Skip to content
Market

Trust as Architecture

Trust as Architecture

How customer data moves, where it lives, who can touch it, and how integration earns its way forward.

Master Data Architecture v1.0 · May 2026 · Customer-presentable

The Promise

Only authorized systems and approved client-side users access the minimum data needed for the function. Every access path is scoped, encrypted, masked where masking applies, and auditable. NxI staff do not browse customer data. Model providers do not train on it. Every high-impact action requires human approval before it executes.

Delivered by architecture, not by policy.

Covenant

Three-state authority gating

Autonomous

Reads, drafts, recommendations. System executes without approval.

Human-in-the-loop

Drafts written by AI. Humans approve before execution. Default for any writeback.

Irreversible

Blocked. The system never executes. Payment, payroll, vendor contracts, record deletion.

Deployment Models

Three deployment models. One architecture. The customer chooses where the boundary sits.

Model A · Customer Cloud

Inside the customer's cloud account. Customer owns keys, policies, network, audit. Default recommendation for sensitive operators, healthcare, defense.

Model B · Private Tenant

NxI-hosted, tenant-isolated. Bring-your-own-key encryption. Per-customer logical and cryptographic isolation. No shared databases.

Model C · Hybrid Edge

Raw ingestion, redaction, aggregation inside the customer's network. Only approved features cross the boundary. AI never sees raw records.

In every model, the customer can shut NxI off without a migration.

Pilot Phasing

Engagements move through stages. Each stage expands access only after the prior stage clears.

Stage 01–2 wks

Discovery

System inventory, data classification, integration plan. No credentials required.

Stage 12–4 wks

Sanitized POC

Masked or synthetic values. Architecture demonstrated end-to-end.

Stage 24–8 wks

Read-only Live

Dedicated service accounts, minimum scopes, encrypted storage. No writeback.

Stage 32–4 wks

AI Recommendations

Live data, derived outputs only. No actions in customer systems.

Stage 42–4 wks

Drafts

AI generates drafts of high-impact artifacts. Humans approve.

Stage 5ongoing

Controlled Writeback

Approved drafts execute through customer-system APIs under Covenant gating.

Handshake to first writeback: 60 to 120 days. Pace is set by the customer.

Data Minimization

Customers authorize fields, not databases.

Data classDefault postureTreatment
Operational data (sales, inventory, vendor lists, POs)Ingested at the aggregation level the function requiresEncrypted, scoped by location and region
Pricing, recipes, vendor terms, contractsIngested when the function requiresConfidential IP. Field-level encryption. Smallest-set access.
Cardholder dataNever ingestedOut of PCI scope by design
Customer PII (guest names, contact info)Not ingested unless the function requires it and the customer authorizesEncrypted, masked, function-scoped
Employee PII (SSN, bank, biometrics)Not ingestedRole and hour aggregates suffice for labor functions
Free-text notes, surveillance, biometricsNot ingested by defaultOften contains private content the customer did not intend to share

Action Gating

Every action classified by risk. Gated accordingly.

ActionRiskRule
Forecast, flag variance, recommend par changes, draft PO, suggest transfers, rank vendors, detect waste, create exception reportsLow / MediumAI executes autonomously. Recommendations and drafts only.
Submit purchase order, approve invoice, change par level, change scheduleHighHuman approval required before execution
Change vendor price, change menu price, change recipeHighHuman approval required. Logged with reason.
Post accounting entry, modify payroll, alter tax or payment settings, delete recordsIrreversibleBlocked. AI never executes.

Access Control

Zero standing access. Authority granted by role, scoped by function, revocable by the customer.

ActorDefault accessRaw dataNotes
Customer executive sponsorReports, dashboardsLimitedBased on customer role policy
Customer security / adminAudit logs, access policiesYes, if authorizedCustomer's data, customer's control
Store / location managerOperational outputsLocation-scoped onlyNo broad raw access
NxI supportHealth metrics, redacted logsNoNo raw payloads ever
NxI engineeringCode, infrastructureNoNo production data by default
AI modelMinimum scoped contextNo full databaseRetrieval-limited
Model providerInference window onlyNo trainingData-processing terms required
Break-glass responderTemporary, approvedPossibleTime-limited, logged, customer-notified

Operating Disciplines

Support blind by default

Support sees system health, connector status, redacted error categories. Support does not see raw payloads, business data, vendor pricing, recipes, employee data, or credentials. Tickets, Slack channels, and email never contain raw customer data.

No production browsing

Engineers do not browse production. Production data is not copied into development. Customer screenshots are not shared. Break-glass access requires a ticket, customer approval, a time limit, and a post-access review.

Metadata, not secrets

Logs contain Job ID, connector ID, store ID, timestamp, record count, error category, schema version, latency, service account ID. Logs do not contain invoice line items, vendor pricing, recipe ingredients, employee names, guest data, secrets, or full model responses with sensitive values.

The AI should never need broad raw-data access when a scoped, masked, purpose-built data view will do.

Forge is the engine. Covenant is the gate. The Agentic Table is the instrument. The whole platform is the NxI Ecosystem.