AWS described a two-stage permissions check for RAG
According to AWS, Amazon Quick and Amazon Bedrock Knowledge Bases supplement document filtering based on stored permissions with a check directly with the source system at query time. The approach addresses the risk of outdated permissions between synchronizations.
AWS described how Amazon Quick and Amazon Bedrock Knowledge Bases check access permissions directly with source systems during RAG queries. According to the company, this check supplements existing filtering based on access control lists (ACL) before document retrieval. It is intended to address situations where the copy of permissions in the index becomes outdated or incorrectly reflects the rules of the source system, for example after a user's access has been revoked.
In the example described, Amazon Quick first retrieves relevant passages from the vector index and uses stored ACLs to select candidate documents. It then checks the user's current permissions through the Google Drive API. To do this, it uses service account credentials supplied by an administrator and impersonates the specific user. It excludes documents the user is not authorized to access and passes only verified passages to the language model as context. According to AWS, limiting these additional checks to candidate documents reduces costs compared with checking every document in the index.
Why it matters
An internal AI assistant may work with confidential documents whose access permissions change over time. Checking with the source system allows revoked permissions to be taken into account when preparing a response, even before the next index synchronization. The approach described thus offers a concrete way to address the security gap that arises when relying solely on copies of ACLs.
Relevant practical impact
What this means
For a business
Teams developing corporate RAG systems have a concrete architectural pattern for access control: supplement filtering in the index with checks on candidate documents at the source. The design also includes user identity management and additional API calls to source systems.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.