Pre-filtering vectors by tenant, permission and attributes — where access control lives in RAG.
Skip to solutionKEEP THE
mediumAI Engineering
How do you scope retrieval with metadata filtering and multi-tenancy?
323 views
01
Understand the problem
metadata-filteringmulti-tenancysecurityrag
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Nudge consolestandby
Stuck? Beam a request up — the console returns a conceptual nudge that guides your logic without spoiling the implementation.
03
Study the solution
Store metadata (tenant ID, ACLs, document type, date) alongside each vector and apply filters as part of the ANN query (pre-filtering), so users can only ever retrieve chunks they are authorized to see. This is the correct place for access control in RAG — enforcing it in the prompt ('do not reveal other tenants data')
Solution ready — 2 min read
Classified // press E to declassify
04
Read the code
Server-derived filters in the retrieval call
async function retrieveForUser(query: string, session: Session, k = 8) {
const qVec = await embed(query);
return vectors.search(qVec, {
limit: k,
filter: {
tenant_id: session.tenantId, // from the session, NEVER from input
acl: { any_of: session.groups },
status: "published",
},
});
}
// deleting a doc / revoking access must also remove or reflag its chunks05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.
Transmission complete // awaiting log
KEEP THE
STREAK ALIVE.
Dossier 47 of 80 decoded in the AI Engineering track. One more won't hurt.