Reuben AI

    Reuben AI guides

    AI agents on live fund data

    Connecting an assistant to a spreadsheet export is easy. Letting an agent act on live fund records is a different problem, because the records are the source of truth for LP reporting, valuations and audit. This page sets out what has to be true before that is safe, and what to ask a vendor before you wire anything in.

    Short answer

    What has to be true before an AI agent can work on live fund records?

    Before an AI agent touches live fund data, four things need to be settled: what the agent is allowed to read, what it is allowed to change, who authorised that scope, and whether every action it takes is recorded in a way an auditor can follow. A read-only assistant answering questions over exported files carries none of that risk and none of the benefit. An agent that can act needs a bounded, revocable, auditable mandate.

    Why chatting over an export is not the same thing

    The most common way teams use AI on fund data today is to export a report, drop it into a general assistant and ask questions. It works, and it is genuinely useful for a one off question. It also has three properties that make it unsuitable as an operating pattern.

    First, the export is a snapshot. The moment a valuation is revised or a capital call is issued, the answer is stale and nothing tells you so. Second, the assistant cannot write anything back, so the work product lives outside the system of record and has to be re-keyed. Third, there is no trail. If a number in a board pack came from an assistant reading a two week old export, nobody can reconstruct that later.

    An agent working on live records fixes all three, but only if the permission model is built for it rather than retrofitted.

    • A snapshot answer gives no signal when the underlying record changes.
    • Work produced outside the system of record has to be re-entered by hand.
    • Without a trail, the provenance of a number cannot be reconstructed at audit.

    A plugin over one system versus agents inside the platform

    Several incumbents in private markets have moved to expose their data to general assistants through plugins or connectors. Carta, for example, publicly promotes plugins that let an assistant query cap table and fund data (see carta.com for their own description). That pattern is a reasonable step, and it makes a single system easier to interrogate in plain language.

    The limit is scope, not quality. A plugin can only reach the system it belongs to. If the cap table lives in one platform, the CRM in another, diligence notes in a document store and valuations in a spreadsheet, an assistant with a plugin into one of them still cannot answer a question that spans the workflow, and still cannot act across it.

    Reuben AI takes the other approach. The deal record, the diligence trail, the valuation history, the portfolio data and the LP reporting layer sit on one platform, so an agent operates across the lifecycle rather than through a window into one part of it. That is a design choice with trade-offs: it asks a firm to consolidate rather than to bolt on.

    Mandate tokens: bounding what an agent may do

    A mandate token is the object that makes agent action reviewable. Instead of an agent inheriting a user's full permissions, it is issued a mandate: a specific scope, over specific records, for a specific purpose, granted by a named person, with an expiry.

    The practical effect is that every agent action can be traced back to a human decision to permit that class of action. A mandate can be narrowed, revoked or allowed to lapse without touching anyone's user account, and an agent operating outside its mandate is refused rather than trusted.

    This is the part most worth interrogating in any vendor conversation. The question is not whether the assistant is capable. It is what it is permitted to do, who permitted it, and how you would prove that in six months.

    • Scope: which records and which fields, read or write.
    • Purpose: the task the mandate exists to serve.
    • Grantor: the named person who authorised it.
    • Expiry and revocation: how the mandate ends.
    • Record: an immutable entry for every action taken under it.

    What an auditable agent action looks like

    If an agent drafts a quarterly narrative, the useful artefact is not the narrative. It is the narrative plus the set of records it drew on, the version of each record at the time, the mandate under which it acted and the human who accepted the output.

    That is the standard applied to any other material step in fund operations, and there is no reason for agent output to sit below it. It is also what makes the output defensible to an LP who asks where a figure came from.

    Questions to ask before you connect anything

    These are neutral questions. They apply to us as much as to anyone else, and a vendor that cannot answer them plainly is telling you something.

    • What data does the assistant read, and is it live or a copy?
    • Can it write back, and if so to which fields?
    • Who grants the permission, and how is it revoked?
    • Is every action recorded, and can that record be exported?
    • Is our data used to train a model, and can we decline?
    • Where is the data processed, and can that be restricted by region?
    • What happens to agent access when a user leaves the firm?
    • Can the output be traced back to the specific records that produced it?

    Common questions

    Is it safe to connect an AI assistant to live fund data?
    It can be, if access is scoped rather than inherited. The risks come from an agent holding a user's full permissions, from data leaving a controlled environment, and from actions that leave no trace. Scoped mandates with expiry, a full action record and a clear data processing position address all three. Ask for each of them explicitly.
    What is a mandate token?
    A mandate token is a bounded, revocable grant that defines what an AI agent may read or change, over which records, for what purpose, authorised by a named person and with an expiry. It replaces the pattern of an agent simply borrowing a user account's permissions, and it makes every agent action traceable to a human authorisation.
    How is this different from a plugin on a cap table platform?
    A plugin exposes one system to an assistant. It is useful for questions about that system. It cannot answer or act across sourcing, diligence, valuations, portfolio monitoring and LP reporting if those live elsewhere. A platform with agents built across the lifecycle can, at the cost of asking the firm to consolidate its data onto one platform.
    Can an AI agent produce something an auditor will accept?
    Auditors accept evidence, not assertions. Agent output is acceptable on the same terms as any other prepared work: the underlying records are identifiable, the version used is known, the authorisation is documented and a human accepted the output. If the tooling does not record those things, the output is harder to defend regardless of quality.
    Should an AI agent ever be allowed to change a fund record?
    For some classes of record, yes, with a narrow mandate and a review step. For others, no. Anything that feeds a capital account, a valuation of record or an LP statement should be proposed by an agent and committed by a person. The distinction to hold is between drafting and committing.

    Keep reading

    See how this works in practice

    Everything on this page is free to read, print and share. If you want to try the workflow itself, a guided trial workspace takes a few minutes to set up and no card is required.

    Cite this guide

    Free to quote and link. Please cite the permalink and the review date.

    Katriona Lee. "AI agents on live fund data." Reuben AI, 2026. Last reviewed 2026-07-29. https://www.goreuben.com/ai-agents-on-fund-data

    Publisher
    Reuben AI
    Author
    Katriona Lee
    Last reviewed
    2026-07-29