An AI assistant connected to company data can become a way around access controls — unless permissions are enforced carefully.
The Risk
An employee asks the assistant about salaries, a confidential project or another customer's account. If the assistant searched everything, it may reveal information the employee couldn't open directly.
Enforce Permissions at Retrieval
- Store access-control information with each indexed document.
- Filter search results by the requesting user's permissions before the model sees them.
- Keep permissions synchronised with source systems as they change.
Tools Act as the User
When assistants call tools and APIs, use the requesting user's credentials or delegated tokens, not a powerful shared service account.
Don't Rely on the Model
Instructions like "don't reveal confidential information" aren't access control. The model can't be trusted to enforce permissions.
Multi-Tenant Systems
Strictly separate customers' data in indexes, caches, logs and fine-tuned models.
Test
Create test users with different permissions and verify each sees only what they should, including through indirect questions.
Audit
Log which documents were retrieved for which user.