Across state and local government, the number of AI tools employees can access has grown from a handful to dozens. Some are sanctioned for the whole organization. Others are appropriate for specific teams; legal, HR, finance, but not for everyone. Governing that reality requires more than a single on/off switch.

For most IT and compliance teams, AI access has been an all-or-nothing decision at the organizational level: either everyone can use a tool, or no one can. There's no straightforward way to grant tool access to specific individuals, mirror the identity groups already managed in Microsoft Entra, or enforce those decisions consistently across every AI interaction.

Darwin's User-Level Access Controls closes that gap. Admins can now control exactly which AI tools each user is allowed to access; manually per user, in bulk via Microsoft Entra group sync, and enforced through configurable Access Control rules that apply the policy across the entire organization.

Manage Access From Every Angle

User-Level Access Controls works from both sides of the access relationship. In Settings > Organization > Users, admins get a user-centric view, every user's Approved Tools column showing exactly which AI systems they can access. In the AI Navigator's Tool Drawer, they get the tool-centric view, an Access Management panel to add or remove authorized users for a specific tool and toggle "Authorized Users Only" to restrict access.

Whether the task is auditing a user's permissions or locking down a specific tool, the same authorization data is visible and editable from wherever the work starts.

Sync With the Identity Structure You Already Use

For agencies already managing identity through Microsoft Entra, User-Level Access Controls eliminates the double bookkeeping of maintaining a separate access policy. Map an Entra group to the AI tools that group should be able to use, run Sync Groups, and every user in that group is automatically authorized, no manual assignment, no drift between identity and tool access.

When groups change in Entra, Darwin follows. Access stays aligned with the identity structure your agency already relies on.

Enforcement Built Into Access Control

Authorization is only useful when it's enforced. User-Level Access Controls ties directly into Darwin's Access Control rules, Usage of Authorized AI System and Usage of Sandbox AI System, where admins choose how strict enforcement should be:

  • Allow all organization users
  • Allow only authorized users for selected tools
  • Allow only authorized users for all tools

The same policy defined in the user or tool view is enforced at the point of use, across every AI interaction Darwin governs.

Built for the Way IT and Compliance Teams Actually Work

Government and enterprise agencies are being asked to demonstrate that AI access is deliberate, documented, and defensible. Darwin's User-Level Access Controls gives IT and compliance teams the fine-grained control to do exactly that, with the same rigor and group structures they already use to manage identity.

Ready to see User-Level Access Controls in action? Book a demo or reach out to your Darwin AI contact to get a walkthrough.

Interested in Learning More?