TwinEthosRequest access

Recommended guardrail

Enforce the requesting user's permissions on every retrieval

Filter every vector search, search-index query, and tool lookup by the requesting user's and tenant's current permissions at query time, and re-check authorization on retrieved items before they enter the model's context. Detect retrieval calls with no user, group, or tenant filter on multi-user data. Caches of model responses are covered by guardrail.opint-scoped-response-cache; injected instructions in retrieved content by guardrail.agent-untrusted-content-isolation; the agent's own credential scope by guardrail.agent-least-privilege-tool-scope.

TwinEthos recommendation — not law

This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.

The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Evidence grade

Standards consensus (3)

3 standards and frameworks · 2 graded incidents.

TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 3 standards and frameworks recommend it (IMDA Agentic AI MGF, NIST AML Taxonomy (AI 100-2e2025) — Agentic, OWASP LLM Top 10 (2025)). 2 graded incidents cited.

Standards and frameworks

Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.

Graded incidents

  • Asana MCP server exposed one organization's data to other organizations' users (2025-06; confirmed) The Register · evidence grade: press of record
  • Copilot surfaced GitHub repositories after they were made private or deleted (2025-02; confirmed) Lasso Security (original researcher disclosure) · evidence grade: primary

The guard to add

Filter every vector, search, and tool lookup by the requester's tenant and groups at query time, and re-check read access on each retrieved item before it enters the prompt.

In the retrieval function that builds the model's context, the authenticated requester's tenant_id and group ids go into the query itself (filter=, namespace=, or the search service's security-trimming parameters), taken from the server-side session and never from the request body or model output. Each returned item is then re-checked with can_read(user, doc) against current permissions and dropped if it fails. Documents are indexed with ACL metadata (tenant_id, allowed_groups) that a sync job updates when permissions change. A single-tenant index, or one holding only content every permitted user may read, removes the need for per-query filters.

Example (LangChain vector store), before:

docs = vectorstore.similarity_search(question, k=5)
context = '\n\n'.join(d.page_content for d in docs)

After:

docs = vectorstore.similarity_search(
    question, k=5,
    filter={'tenant_id': user.tenant_id})   # from the session, not the request body
docs = [d for d in docs if can_read(user, d.metadata['doc_id'])]   # current ACL re-check
context = '\n\n'.join(d.page_content for d in docs)

Control: Retrieval ignores the requesting user's permissions. Engineering guidance, not legal advice.

Why

An assistant that retrieves with the system's permissions rather than the requester's can turn any search into a disclosure. One operator told customers that a bug in its AI tool server could have exposed one organization's data to other organizations' users, and a security firm reports that an assistant could return repository content after the repositories were made private or deleted.

Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-retrieval-respects-requester-permissions