AI architectureOn access & evidence

Who is allowed to know the answer?

The question stays the same.
The permitted evidence changes.

“What should I tell the customer about this renewal?” A support colleague and an account owner type the same question. Both can read the general renewal policy. Only the account owner can read the account-specific agreement. A useful assistant has to preserve that difference all the way into its answer.

A citation does not make an answer safe to share. If the assistant read a restricted agreement and then removed the link, the information has already crossed the boundary. The decision about what it may read has to happen earlier.

The answer starts before the model sees a document

The application should establish who is asking and what they can access before retrieving evidence. That identity comes from the authenticated session. It does not come from a sentence in the prompt that says the user is an account owner. The retrieval service then uses the permitted scope when it calls the source system or queries the database.

There are several ways to enforce this. An API may evaluate access as the user. A policy service may authorize individual records. A database may apply row security. The mechanism matters less than whether it holds when the model asks for something outside the user’s scope.

PostgreSQL’s row-security documentation illustrates why configuration deserves attention. Table owners normally bypass row policies, and so do superusers and roles with the BYPASSRLS attribute. A carefully written policy can offer little protection if the application connects using the wrong role. Test with the identity the running service uses.

In the small example below, the support colleague receives the general procedure. The account owner receives that procedure plus the permitted account detail. The documents are fictional.

Illustrative example

One question. Two readers.

Switch the reader or withdraw a source and watch which parts of the answer survive.

Choose who is asking

What should I tell the customer about this renewal?

Answer for the support colleague

Check the current agreement before confirming terms. The account owner should review any commercial proposal.

What still needs checking

Ask the account owner to confirm the account-specific terms. The general procedure does not establish them.

Only the general procedure supports this answer.
Evidence the assistant may read
General policy · current version

Renewal procedure

Before discussing a renewal, check the current agreement. The account owner reviews any proposed commercial terms before they are shared with the customer.

Available to both readers

Account-specific content stays outside this reader’s evidence set.

These are fictional documents.

Follow the citation

Give every citation a specific job

An answer can contain several kinds of statements. One sentence may describe the general process. Another may state something about this account. Put a source beside the statement it supports so the reader can see the difference. A bibliography at the bottom is a much slower way to check an operational answer.

A retrieved passage needs to keep its source identity and version. Otherwise, the assistant can quote a previous agreement while sounding as though it describes the current one. Text that matches the question is not necessarily the evidence with authority over the answer. The application should use known rules about current versions instead of asking the model to guess.

Now choose the account owner and withdraw the account agreement in the illustration. The general procedure is still available. The account-specific answer is no longer supported, so that part disappears and the assistant says what must be checked. There is no need to turn one missing source into either a confident guess or a completely useless response.

Opening the citation is another access check. So is loading conversation history or serving a cached answer. A response generated while someone had permission should not become an unrestricted copy after that permission changes. Decide how revoked access affects every place an answer is kept, including conversation history, caches and exports, rather than protecting only the search endpoint.

Test the boundary

A document cannot grant itself more access

The assistant will encounter instructions inside documents. Some belong to the business process; others may try to redirect the assistant itself. Retrieved text should remain material to analyze. It should not be able to change the user’s identity, expand the set of available records, or authorize a tool action.

A practical test is to place an instruction in an otherwise ordinary test document asking for another account’s agreement. Check both the response and the tool calls. A refusal in the final answer is insufficient evidence if the assistant retrieved the restricted material first. The backend must enforce the boundary even when the prompt is persuasive.

Then test the complete session. Ask a follow-up, open the citation, change the permission, and repeat the request. Use two ordinary accounts with different access instead of performing every check as an administrator. Include source outages so a technical failure is not confused with an empty search result.

Finally, separate knowing from deciding. An answer can help a colleague prepare a conversation without authorizing a commercial change. Show the evidence and proposed wording to the responsible person. Let them decide what to tell the customer, with the source and its limits still in view.

Further reading

All blog postsExplore Applied AI and agentsTalk about your project

Keep reading

Another angle on the work.

AI delivery · 4 min read

The demo worked. Then the source went offline.

Follow one ordinary request through the less ordinary work of making an AI assistant ready for production.

Search engineering · 4 min read

The answer can only be as good as the search

Work through a small document collection to see how keywords, hard constraints, and missing evidence shape an AI answer.