Resources · 58

RAG: verify document access rights and isolation

Test retrieval, citations, caches and revocation so a document assistant respects each user’s permissions.

· 3 min

Method diagram: Scopes → Authorisation → Caches → Revocation → Negative tests Method diagram · steps explained in the text

What this guide helps achieve

  • Define boundaries
  • Filter before exposure
  • Separate caches
  • Exercise revocation

Quick check

  • Is a separate vector namespace enough?
  • Should permissions be in the prompt?
  • How can confidential documents be avoided in testing?

Step-by-step method

  1. 01

    Define boundaries

    Assign each document an owner, scope and access rule. OWASP describes cross-context leakage from misaligned vector-store permissions. Our proposed method also treats chunks and metadata as protected objects.

    Deliverable: document, group and scope inventory.

  2. 02

    Filter before exposure

    Enforce authorisation in the retrieval service before a chunk reaches the model. Cover vector search, lexical search, graphs and direct downloads. A prompt instruction cannot replace server-side authorisation.

    Deliverable: decision points and missing-identity behaviour.

  3. 03

    Separate caches

    Inventory retained search results, conversations, citations and answers. Check that reuse depends on the relevant access context. An index field naming a customer does not by itself prove isolation.

    Deliverable: cache keys and separation scenarios.

  4. 04

    Exercise revocation

    Using non-sensitive test documents, remove access, delete a document and change a group. Replay a conversation opened before the change. Measure when chunks, links and retained answers become unavailable.

    Deliverable: timestamped revocation evidence and gaps.

  5. 05

    Keep negative tests

    Ask the same question as an authorised user, another group and an unknown identity. Inspect filenames, excerpts, citations and logs. Replay after index or connector changes; a few passing cases only establish limited coverage.

    Deliverable: test matrix and correction owner.

Reusable worksheet

Complete with your authorised observations. These fields are a working template, not observed results.

FieldInformation to record
Document / chunkOwner and scope
Test identityAllowed group, other group, missing identity
Access routeRetrieval, citation, file or cache
ResultExpected, observed, date and correction

Worked example

Illustrative situation

Fictional example: a staff member changes teams but an earlier conversation still cites a withdrawn document.

Decision and expected evidence

The test follows retrieval and the conversation cache, then confirms refusal and absence of citations after correction.

Distinguish the mechanisms

MechanismPurposeCheck or limitation
Retrieval filterLimit retrieved chunksCover lexical routes and direct links too
Refusal promptGuide response behaviourDo not delegate authorisation to it
Answer cacheReuse a resultCheck permission context before reuse

Management indicators

IndicatorWhat it measuresFirst action
Observed leaksTest data exposed outside scopeBlock affected use and inspect cause
Revocation delayTime until all tested routes refuseName caches still accessible
Route coverageConnectors and retrieval modes exercisedIdentify untested paths

Common pitfalls

  • Cover lexical routes and direct links too
  • Do not delegate authorisation to it
  • Check permission context before reuse

Frequently asked questions

Is a separate vector namespace enough?

It helps partition data, but caches, file links and tools must honour the same boundary.

Should permissions be in the prompt?

Useful context may reach the model; the service exposing data must enforce access decisions.

How can confidential documents be avoided in testing?

Create fictional sentinel documents for each group with distinct markers, then inspect answers and citations.

Official references

References consulted on 2 October 2026. The method and worksheet propose checks to adapt to your context; they do not constitute certification.