What Ace Can and Cannot See
The short version: the assistant sees exactly what you see, and nothing else. This page explains how that is enforced, because it is the question everyone sensibly asks first.
Your permissions bound every answer
The assistant reads your data through defined capabilities, and each is gated twice:
- Licence. A capability belonging to a module your organisation does not have is not available at all.
- Permission. A capability you personally lack the right to use is not available to you, even though a colleague may have it.
There is no path by which asking the assistant returns data a query would have refused you. It is another way of reading what you can already read, not a way around the permission system.
A practical consequence: two people asking the identical question can legitimately get different answers. That is the permission model working, not an inconsistency.
Logical groups apply too
If your access is narrowed by a logical group — to certain cameras, locations or entities — the assistant is narrowed the same way. Ask about a location outside your group and it has nothing to report.
What leaves your system
Answers are produced by a language model, which may run on your own hardware or on a hosted service, depending on how your administrator has configured it. See AI Configuration.
Two protections apply regardless of which:
- Camera credentials are never included in what is sent.
- Personal data is filtered by server-side guardrails before a request leaves eConnect.
If your organisation requires that nothing leaves the premises at all, that is a deployment choice: a provider pointed at a server on your own network keeps every request internal. Your administrator will know which is configured.
What is recorded
Using the assistant is audited like any other work. Sessions created, renamed and deleted, messages sent, emails sent on your behalf, and feedback given are all recorded against your account.
That cuts both ways, and is worth knowing: a question you ask the assistant is part of the record of what you did, exactly as running a query is. See What eConnect Audits.
What it does not do
- It does not change data. No editing subjects, tags, transactions or configuration.
- It does not act without asking. Sending an email is confirmed with you first.
- It does not remember across users. Your conversations are yours.
- It does not learn from your data. Answers come from reading your system at the time you ask.
If an answer seems incomplete
Before assuming a fault, check whether it is a boundary:
- Do you have the module in your navigation drawer?
- Can you reach the same data through the ordinary views?
- Is your access narrowed by a logical group?
If all three are fine and answers are still thin, the cause may be a failing capability rather than a permission — an administrator can see that under AI Usage and Analytics.