A technician asks the assistant a pricing question and gets back the margin on a job she was never supposed to see. Nobody meant for it to happen. The AI had broad access so that it could answer quickly, and it answered quickly.
That's the failure this article is about, and it's more likely to happen by accident than through an attack. The AI in your field operation should know your price list, your work orders and your technicians. It should also know nothing the person asking isn't allowed to see.
None of the uses of AI in where AI actually changes a field service operation is worth having if the AI is ungoverned, insecure or out of compliance. This is the article for the security reviewer, the CIO and the procurement team.
The one question
How do you make sure AI doesn't show employees data they shouldn't see? Ask one question of any vendor: whose permissions does the AI inherit?
If the answer is anything other than the caller's own, the AI can surface data the person asking isn't allowed to see. That's the whole test.
A separate permission model for AI is the wrong answer, even when it's built with the best intentions. It's a second set of rules, and a second set of rules drifts from the first. Someone changes a role in the HR system, and the AI's rules don't follow. Someone adds a new data source, and it's exposed before anyone thinks to restrict it.
The right answer is plain. Every request runs as the person who made it. It can't return anything they couldn't already access. Every action is logged. There's no separate AI permission structure to get wrong.
Governance is not only about reading
Most talk about AI security is about what the AI can read. In an operation that dispatches licensed technicians, it's just as important what it can do.
The platform should decline an assignment that a technician's credential doesn't support. That isn't a data-access rule. It's a constraint on the action. If the AI recommends a technician, it shouldn't recommend one whose credential doesn't cover the work. If a person tries to assign one manually, the board should say no. The detail is in why an expired certification should block dispatch automatically.
Governance that only covers reading leaves the more consequential half open.
The controls, plainly
Here's what governed AI looks like in practice, without the jargon.
Rules for who sees what. Role-based access, so the right assistants go to the right employees. Field technicians get field tools, dispatchers get operations tools and executives get analytics. No one sees what they shouldn't.
A record of what the AI was asked. Sensitive customer and employee data is flagged automatically, prompts are logged and unusual activity is surfaced to administrators before it becomes a problem.
One place to see where AI is used. Usage analytics show where AI is being adopted, which assistants produce value and where the gaps are, so AI ROI is measured and not assumed.
Your choice of model, with failover. The platform uses OpenAI, Anthropic or Google Gemini, with automatic failover, so one vendor's outage doesn't take your AI offline. Which provider you use is a setting, not a re-platform.
Your data stays yours. Your company's information never trains public models, and enterprise data stays inside your boundaries.
Ask a vendor for each of those five, and ask them to show it. A control that can only be described is not the same as one that can be inspected.
Certifications and deployment
Security review teams look for the same things, and it's easiest to list them.
Certifications. HITRUST CSF, SOC 2 Type II and ISO 27001, all on one unified system. FedRAMP ATO for U.S. public sector. HIPAA with a BAA. GDPR.
Deployment. SaaS, Private Cloud, Customer VPC or On-Premise, with a 99.9% uptime SLA.
Tenancy. Single-tenant architecture, so your data never co-mingles with another customer's.
Access and data controls. SSO and SAML, multi-factor authentication, field-level role-based access, geo-fencing, data loss prevention, audit logs and eDiscovery.
What security certifications should an AI workforce platform have? For a platform that holds employee records and customer data and puts AI in front of them, the three to look for together are HITRUST CSF, SOC 2 Type II and ISO 27001, held on the same system you'll be using and not across products acquired separately. Whether a vendor holds all three on one system is a factual question you can ask for evidence of. Confirm anything else your industry requires against your own compliance program.
A test you can run in an afternoon
Don't rely on a description. You can check the permission question yourself in a demo or a trial.
Create two users with very different roles: a field technician and an executive, say. Ask the assistant the same question as each of them, one that touches data only the executive should see, such as margins or another team's records. The technician should get a refusal or an answer built only from what they could already open. Then ask for the log of both requests and confirm that both are in it, attributed to the person who asked.
Next, ask what happens when the model provider is down. A vendor with failover can show you. Finally, ask for an assignment the technician's credentials don't support and see whether the platform declines it. Four checks, and none of them needs the vendor's help beyond a login.
Who owns AI governance on your side
A platform can enforce the rules, but someone has to decide them. In most field service companies, three people share the job. IT or security owns the permission model and the review of where data goes. The operations lead decides which assistants each role gets and what they're allowed to do. And a compliance or safety lead confirms that what the AI says about procedures matches what the company has approved.
When those three agree on the rules up front, the platform just applies them. When they haven't met, the platform will apply whatever it was configured with on the first day, which is usually too permissive. It's worth a meeting before anything goes live.
What happens to your data if you leave
Procurement readers look for this and are often disappointed. It's worth asking a vendor early.
Retention is configurable. Data subject requests under GDPR are supported. Records can be exported in an audit-ready format. Your records are yours, in a portable format, whenever you ask.
Questions for any AI vendor
A short list to bring to the next meeting:
- Whose permissions does the AI inherit?
- Where does a prompt go, and what is retained?
- Does anything train a public model?
- What happens when the model provider is down?
- Can I see every action the AI took?
- Can it decline an action, or only withhold information?
The first is question eight, and certifications are question ten, in the twelve-question evaluation guide. The rest are what to ask once a vendor has passed those.
The AI you can audit is the AI you can expand
Governance from day one is what lets the same platform put AI in front of the technician, the dispatcher and the controller without a separate review for each. The AI you can audit is the AI you can expand.
MangoApps is The AI Platform for the Frontline Workforce. Field Service Suite runs on the same platform as the rest of it, so AI in the field inherits the permissions and the audit trail of the platform already in your security review. If you're in utilities or telecom, this is the article to pair with the one on operations at scale. And if you're already running a field service tool, the migration article explains how this fits with it.
The Field Service Management guide also has the security and deployment summary in one place for your IT and procurement reviewers. You can also see the Field Service Suite itself.
Frequently asked questions
How does the AI know what it is not allowed to show someone?
It inherits your permission model. A request runs as the person making it and can't return anything they couldn't already access. There's no separate AI permission structure to keep in sync, so when a person's role changes, what the AI can show them changes too.
Does MangoApps AI train on our data or our customers' data?
No. Your company's information never trains public models, and enterprise data stays inside your boundaries. Every AI action is logged.
Which AI models does the platform use, and what if one is down?
The platform works with OpenAI, Anthropic and Google Gemini, with automatic failover, so one vendor's outage doesn't take your AI offline. Provider choice is a setting and not an architectural commitment.
What certifications does the platform hold for AI and data security?
HITRUST CSF, SOC 2 Type II and ISO 27001 on one unified system, plus a FedRAMP ATO for U.S. public sector, HIPAA with a BAA and GDPR. The platform can be deployed as SaaS, Private Cloud, Customer VPC or On-Premise.
Can we export our data if we leave?
Yes. Retention is configurable, GDPR data subject requests are supported, and records can be exported in an audit-ready, portable format whenever you ask.
The MangoApps Team
We're the product, research, and strategy team behind MangoApps — the unified frontline workforce management platform and employee communication and engagement suite trusted by organizations in healthcare, manufacturing, retail, hospitality, and the public sector to connect every employee — deskless or desk-based — to the people, tools, and information they need.
We write about enterprise AI for the workplace, internal communications, AI-powered intranets, workforce management, and the operating patterns behind highly engaged frontline teams. Our perspective is grounded in a decade of building for frontline-heavy industries and shipping AI agents, employee apps, and integrated HR workflows that real employees actually use.
For short-form takes, product news, and field notes from customer rollouts, follow Frontline Wire — our ongoing stream on AI, frontline work, and the modern digital workplace — or learn more about MangoApps.