All articles
engineering notes · Practical business guide

Multi-Tenant RAG: Protect Business Documents Before Retrieval

By SyntaxLab · 2 min read

Design tenant and document permissions into retrieval queries, caches, citations, and evaluation so business knowledge stays within the intended audience.

Multi-Tenant RAG: Protect Business Documents Before Retrieval

An instruction asking a model to keep companies separate does not enforce data isolation. Tenant and document permissions must restrict what the application retrieves before the model sees it. The same rule applies to cached answers and links to source documents.

A practical scenario

A shared assistant serving two property agencies may hold brochures with similar development names. A semantic match from the wrong agency can look highly relevant. Resolve the authenticated tenant and user on the server, apply permissions in the search query, and reject any source whose scope does not match.

Design the first version

Propagate access changes into the retrieval layer. Cache keys should include the relevant permission boundary and content version. Validate source downloads independently of the chat route. Background ingestion jobs need tenant checks too; isolation can fail during indexing even when the final search filter looks correct.

What to test and measure

Create adversarial tests with near-identical documents in different tenants. Ask direct questions about restricted records, revoke access mid-session, and retry an old citation URL. Record what evidence entered the model context. A successful isolation test demonstrates absence of unauthorized material throughout the flow.

Questions to resolve before commissioning

  • Which source system owns the facts used in this workflow?
  • Who reviews exceptions and corrects inaccurate output?
  • What baseline and acceptance criteria will determine whether the pilot is useful?
  • What should the user do when a source, tool, or device is unavailable?

Explore the implementation

This is a planning guide, not a report of measured client results. Examples are illustrative. Explore the related SyntaxLab demo to discuss the interaction, then use your own records and acceptance criteria for a production pilot. Discuss a scoped project or review our AI automation services.

Further reading

Read Microsoft guidance on evaluating RAG answers for technical background. Continue with Prompt Injection in Business AI: Protect Tools and Retrieved Content.