6.3 Data Flows and Access Management

Data flows and access management are critical to maintaining control, accountability and trust in how data is used across the organisation. Data is reused widely across systems, services and advanced capabilities, and actions can increasingly be initiated without direct human intervention. This places higher demands on how data flows are defined and how access is granted, monitored and enforced.

New forms of data use, including large-scale reuse, unstructured information and AI-assisted processing, require more deliberate control over data flows and access rights. AI-enabled capabilities increase the volume, speed and autonomy of data use, making implicit assumptions and informal controls insufficient.

The Data Architect ensures that data flows are visible, reliable and aligned with information architecture. The Chief Information Security Officer (CISO) ensures that access rights, identities, security controls and monitoring protect data across human users, integrations, automation and AI-enabled capabilities. Together, these roles help ensure that data can move efficiently without weakening accountability or control.

Data flows as part of information architecture

Data flows are defined as part of information architecture and remain an integral element of enterprise architecture. They describe how data moves between systems, platforms and services, how it is transformed along the way, and where controls are applied. In practice, data flows are implemented through integration platforms, interfaces and data pipelines where rules, validations and controls are configured.

These flows ensure that data is delivered to the right place, in the right format and at the right time. They also define which systems are allowed to produce, consume, transform or update data. Clear definition of data flows remains a prerequisite for reliability, traceability and control.

As data is reused more broadly, data flows must also describe the context in which data is used. It is not enough to know that data moves from one system to another. The organisation must understand whether data is used for reporting, operational processing, automation, decision support or action-triggering. This makes data flows an essential management view, not only a technical integration view.

 

Figure 6.3.1 Data flows as part of information architecture

6-3-1 Data flows as part of information architecture

Role-based access as the foundation

Access to data is traditionally managed through role-based access control. Individuals are assigned roles, and roles carry predefined access rights. This approach simplifies maintenance, supports segregation of duties and ensures consistency. When access rights change, the change applies uniformly to all users in the role.

The same rules apply no matter how data is accessed. Whether a person uses a system directly or another system uses the data automatically, the same access rights should apply. This ensures that data is protected consistently and does not become easier to access simply because it is used through an integration, automation layer or AI-enabled capability.

This role-based foundation remains essential, but it is no longer enough. New forms of automation and AI-driven use challenge existing assumptions about predictability, supervision and accountability. Access must therefore be designed with greater precision, so that rights reflect what the user, system or AI-enabled capability is actually allowed to do.

Impact of AI-driven use on access and accountability

Like earlier automation, AI-enabled capabilities can be configured to use systems through the same interfaces and access rights as human users. In robotic process automation, this behaviour was predictable and tightly scripted. The automation followed predefined steps and performed only the actions it was explicitly programmed to do.

Generative AI changes this dynamic. These capabilities can interpret unstructured information and produce content, decisions or actions beyond fixed scripts. For example, an AI-assisted sales capability may prepare a customer offer and, once approved, enter the order into core systems in the same way a sales employee would.

Because AI-enabled capabilities can be created, configured and shared rapidly, responsibility can become blurred. Actions may technically be executed under personal user credentials, but this should be treated as a risk rather than a target model. Growing trust in AI can also reduce active human supervision, making it harder to see who is effectively making decisions, under what authority and within which boundaries.

AI-enabled capabilities therefore need explicit accountability, controlled access, traceability and oversight. The organisation must define whether the capability is only supporting a person, preparing a recommendation, changing data, creating records or triggering business commitments. These are different levels of authority and require different levels of control.

Principles for managing access in an AI-enabled environment

Addressing reduced predictability and blurred accountability requires a more disciplined approach to access and oversight. Access rights to systems and interfaces must be designed and reviewed with greater precision. Overly broad privileges should be avoided, and access should distinguish clearly between:

  • Reading data
  • Creating or changing data
  • Approving decisions
  • Triggering business commitments
  • Administering rules, users or configurations

The development, publication and use of AI-enabled capabilities must follow an agreed operating model that defines who may create, configure, share and use them, and under what conditions. Compliance with this model must be actively monitored.

As AI agents and digital workers become part of normal operations, organisations need explicit controls over what these capabilities are allowed to do and how they are allowed to behave. Unlike traditional automation, AI-assisted capabilities can interpret situations and initiate actions dynamically, which increases the importance of clear behavioural boundaries.

These boundaries must be enforced both around the AI-enabled capability and within the core transactional systems it uses. Core systems need strict rules that define valid and acceptable use, including limits that reflect the organisation’s ability to manage business risk. For example, an online sales process may define allowed product combinations, discount limits, order quantity thresholds and approval requirements. This ensures that an AI-enabled capability cannot create commitments that exceed agreed risk thresholds, even if it misinterprets input or context.

AI use that relies on organisational data should be channelled through controlled mechanisms that enforce these boundaries consistently. Rather than allowing unrestricted access, controls must define which data can be used, for what purpose and under what conditions. Activity must be traceable, and behaviour observable, so that unexpected or undesirable actions can be detected and addressed early.

Together, clearly defined system rules and controlled AI use ensure that AI-enabled work remains predictable, accountable and aligned with business intent as autonomy and scale increase. Data flows and access management are no longer only technical concerns about moving data and assigning user rights. They are core management practices for maintaining control in an environment where data is reused widely and actions can be initiated without direct human intervention.

Clear data flows, precise access design and disciplined oversight ensure that data remains protected, accountable and fit for purpose while still supporting efficient and scalable use. As AI agents and digital workers become part of operational work, this control becomes essential for maintaining trust, traceability and business accountability.