The New Stack published an analysis arguing that access permissions must be considered when selecting enterprise data for AI. The author argues that permissions must be part of assembling context for a specific user, not a filter applied afterward.

In the author’s example, an employee moved from the finance team at 9:00 can still retrieve financial documents from the search index for 17 hours when syncing runs overnight. The author also says that he runs Modus, a company in this field.

Truto advises syncing source-system permissions to metadata in vector databases, stores for finding similar texts. OWASP advises fine-grained access controls and permission-aware vector and embedding stores.

Claim check:

  • The New Stack published an analysis arguing that access permissions must be considered when selecting enterprise data for AI. (confirmed by the publication itself: evidence; «Permissions belong in the assembly context»)
  • The author argues that permissions must be part of assembling context for a specific user, not a filter applied afterward. (confirmed by the publication itself: evidence; «Permissions are not a filter you apply to context after you have assembled it. They are a property of how context gets assembled for a particular identity»)
  • In the author’s example, an employee moved from the finance team at 9:00 can still retrieve financial documents from the search index for 17 hours when syncing runs overnight. (confirmed by the publication itself: evidence; «Someone moves off the finance team at 9 a.m. on a Monday. Your sync runs nightly at 2 a.m. For seventeen hours, that person can still pull finance documents out of your retrieval index»)
  • The author also says that he runs Modus, a company in this field. (confirmed by the publication itself: evidence; «I run a company, Modus, that builds in this lane, so weigh the argument accordingly.»)
  • Truto advises syncing source-system permissions to metadata in vector databases, stores for finding similar texts. (confirmed by the publication itself: evidence; «engineering teams must sync source-system ACLs into vector metadata»)
  • OWASP advises fine-grained access controls and permission-aware vector and embedding stores. (confirmed by the publication itself: evidence; «Implement fine-grained access controls and permission-aware vector and embedding stores.»)

Publications:

Primary sources:

score 68.5 · kind analysis · revision 1 · stories st-2utwmr