Resources · 58
RAG: verify document access rights and isolation
Test retrieval, citations, caches and revocation so a document assistant respects each user’s permissions.
· 3 min
What this guide helps achieve
- Define boundaries
- Filter before exposure
- Separate caches
- Exercise revocation
Quick check
- Is a separate vector namespace enough?
- Should permissions be in the prompt?
- How can confidential documents be avoided in testing?
Step-by-step method
- 01
Define boundaries
Assign each document an owner, scope and access rule. OWASP describes cross-context leakage from misaligned vector-store permissions. Our proposed method also treats chunks and metadata as protected objects.
Deliverable: document, group and scope inventory.
- 02
Filter before exposure
Enforce authorisation in the retrieval service before a chunk reaches the model. Cover vector search, lexical search, graphs and direct downloads. A prompt instruction cannot replace server-side authorisation.
Deliverable: decision points and missing-identity behaviour.
- 03
Separate caches
Inventory retained search results, conversations, citations and answers. Check that reuse depends on the relevant access context. An index field naming a customer does not by itself prove isolation.
Deliverable: cache keys and separation scenarios.
- 04
Exercise revocation
Using non-sensitive test documents, remove access, delete a document and change a group. Replay a conversation opened before the change. Measure when chunks, links and retained answers become unavailable.
Deliverable: timestamped revocation evidence and gaps.
- 05
Keep negative tests
Ask the same question as an authorised user, another group and an unknown identity. Inspect filenames, excerpts, citations and logs. Replay after index or connector changes; a few passing cases only establish limited coverage.
Deliverable: test matrix and correction owner.
Reusable worksheet
Complete with your authorised observations. These fields are a working template, not observed results.
| Field | Information to record |
|---|---|
| Document / chunk | Owner and scope |
| Test identity | Allowed group, other group, missing identity |
| Access route | Retrieval, citation, file or cache |
| Result | Expected, observed, date and correction |
Worked example
Illustrative situation
Fictional example: a staff member changes teams but an earlier conversation still cites a withdrawn document.
Decision and expected evidence
The test follows retrieval and the conversation cache, then confirms refusal and absence of citations after correction.
Distinguish the mechanisms
| Mechanism | Purpose | Check or limitation |
|---|---|---|
| Retrieval filter | Limit retrieved chunks | Cover lexical routes and direct links too |
| Refusal prompt | Guide response behaviour | Do not delegate authorisation to it |
| Answer cache | Reuse a result | Check permission context before reuse |
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Observed leaks | Test data exposed outside scope | Block affected use and inspect cause |
| Revocation delay | Time until all tested routes refuse | Name caches still accessible |
| Route coverage | Connectors and retrieval modes exercised | Identify untested paths |
Common pitfalls
- Cover lexical routes and direct links too
- Do not delegate authorisation to it
- Check permission context before reuse
Frequently asked questions
Is a separate vector namespace enough?
It helps partition data, but caches, file links and tools must honour the same boundary.
Should permissions be in the prompt?
Useful context may reach the model; the service exposing data must enforce access decisions.
How can confidential documents be avoided in testing?
Create fictional sentinel documents for each group with distinct markers, then inspect answers and citations.
Official references
References consulted on 2 October 2026. The method and worksheet propose checks to adapt to your context; they do not constitute certification.






