
An instruction asking a model to keep companies separate does not enforce data isolation. Tenant and document permissions must restrict what the application retrieves before the model sees it. The same rule applies to cached answers and links to source documents.
A practical scenario
A shared assistant serving two property agencies may hold brochures with similar development names. A semantic match from the wrong agency can look highly relevant. Resolve the authenticated tenant and user on the server, apply permissions in the search query, and reject any source whose scope does not match.
Design the first version
Propagate access changes into the retrieval layer. Cache keys should include the relevant permission boundary and content version. Validate source downloads independently of the chat route. Background ingestion jobs need tenant checks too; isolation can fail during indexing even when the final search filter looks correct.
What to test and measure
Create adversarial tests with near-identical documents in different tenants. Ask direct questions about restricted records, revoke access mid-session, and retry an old citation URL. Record what evidence entered the model context. A successful isolation test demonstrates absence of unauthorized material throughout the flow.
Questions to resolve before commissioning
- Which source system owns the facts used in this workflow?
- Who reviews exceptions and corrects inaccurate output?
- What baseline and acceptance criteria will determine whether the pilot is useful?
- What should the user do when a source, tool, or device is unavailable?
Explore the implementation
This is a planning guide, not a report of measured client results. Examples are illustrative. Explore the related SyntaxLab demo to discuss the interaction, then use your own records and acceptance criteria for a production pilot. Discuss a scoped project or review our AI automation services.
Further reading
Read Microsoft guidance on evaluating RAG answers for technical background. Continue with Prompt Injection in Business AI: Protect Tools and Retrieved Content.