01A policy document does not stop a query.
Access rules usually live in a spreadsheet, a wiki page and somebody's memory. The database reads none of them, so the rule holds right up until a report, a dashboard or an agent asks for something nobody thought to check.
02You set it. The platform enforces it.
Where Parable runs, what it is allowed to store, and who can see which rows are your decisions. They are applied by the platform itself — in the database, under keys you hold, inside a boundary you choose — so the rule holds even when the thing asking forgets to.
03The same rules, whoever is asking.
A person in the app, a scheduled report and an agent over MCP all hit the same tables under the same roles, so an agent cannot see what the person running it could not. The controls behind SOC 2, ISO 27001 and GDPR are those same identity, encryption and deployment choices rather than a separate set of promises kept in a binder.