Skip to content
← All posts
Security30 Jun 2026·4 min read·Ava Sharma

Permission-aware retrieval is the boring feature that makes AI enterprise ready

Filtering results after the model has seen them is not access control. Here is how retrieval is scoped before anything reaches the context window.

Plenty of products bolt a chat box onto a knowledge base and call it done. The interesting question is what happens when a client account asks "what is blocking the release?" and the honest answer lives in an internal engineering channel.

Order of operations

Loop resolves the asker's role and project membership first, converts that into a SQL filter, and only then runs the search. A client account is restricted to sources marked shared — task progress and explicitly published documents. Internal chat and comments are never candidates, so they cannot appear in the context window and the model cannot leak what it was never given.

Citations are not decoration

Every answer numbers its sources and links back to them. If a claim has no citation it is a bug, not a stylistic choice — and because retrieval was already filtered, following a citation can never land somebody on a page they are not allowed to open.

Filtered, not just ranked

Retrieval matches on the words in your own tasks and documents, over the same permission-filtered rows — so a result is only ever as wide as your access, never wider. The failure mode is fewer results, never a leak.

See it on a real board

Demo accounts for every role, no card needed.

Create a workspace