Access control in retrieval
Ensuring RAG only retrieves documents the **current user is allowed to see**.
What it is
Ensuring RAG only retrieves documents the current user is allowed to see.
Why it matters
Vector search without ACLs is a data leak machine.
How it works (plain)
Filter by permissions at retrieve time (preferred) or in a secure index per tenant. Never “retrieve then hope the model won’t quote.”
Try it
Design ACL fields for docs: tenant, group, user. Write one query test that must return empty for the wrong user.
Myths
- ⚠️ Myth: Prompting “don’t reveal secrets” is an access control.
- ✓ Reality: Enforce in the retriever/tool layer.
Sources
- Course 09 RAG; Course 19 security/privacy
- OWASP LLM Top 10: https://owasp.org/www-project-top-10-for-large-language-model-applications/ ↗
