Enterprise RAG connects a language model to internal documents. Without careful access control, anyone who can ask a question can read anything indexed.
Enforce Permissions at Retrieval
Store access information (users, groups, roles) as metadata on each chunk and filter searches by the requesting user's permissions. Content the user can't access must never enter the prompt.
Keep Permissions in Sync
Source permissions change as people move teams and documents are reshared. Sync permission metadata regularly, and handle revoked access quickly.
Watch the Other Paths
- Caches: don't serve a cached answer generated for one user to another with different permissions.
- Logs: prompts and responses in logs may contain sensitive content; protect and limit them.
- Conversation memory: don't carry retrieved restricted content into shared contexts.
- Evaluation data: test sets built from real documents inherit their sensitivity.
Prompt Injection
Documents in the index could contain instructions designed to manipulate the model into revealing other content or taking actions. Treat retrieved text as untrusted data.
Test It
Include access-control tests: users asking about documents they shouldn't see must get nothing from them. Automate these tests.
Start Narrow
Begin with content that all users may see, then add permission-controlled sources once filtering is proven.