Make Authorization a Retrieval Boundary
An AI search feature should retrieve documents under the signed-in customer's current permissions before any content reaches the model. A prompt asking the model to respect privacy cannot repair unrestricted retrieval. Once another organisation's document has entered the model context, output redaction is only a secondary containment measure.
Define the user, active organisation, permitted documents and allowed action at the server boundary. The practical output below is a proposed design and test matrix for a hypothetical multi-organisation document service. It is not evidence that a particular deployment has passed isolation tests.
The main acceptance condition is concrete: an ordinary customer must never cause unauthorized document text, snippets, filenames, citations or cached answers to be returned through the retrieval flow.
Verify Identity and Current Entitlement
Validate the request's authenticated identity using the application's trusted authentication path. Treat the active organisation selected in the interface as a request to enter that context, not proof of membership. Resolve the allowed organisation and record scope from server-owned membership and document permission data.
JWT claims can identify a session, but membership information embedded in an older token can remain stale. Supabase documents this limitation and warns against using user-editable metadata for authorization. For prompt permission changes, check current server-owned state on the protected request. Supabase JWT authorization guidance
Do not let the browser supply an arbitrary vector-store ID, tenant filter or document allowlist. A user should not be able to search organisation B by changing a field in a request payload. Bind scope to the verified identity and approved organisation before constructing the retrieval call.
If a user's membership is removed during a long-running request, define whether the server checks again before delivering the answer. For sensitive documents, a proposed policy is to revalidate the permission version at delivery and discard an answer built under a withdrawn grant.
Distinguish Database Policies From Remote Search
RLS can enforce row boundaries on the database queries to which it applies. It does not automatically govern a copy of those documents in an external vector store. A service credential, privileged view or server integration can also have a broader execution context than the ordinary user's database request. Inspect the actual paths and roles. Supabase RLS role and view boundaries
Maintain a server-owned mapping from each indexed file to its document ID, organisation, version and permission classification. Index metadata must come from trusted records, not an uploaded filename or customer-supplied tag alone. A metadata error can put a correctly filtered request into the wrong permission group.
OpenAI File Search searches files in supplied vector stores and supports metadata filters. The server must choose the permitted stores and filters for the request; the feature does not establish your application's membership or document ACL by itself. OpenAI File Search
Choose a design that enforces the required scope before generation. A dedicated store per approved boundary may be appropriate in one product. Another may use trusted metadata filtering with explicit document authorization. Verify how ingestion, search, model tools and updates preserve the boundary. Do not assume a numeric “Viewer < Editor < Admin” scale captures project restrictions or record-specific grants.
Authorize Candidates Before Model Context
For an application-managed retrieval pipeline, search within the permitted boundary, map candidate identifiers back to current document records, authorize each candidate and only then load its text for generation. Drop an unauthorized candidate rather than merely hiding its citation after the model has already read it.
For a hosted model-driven file-search tool, configure the permitted stores and server-derived filters before the tool runs. If the provider's filtering cannot represent your current document ACL, use a different boundary or an application-managed retrieval step. A later database check cannot retroactively remove unauthorized text already supplied to the hosted tool.
Fail closed when identity, mapping, permission state or index scope cannot be verified. Distinguish “no permitted results” from an operational search error internally, while keeping public errors free of unrelated tenant names and document details.
Use an explicit output contract: answer only from authorized sources, return a bounded fallback when evidence is insufficient, and include only citation identifiers drawn from the authorized context. These are quality and containment rules, not the authorization mechanism itself.
Protect Citations, Downloads and Conversation State
Check every displayed citation against the authorized source mapping. A document title, filename, page count or snippet can be sensitive even when the complete file is not shown. Citation links should reach a server endpoint that rechecks current permission before returning a document.
A valid direct signed URL is a bearer credential, so a server check made when minting it is not a fresh check on every later download. Supabase Storage signing is separate from Auth JWT keys; logout or Auth key rotation does not revoke those links. Supabase private downloads Warmed responses can also outlive the token's expiry under Smart CDN. Supabase signed URL caching
Separate conversations, retrieval caches and answer caches by verified organisation and relevant permission context. When a user changes organisations, do not reuse another organisation's previous context. Revalidate source access before serving a cached answer whose underlying permissions may have changed.
Deleting a document from the primary database does not automatically delete its vector-store copy, cached snippet or conversation history. Define the propagation and retention workflow for each copy, and withhold newly unauthorized content while asynchronous cleanup completes.
Review Provider Data Handling Explicitly
Do not describe a request as ephemeral merely because the application discards its local prompt variable. Provider retention depends on the endpoint, stored objects and the organisation's applicable controls. OpenAI's data-controls documentation distinguishes these behaviors; inspect the exact configuration and object lifecycle before making a retention promise. OpenAI data controls
Minimize the text sent to the model to what the authorized task needs. Keep request logs useful without duplicating entire private documents, full prompts, signed query strings or access tokens in general analytics. A correlation ID, permission version and permitted document IDs can support investigation without routinely copying the source content again.
Filled Hypothetical Retrieval Design
Suppose DocuServe serves organisations A and B. User A may read public-to-A project notes, but not A's restricted finance file and not any B file. These labels are proposed fixture permissions.
| Stage | Proposed server decision | Evidence |
|---|---|---|
| Identity | Verified user A session | Authentication result |
| Active organisation | A membership is current | Server membership version |
| Allowed documents | A project notes only | Document ACL evaluation |
| Search scope | Server chooses allowed store/filter | Redacted retrieval request |
| Candidate check | Reject stale or mismapped document IDs | Authorization results |
| Model context | Only permitted notes and source IDs | Controlled test context |
| Citation delivery | Citation ID resolves through current permission | Citation route allow/deny tests |
| Cache | Scope includes organisation and permission version | Cross-user/cache test |
| Logging | Correlation ID and bounded event metadata | Log field review |
OWASP recommends permission checks on every request and least privilege. Apply that to retrieval, model tools, citation downloads, exports and cache reads. The identity check at login is only the beginning of this path. OWASP authorization guidance
Practical Isolation-Test Matrix
Use unique harmless markers in each fixture document so tests can identify a leak without real customer data. Record the exact index version and model/tool configuration. Expected results below are proposed acceptance criteria.
| Test | Expected result |
|---|---|
| A searches an allowed A project note | Useful answer and permitted citation |
| A asks about a known B marker | No B text, title, snippet or citation |
| A asks about restricted A finance file | No restricted finance content despite same organisation |
| A substitutes B's organisation or store ID | Request scope rejected or safely overridden by server |
| Document is indexed with wrong tenant metadata | Ingestion check or current candidate ACL prevents exposure |
| Membership removed while old JWT remains valid | New retrieval denied by current state |
| Permission removed during generation | Delivery follows the documented revalidation policy |
| A switches to B context without B membership | Denied; earlier context cannot be reused |
| Cached answer's source permission withdrawn | Cache cannot bypass current source authorization |
| Citation points to unauthorized document ID | No protected metadata or bytes returned |
| Document text instructs tool to search another tenant | Tool boundary prevents expansion |
| Privileged worker or integration runs retrieval | Same approved request scope enforced outside RLS |
A no-results response for every query is not a successful permission-aware feature. Retain the positive allowed-document test as well as the denied cases. Distinguish absence of authorization from absence of relevant search results.
Test direct vector-search calls, hosted file-search tools and alternate API routes used by the product. A correct database policy test alone does not validate a remote search integration.
Repair Permission Failures Outside the Model
If unauthorized content is retrieved or delivered, stop the affected retrieval path and preserve restricted diagnostic evidence. Inspect identity binding, current membership, store selection, trusted metadata, candidate authorization, caches and citation endpoints.
Repair the enforcing ACL boundary and remove or quarantine mismapped index entries. Reconcile copied content and repeat the full isolation matrix with positive controls. Rotate credentials when credential compromise is involved; rotation alone does not fix a wrong filter or unauthorized cache.
Prompt changes, output filters and fine-tuning can improve response behavior, but they are not repairs for a data permission failure. The corrected server and retrieval boundaries must prevent the unauthorized content from reaching the model in the first place.
Assign owners for indexing permission changes, cleanup propagation and denied-request monitoring. Record source and permission versions with test evidence so later changes can be reviewed against the same contract.
Frequently asked questions
How can I ensure AI models do not hallucinate restricted content?
Enforce authorization before retrieval content reaches the model, and validate citation IDs against the allowed context. Prompt rules and redaction are secondary controls; they cannot guarantee that a model will never speculate or repair an ACL failure.
What if a user’s permissions change while they have an active session?
Check current server-owned permission state on protected requests and define revalidation before delivering long-running answers. An old valid JWT can retain stale membership claims; client refresh alone is insufficient.
Are signed URLs sufficient for document security?
A signed URL grants bearer access under separate token and cache lifetimes. Authorizing its creation does not recheck later downloads. Use a tested authenticated delivery path when current per-user revocation is required.
How do I test row-level security policies effectively?
Create test users with different organisation IDs and roles, then verify that queries only return permitted data. Use automated integration tests against your database.
If your business needs help implementing permission-aware AI retrieval features, or you want to ensure your SaaS platform enforces strict access controls, get in touch with our expert team at Symaxx via our SaaS development service route.
For more on SaaS development best practices, visit our guides on SaaS development. To understand the trade-offs between CMS and custom platforms, read our CMS vs custom development guide. Learn about ongoing costs in website maintenance costs. Finally, understand user experience flows in our user journey glossary entry.

