Permission-Aware Knowledge Search
Multi-Tenant RAG & Authorization
Question
Scenario
A customer wants an internal assistant over millions of documents across Google Drive, Notion, and a ticketing system. Access differs by user, team, region, and customer account. Permissions can change within minutes, documents may be deleted, and every answer must cite evidence.
The prototype occasionally cites a document the current user cannot open.
Your task
Design a production architecture that prevents unauthorized disclosure. Cover ingestion and indexing, identity and permission propagation, retrieval-time authorization, permission changes and deletion, citations and audit evidence, evaluation, and the tradeoff between security, freshness, latency, and recall.
Answer
Design the architecture
Explain the decision in writing, draw the system, or use both.
Write your answer before opening the hints or solution.
0 words
Interviewer nudges3 prompts · Open
- 1.Filtering the final answer is too late if unauthorized text entered model context.
- 2.Consider document and chunk metadata, with the source system as authority.
- 3.Test cross-tenant and stale-permission leaks.
Strong answerReview after your attempt · Open
Strong answer outline
Preserve source IDs, tenant, ownership, ACL metadata, version, and deletion state for every chunk. At request time resolve the authenticated principal and enforce authorization before any chunk enters model context, using indexed ACL filters, live source checks, or both.
Consume permission and deletion events, define a maximum staleness window, and use online authorization for high-risk sources even when it costs latency. Citations must link only to resources the user can open and should record source version and retrieval evidence.
Evaluate relevance together with cross-tenant, revoked-access, deleted-document, inherited-group, and ambiguous-identity tests. Unauthorized disclosure is a release blocker; lower recall is the safer failure mode.
Reference diagram
Permission-aware retrieval path
Signed-in user
Identity + tenant
Authorization filter
Current permissions
Scoped retrieval
Only allowed documents
Answer + citations
Auditable evidence