If agent-mode Genie answers may contain data outside the reviewing managerโs own RLS/CLS scope, does that mean potentially sensitive data outside the Genie space (that is viewable to Genie Space user) is being processed by underlying foundation model?
I am working on a use case where some sensitive data in the workspace must not leave UK South region (i.e. no cross-Geo processing) and Genie space data must be restricted to non-sensitive data only. However, the above implies a potential governance issue, where sensitive data from outside the Genie space could be processed alongside non-sensitive Genie space data to generate the response.
What can be done to ensure strict data governance and context separation, so that no sensitive data outside the Genie space is processed as part of Genie Space usage?