Translating each connected system's own permission model — SFDC sharing rules, SAP authorisation objects, ServiceNow ACLs — into one filterable model, then enforcing it consistently at query time regardless of which source a given field came from.