Recommended guardrail
Enforce the requesting user's permissions on every retrieval
Filter every vector search, search-index query, and tool lookup by the requesting user's and tenant's current permissions at query time, and re-check authorization on retrieved items before they enter the model's context. Detect retrieval calls with no user, group, or tenant filter on multi-user data. Caches of model responses are covered by guardrail.opint-scoped-response-cache; injected instructions in retrieved content by guardrail.agent-untrusted-content-isolation; the agent's own credential scope by guardrail.agent-least-privilege-tool-scope.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Standards consensus (3)
3 standards and frameworks · 2 graded incidents.
TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 3 standards and frameworks recommend it (IMDA Agentic AI MGF, NIST AML Taxonomy (AI 100-2e2025) — Agentic, OWASP LLM Top 10 (2025)). 2 graded incidents cited.
Standards and frameworks
- Every AI agent should have a distinct identity and its actions should be traceable to a supervising human (Singapore (SG); IMDA MGF for Agentic AI (v1.5) — Section 2.1.2, Agent identity and authorisation; cited)
- Untrusted external content should not flow into agent instructions or tool calls without mediation (OWASP LLM Top 10 (2025); OWASP Top 10 for LLM Applications (2025) — LLM01: Prompt Injection; cited)
- AI agents should mitigate indirect prompt injection and agent hijacking (NIST AI 100-2e2025) (NIST AML Taxonomy (AI 100-2e2025) — Agentic; NIST AI 100-2e2025, Secs. 3.4 (Indirect Prompt Injection Attacks and Mitigations), 3.5 (Security of Agents) and 3.6 (Benchmarks for AML Vulnerabilities); cited)
Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.
Graded incidents
- Asana MCP server exposed one organization's data to other organizations' users (2025-06; confirmed) The Register · evidence grade: press of record
- Copilot surfaced GitHub repositories after they were made private or deleted (2025-02; confirmed) Lasso Security (original researcher disclosure) · evidence grade: primary
The guard to add
Filter every vector, search, and tool lookup by the requester's tenant and groups at query time, and re-check read access on each retrieved item before it enters the prompt.
In the retrieval function that builds the model's context, the authenticated requester's tenant_id and group ids go into the query itself (filter=, namespace=, or the search service's security-trimming parameters), taken from the server-side session and never from the request body or model output. Each returned item is then re-checked with can_read(user, doc) against current permissions and dropped if it fails. Documents are indexed with ACL metadata (tenant_id, allowed_groups) that a sync job updates when permissions change. A single-tenant index, or one holding only content every permitted user may read, removes the need for per-query filters.
Example (LangChain vector store), before:
docs = vectorstore.similarity_search(question, k=5)
context = '\n\n'.join(d.page_content for d in docs)After:
docs = vectorstore.similarity_search(
question, k=5,
filter={'tenant_id': user.tenant_id}) # from the session, not the request body
docs = [d for d in docs if can_read(user, d.metadata['doc_id'])] # current ACL re-check
context = '\n\n'.join(d.page_content for d in docs)Control: Retrieval ignores the requesting user's permissions. Engineering guidance, not legal advice.
Why
An assistant that retrieves with the system's permissions rather than the requester's can turn any search into a disclosure. One operator told customers that a bug in its AI tool server could have exposed one organization's data to other organizations' users, and a security firm reports that an assistant could return repository content after the repositories were made private or deleted.
Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-retrieval-respects-requester-permissions