FAQ

The questions enterprise teams actually ask.

Straight answers on governance, access controls, data provenance and deployment — the things security, data and architecture teams need to know before SenseMesh touches the estate.

01Governance

Governance and control

How is governance enforced — is it just policy documents?

Governance is executable. Definitions, sensitivity classes and consumption policies are stored as versioned configuration and evaluated on every query and agent request. A policy change is a reviewed code change with an audit trail, not a wiki page.

Who owns a business definition in SenseMesh?

Every definition has a named human owner and an approval history. Ownership is required to publish a definition into the semantic layer, and ownership transfer is itself a governed, audited event.

Can agents bypass governance if they connect directly to our warehouse?

SenseMesh governs everything that flows through the mesh. Agents deployed with OneCortex consume only SenseMesh products. If other tools query sources directly, those paths are outside the mesh — the readiness assessment explicitly inventories them so they stop being invisible.

How do you handle regulatory change?

Policies and classifications are versioned. When a regulation changes, you update the policy pack, review the affected products through lineage impact analysis, and roll forward with full history of what changed and when.

02Access controls

Identity and access

Which identity providers do you support?

Any SAML 2.0 or OIDC provider — Entra ID, Okta, Ping and others. SCIM handles provisioning so role changes propagate without manual steps.

Are AI agents treated as users?

Yes — agents are first-class principals with their own identities, scopes and rate limits. An agent's permissions are typically narrower than any human's: it gets the specific products its task requires, nothing more.

How granular can access get?

Grants apply at the level of intelligence products, entities and attributes. A product can expose an entity while masking classified attributes, with masking inherited automatically by anything derived from it.

What happens when someone leaves the organisation?

SCIM deprovisioning revokes access immediately. Their definition ownership is flagged for reassignment so governed knowledge never becomes orphaned.

03Data provenance

Lineage and provenance

What does lineage actually cover?

Field-level lineage from source system through every transform to the intelligence product, plus definition authorship and decision lineage — which products and definitions produced a given answer.

Can we replay why an agent gave a specific answer?

Yes. Every assistant or agent response records the exact products, definition versions and source freshness windows used. You can replay the decision against the state of the mesh at that moment.

Does SenseMesh copy our data?

No bulk copies are required. SenseMesh reads metadata, profiles and samples during discovery, and queries sources in place through governed connectors. Materialisation only happens where you explicitly configure it for performance.

How fresh is the data behind a product?

Every product declares its freshness window and actual freshness is monitored against it. Consumers see staleness explicitly — an agent knows when it is reasoning over data that is six hours old versus six minutes.

04Enterprise deployment

Deployment and operations

Where can SenseMesh run?

Three models: SenseMesh-managed cloud with regional data residency, your own VPC, or fully air-gapped for disconnected environments. All three share the same governance plane and feature set.

What systems does it connect to?

Warehouses and lakehouses (JDBC, CDC), SaaS systems such as ERP, CRM, ITSM and HRIS via API connectors, document and content stores, and existing catalogs. Connectors are read-scoped and credential-isolated per tenant.

How long does a deployment take?

A readiness assessment surveys an estate in weeks. First governed intelligence products typically ship within the first quarter, domain by domain, rather than as a big-bang programme.

What support and success model comes with it?

Enterprise deployments include a named architecture team, rollout planning per domain, and 24/7 SLA options. See the pricing page for tier detail or contact sales for custom terms.

Something more specific?

Architecture, security or procurement questions go straight to the team that owns them.