Pre-filtering vectors by tenant, permission and attributes — where access control lives in RAG.
01
01
Understand the problem
metadata-filteringmulti-tenancysecurityrag
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
Server-derived filters in the retrieval call
async function retrieveForUser(query: string, session: Session, k = 8) {
const qVec = await embed(query);
return vectors.search(qVec, {
limit: k,
filter: {
tenant_id: session.tenantId, // from the session, NEVER from input
acl: { any_of: session.groups },
status: "published",
},
});
}
// deleting a doc / revoking access must also remove or reflag its chunks05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.