Rethinking access control for RAG with Amazon Quick and Amazon Bedrock
Enterprise RAG unlocks insights from knowledge sources like SharePoint, Google Drive, and Confluence, but those sources carry complex permissions. Learn how Amazon Quick and Amazon Bedrock Knowledge Bases enforce document-level access controls in real time, verifying permissions directly with authoritative sources at query time.
Enterprise organizations are increasingly utilizing Retrieval Augmented Generation (RAG) to extract insights from their company knowledge repositories like Microsoft SharePoint, Google Drive, and Atlassian Confluence. These repositories often contain sensitive data governed by intricate permission structures. Ensuring that AI-generated responses adhere to these permissions is one of the most significant challenges in enterprise AI.
Consider a scenario where a SharePoint site owner establishes a knowledge base for their organization. Multiple team members from various departments utilize an AI assistant to obtain answers from this knowledge base. The crucial requirement is that each user should only receive AI-generated insights from documents they are authorized to access. This common enterprise challenge demands a solution that democratizes access to AI-powered insights without jeopardizing existing security protocols.
Traditional RAG access control approaches typically employ a replicate-and-filter mechanism. This involves a data source connector (e.g., SharePoint connector) extracting ACLs through periodic sync jobs, replicating them as attributes within an index, and subsequently mapping user permissions during query time to filter results accordingly.
However, this method has three major flaws. Firstly, the AI system acts as the sole authority for enforcement rather than being the authoritative source of permissions. This necessitates data connectors to accurately mirror complex, source-specific ACL logic across diverse data sources, a task fraught with errors due to the varied permission models of each data source.
Secondly, these solutions employ pull-based syncs that generate a snapshot of ACLs at specific intervals, potentially leading to outdated information. For instance, a user who has had their access revoked might still receive AI responses from documents they should no longer view between syncs. Lastly, evolving data source capabilities, such as new permission features in SharePoint or changes in the Google Drive sharing model, could create gaps in the ACL mapping logic, potentially exposing sensitive information until the connector is updated.
To tackle these issues, AWS has implemented real-time ACL enforcement as an additional security layer for Amazon Quick and Amazon Bedrock Knowledge Bases. This approach ensures the system enforces the most current access controls by verifying permissions directly with the authoritative source at query time, thereby circumventing the reliance on potentially stale or inaccurately mapped ACL data.
The architecture consists of a hybrid approach that combines pre-retrieval filtering and real-time verification. During Stage 1, Amazon Quick performs a semantic search against the vector index to identify the most relevant document passages and applies pre-stored access control lists (ACLs) to generate a preliminary set of candidate documents.
This stage is necessary due to the prohibitive cost of real-time API calls for every document in the index. In Stage 2, Amazon Quick verifies the candidate documents in real-time by querying the Google Drive APIs using a service account credential provided by the administrator. These credentials generate user-specific access tokens through impersonation, allowing Google Drive to maintain the source of truth for ACLs associated with each document.
Any documents the user lacks authorization to access are subsequently excluded from the retrieved result set. Only the verified and authorized document passages are passed to the large language model (LLM) as context, which then generates the response.
In addition to ACL enforcement, Amazon Bedrock offers responsible AI controls, including Amazon Bedrock Guardrails for content filtering, grounding checks to minimize hallucinations, and customizable safety policies to facilitate organizations in deploying generative AI applications responsibly.
The benefits of this approach are manifold. It guarantees always-current permissions, eliminating security gaps that may arise between sync cycles in replicate-and-filter solutions. If an employee's access is revoked, the change is reflected in AI responses within mere moments, not hours, ensuring the integrity and security of sensitive information.
Written by urgent.news from AWS Machine Learning's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.