scopes and limits

    Issue one key per agent and per environment, scoped to the markets and fields that agent needs. Rotate on a schedule. Never let a prototype share the production key.

    Set request and cost ceilings per key, with an alert before the ceiling. A looping agent can burn a monthly quota in an hour if nothing stops it.

    Caching, retention and correctness

    Cache by volatility: identity fields for long, status and address for short, signals not at all. Record the fetch timestamp so any answer can state how fresh it is.

    Keep an audit log of every tool call: who or what asked, which record, which fields, and what was returned. Without it you cannot reconstruct why an agent said something.

    Personal data and lawful use

    Director and officer details come from public registers, but publishing a register is not the same as unlimited reuse. Document your purpose and legal basis, honour objection requests, and keep personal fields out of general-purpose prompts unless they are needed.

    Drimble sources from official registers and does not provide company data for the Netherlands; make the same scope explicit in your agent's instructions so it does not improvise coverage it does not have.

    Frequently asked questions

    How do I explain an agent's answer to a customer?

    From the audit log: the tool calls made, the records returned, the register and the timestamp. Design for that from day one rather than adding logging after an incident.

    Can I put director names into an AI prompt?

    Only with a documented purpose and legal basis, and only the fields you actually need. Minimise personal data in prompts and keep it out of long-term model logs.