UM-SA-001 · Revision 4.0AI feature: what it can read and do
Fernleaf’s assistant answers questions about a customer’s billing. We mapped what it can reach and tested whether a document could steer it.
Who it’s for
What we checked
What the assistant reads, which actions it can take, and whether an uploaded document or a message can change what it does.
What it can reach
- It reads
- The asking account’s invoices and the documents its users upload.
- It does
- Searches, summarises and drafts. Sending email is switched off for now.
What we found
- Search could return another customer’s documents (AI-01, High).
- Hidden text in an uploaded statement made it queue an email outside the company, with no one signing it off (AI-02, High).
In place now
- The send action is switched off until each send needs a person’s sign-off.
- The assistant runs under its own role, with no access to payment details.
Planned
- Search filtered by account, by Fernleaf’s developers from our pattern4 to 6 weeks
- A verified sign-off for each send, tied to the recipient and the report4 to 6 weeks
- Cloud monitoring: alerts on the assistant’s actions1 to 2 weeks
- Our retest of both fixes, one round includedAfter the fixes
Evidence
Every answer on this page points at an item in the evidence index on page 24: exports, policy files, restore logs.
Questions
Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.
Fictional sample. The company, systems and data are invented; no real client was assessed.