Home / RAG / Permissions
RAG guide

Permissions: the right answers for the right people

A RAG system that ignores document permissions is a data leak with a chat interface. Anyone could ask about salaries, board decisions or customer data and get an answer. Permissions must be enforced before the model sees anything.

Check atSearch time
Source of truthOriginal document permissions
SyncWith every change
Test withReal user roles

How it works

  1. When a document is indexed, its access list (users and groups) is stored with every passage.
  2. When someone asks a question, the system knows who they are from company sign-in.
  3. Search only returns passages that person is allowed to read. Everything else is filtered out before the model is involved.
  4. When permissions change at the source, the index is updated too.

Try it in the interactive demo: ask the salary question as an employee and as an HR manager.

Mistakes to avoid

  • Filtering after the model answers. Too late: the model has already seen the restricted text.
  • One shared index for everything, with no access lists. Simple to build, unsafe to run.
  • Forgetting removed access. When someone leaves a team, their access to its documents must disappear from the index too.
  • Not testing with real roles. Test with accounts from different departments before go-live.

Want answers from your own documents?

Tell us where the documents live, who should be able to ask, and ten questions people ask today. We will come back with a plain view of what it takes to answer them well, and safely.