Secure RAG
Secure RAG is the practice of making retrieval-augmented generation respect information boundaries throughout ingestion, retrieval and answer delivery. It combines document authorization, trusted identity handling and adversarial testing so that an assistant can use relevant evidence without exposing material its user is not allowed to read.
What it is
A retrieval system creates additional copies of source information: chunks, embeddings, metadata, cached results and generated answers. Secure RAG preserves the source permission model across those copies and applies authorization before material enters the model context. Authentication establishes who is asking; authorization establishes which records that identity may access. Retrieved text remains untrusted data even when access is legitimate, because a document can contain malicious instructions. Security therefore includes both controlling which evidence is retrieved and constraining what the application can do with it. Encryption alone does not provide these application-level boundaries.
What the work involves
A practitioner maps source permissions to indexed records, derives query filters from a trusted identity service and verifies that every retrieval path applies them. They decide how revocation propagates to chunks and caches, and separate tenant data where isolation requires it. Useful artifacts include a permission propagation diagram, denial tests and a policy for logging sensitive context. Tests should cover direct queries, citations, summaries and follow-up questions, because a restriction that works only in the first search can fail later in a conversation.
Illustrative example
An employee assistant searches both general policies and restricted compensation documents. A user asks why a colleague received a salary adjustment. The retriever excludes the restricted records before constructing context, while the assistant can still explain the public compensation policy. A regression test repeats the request through paraphrases and cached conversations, then removes a user's access and confirms that previously retrieved compensation chunks cannot reappear in a new answer.
Limits and common mistakes
A refusal instruction is not an access-control system, and hiding a citation does not remove information already supplied to the model. Permission metadata can become stale, shared caches can cross user boundaries and overly broad service accounts can defeat careful query filtering. A strong test checks what context and side effects were possible, not only whether the final response looked harmless. Secure retrieval also does not make the retrieved facts accurate.
Prerequisites
Permission-aware retrieval is a security layer ON TOP of a RAG pipeline — you must understand the pipeline to secure it
- mediumPrompt Injection Defense
Securing RAG involves defending against prompt injection attacks that attempt to bypass retrieval permission boundaries
Related skills
- → is subcategory of: Retrieval-Augmented Generation
Sources and further reading
- Microsoft Learn: document-level access control
Supports preserving document permissions and enforcing them at retrieval; the example is illustrative.
- OWASP: prompt injection
Supports direct and indirect prompt-injection threats and layered mitigations.
Last updated: 2026-10-10