Day 6: Enterprise RAG Security: RBAC, Document-Level Access Control, and Prompt Injection
Production RAG Masterclass · Day 6 of 7 The most expensive RAG bug is not a wrong answer. It is a correct answer pulled from a document the user was never allowed to see. Figure 1. Permissions belong in retrieval — not only in the UI. Thesis Ingesting confidential enterprise documents without strict permission controls creates severe security leaks. Retrieval must respect identity. Document-Level Security (DLS) Every chunk carries ACL metadata: roles, groups, tenant IDs, classification. If the chunk does not know who may read it, the vector index will happily serve it to everyone. chunk.metadata = { "doc_id": "hr-comp-2025", "acl_roles": ["hr_admin", "comp_committee"], "tenant_id": "acme", "classification": "confidential" } Figure 2. Enforce ACLs on the retrieval path. Pre-filter vs post-trim Metadata pre-filtering (preferred) — push ACL filters into the vector q...