Compare AIFind AIAI NewsAI How-To
About Us
PrivacyTermsFAQContactContact
AIB Inc.Company info
© 2026 AIB Inc.

AWS Adds Real-Time Permission Checks to RAG

AWS Adds Real-Time Permission Checks to RAG

AWS ML Blog·Thursday, October 8, 2026
  • •Amazon Quick and Bedrock Knowledge Bases verify document permissions against source systems at query time.
  • •Two-stage filtering combines indexed ACLs with live Google Drive API checks before passages reach the language model.
  • •Mondelēz International has deployed Amazon Quick for more than 35,000 employees across four regions.
  • •Amazon Quick and Bedrock Knowledge Bases verify document permissions against source systems at query time.
  • •Two-stage filtering combines indexed ACLs with live Google Drive API checks before passages reach the language model.
  • •Mondelēz International has deployed Amazon Quick for more than 35,000 employees across four regions.
  • •Amazon Quick and Bedrock Knowledge Bases verify document permissions against source systems at query time.
  • •Two-stage filtering combines indexed ACLs with live Google Drive API checks before passages reach the language model.
  • •Mondelēz International has deployed Amazon Quick for more than 35,000 employees across four regions.
  • •Amazon Quick and Bedrock Knowledge Bases verify document permissions against source systems at query time.
  • •Two-stage filtering combines indexed ACLs with live Google Drive API checks before passages reach the language model.
  • •Mondelēz International has deployed Amazon Quick for more than 35,000 employees across four regions.

Amazon Quick and Amazon Bedrock Knowledge Bases use real-time access control list (ACL) checks to make retrieval-augmented generation (RAG) answers respect each user’s document permissions. AWS says the checks run against authoritative sources, including Google Drive, at query time, alongside existing filtering before retrieval. The approach addresses the risk that an AI assistant could surface confidential strategy documents, unreleased financial data or sensitive human resources information to someone without permission.

A common alternative copies source permissions into an index during scheduled or on-demand connector syncs, then filters search results using the stored ACLs. AWS identifies three weaknesses: the AI system may misrepresent source-specific rules such as inherited permissions, group memberships, conditional access policies and deny rules; copied permissions can become stale between syncs; and changes to systems such as SharePoint or Google Drive can outpace connector updates. AWS notes that Confluence, for example, does not emit an event when group membership changes, so a revoked user might retain access through answers until permissions sync again.

In AWS’s two-stage design, Amazon Quick first searches a vector index for relevant passages and filters candidates using stored ACLs. It then checks each candidate against the source in real time. For a Google Drive knowledge base, Quick calls Google Drive APIs using an administrator-provided service account credential to generate user-specific access tokens through impersonation. Google Drive remains the permission authority, and documents the user cannot access are removed before authorized passages are sent to the large language model as context. Checking every indexed document through live API calls would be too costly at scale, AWS says, so the first stage narrows the candidates.

AWS says this combination uses cached permissions for efficiency and live checks for current access decisions. If an employee’s access is revoked, the change should appear in AI responses within moments rather than hours or days. The company also says organizations can expand knowledge-base coverage with source-side checks on every query and avoid managing sync frequency. Amazon Bedrock offers additional controls, including Guardrails for content filtering, grounding checks to reduce hallucinations and configurable safety policies.

Mondelēz International says its security and compliance teams prioritized limiting colleagues to information they are authorized to see, and that Amazon Quick’s real-time access control gave its internal review board confidence to proceed. The company has deployed Amazon Quick for more than 35,000 employees across four regions. AWS identifies Jamahl Wiggins, senior specialist for M365 Innovation at Mondelēz International, as the source of the customer statement.

Amazon Quick and Amazon Bedrock Knowledge Bases use real-time access control list (ACL) checks to make retrieval-augmented generation (RAG) answers respect each user’s document permissions. AWS says the checks run against authoritative sources, including Google Drive, at query time, alongside existing filtering before retrieval. The approach addresses the risk that an AI assistant could surface confidential strategy documents, unreleased financial data or sensitive human resources information to someone without permission.

A common alternative copies source permissions into an index during scheduled or on-demand connector syncs, then filters search results using the stored ACLs. AWS identifies three weaknesses: the AI system may misrepresent source-specific rules such as inherited permissions, group memberships, conditional access policies and deny rules; copied permissions can become stale between syncs; and changes to systems such as SharePoint or Google Drive can outpace connector updates. AWS notes that Confluence, for example, does not emit an event when group membership changes, so a revoked user might retain access through answers until permissions sync again.

In AWS’s two-stage design, Amazon Quick first searches a vector index for relevant passages and filters candidates using stored ACLs. It then checks each candidate against the source in real time. For a Google Drive knowledge base, Quick calls Google Drive APIs using an administrator-provided service account credential to generate user-specific access tokens through impersonation. Google Drive remains the permission authority, and documents the user cannot access are removed before authorized passages are sent to the large language model as context. Checking every indexed document through live API calls would be too costly at scale, AWS says, so the first stage narrows the candidates.

AWS says this combination uses cached permissions for efficiency and live checks for current access decisions. If an employee’s access is revoked, the change should appear in AI responses within moments rather than hours or days. The company also says organizations can expand knowledge-base coverage with source-side checks on every query and avoid managing sync frequency. Amazon Bedrock offers additional controls, including Guardrails for content filtering, grounding checks to reduce hallucinations and configurable safety policies.

Mondelēz International says its security and compliance teams prioritized limiting colleagues to information they are authorized to see, and that Amazon Quick’s real-time access control gave its internal review board confidence to proceed. The company has deployed Amazon Quick for more than 35,000 employees across four regions. AWS identifies Jamahl Wiggins, senior specialist for M365 Innovation at Mondelēz International, as the source of the customer statement.

Read original (English)·Oct 7, 2026
Infra#amazon quick#amazon bedrock#retrieval augmented generation#access control list#rag#google drive#real time permissions#enterprise security