Permission-aware ingestion
Each document and chunk keeps its source permissions. Files with no matching rule are not indexed.
Connect generative AI to your documents and keep existing access rules.
A reference implementation of retrieval-augmented generation (RAG) for enterprise content. Document permissions carry through to the search index, so people only get answers from content they can already see. Every answer cites its sources and every request is logged. We adapt it to your document stores, identity provider, and chosen models.
Download the PDFAn assistant that answers from your content and respects who can see what.
The problem it solves, what is included, how it works, the technical components, and how we adapt it with you.
Your download has started.
We also emailed the link to . It stays valid for 7 days.
Download didn't start? Get the PDF
Want to see how it would fit your data? Talk to us.
Connect a model to your document stores and it can answer from the salary file or the board pack for anyone who asks. Hidden instructions inside documents can also steer what it says.
The Secure RAG Starter carries document permissions through to the search index, so people only get answers from content they can already see.
Four parts, each adapted to your data, platforms, and controls. What we adapt for you is yours to keep.
Each document and chunk keeps its source permissions. Files with no matching rule are not indexed.
Every answer cites the source documents it came from.
Every request logged, with daily request and cost limits.
SharePoint Online and OneDrive through Microsoft Graph, and Confluence Cloud, with their permissions.
Every document gets allowed and denied groups or users, read from the source system.
A file that matches no rule is not indexed at all.
Splitting a document never widens who can see it.
Content a user cannot read is never scored or returned.
The assistant re-checks every result and raises an alert if any fails.
A denied group overrides an allowed one, whichever groups a person belongs to.
Vendor-neutral Python and configuration, Azure first, with tests included from the start.
Bob works in engineering. Alice works in HR. Both ask for the salary range for band L4.
The rest of the supplier FAQ stays searchable. Every request is logged, and any failed permission re-check raises an alert.
SharePoint, OneDrive, Confluence, or a loader for your other stores, with real permissions.
Your identity groups mapped to principals from the signed-in user's token.
Your model deployment, with prices set so cost limits mean something.
A test set from your content, with one permission test per restricted area.
You keep the ingestion, connectors, index schema, and assistant code, running under your own identities.
We state the limits up front, and we recommend tools based on fit. We do not resell platforms.
Get the 10-page PDF to share with your team, or tell us the decision you want to improve and we will tell you whether the Secure RAG Starter fits.