1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →
How do you implement permission-aware (ACL-aware) retrieval correctly?
30-second answerSay your answer out loud first, then reveal.

Approaches
| Approach | How | Pros | Cons |
|---|---|---|---|
| Pre-filter in engine (recommended) | ACL fields on chunks; engine filters during search | Secure, correct k | Needs filtered-ANN support; ACL fields must stay synced |
| Post-filter | Retrieve top-N, then check permissions per result | Simple; real-time permission check against source | May return fewer than k; wasteful; risk of leaks if buggy |
| Index per tenant / per group | Separate indexes | Strong isolation | Explodes with many groups; good for tenant-level isolation |
| Hybrid | Pre-filter by coarse ACL, then a real-time check for sensitive docs | Defence in depth | More complexity |
Hard parts
- Group explosion and nesting: users belong to hundreds of nested groups. Flatten them at sync time, cache them per user, and handle large group lists in filters.
- ACL change propagation: when someone loses access, results must stop showing within an SLA. Treat revocations as high priority.
- Inheritance: folder-level permissions inherited by files, plus page-level restrictions (Confluence).
- Derived data leakage: caches, summaries, and contextual enrichment generated from restricted docs must carry the same ACL. A semantic answer cache must be keyed by permission scope.
- Testing: automated tests with synthetic users verifying that they cannot retrieve restricted content, including through paraphrased queries.
Interview line. "Security filtering happens before the model sees anything. The LLM is not an access-control layer."
Related
You understood something today that you didn't yesterday.