Skip to content

Access Control for AI Assistants and RAG

Making sure AI assistants only reveal information each user is allowed to see.

Editorial team 1 min read

An AI assistant connected to company data can become a way around access controls — unless permissions are enforced carefully.

The Risk

An employee asks the assistant about salaries, a confidential project or another customer's account. If the assistant searched everything, it may reveal information the employee couldn't open directly.

Enforce Permissions at Retrieval

  • Store access-control information with each indexed document.
  • Filter search results by the requesting user's permissions before the model sees them.
  • Keep permissions synchronised with source systems as they change.

Tools Act as the User

When assistants call tools and APIs, use the requesting user's credentials or delegated tokens, not a powerful shared service account.

Don't Rely on the Model

Instructions like "don't reveal confidential information" aren't access control. The model can't be trusted to enforce permissions.

Multi-Tenant Systems

Strictly separate customers' data in indexes, caches, logs and fine-tuned models.

Test

Create test users with different permissions and verify each sees only what they should, including through indirect questions.

Audit

Log which documents were retrieved for which user.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025