Why it matters
Access control prevents customer apps from reading internal collections. Mistakes are data breaches with chat UI. Human folder ACLs do not translate cleanly to app access.
Mergers and integrations widen scope silently unless access reviews are routine.
Integrations sync new sources silently. Access reviews must include connector scopes, not only app configs. Widened OAuth scopes have leaked internal docs into customer indexes in real deployments.
Mergers combine employee populations before knowledge boundaries are redrawn. Access remediation is merger critical path work.
How it works
Maintain app-to-collection matrices with document states and regions. Enforce at query time with logged denials.
Penetration test public apps for internal content elicitation regularly.
Review access on new collections, apps, and ingestion connectors together.
Document break-glass takedowns with mandatory post-incident narrowing.
Map service accounts and automation tokens in access matrices alongside human-facing apps. Non-human principals cause quiet scope creep.
Run quarterly access certification with domain owners signing collection lists per app. Certification creates accountability rhythm.
Example
Nintendo access control blocks the customer chatbot from internal discount runbooks even when user questions sound like enterprise pricing queries. Sales copilot access includes those collections under separate policy.
Common mistakes
- 1Shared API keys across apps with different audiences
- 2Access rules documented but not enforced in index queries
- 3Forgotten legacy indexes still reachable after app migration
- 4Testing access only at launch
Your AI does not need more access. It needs the right access.
Set policies that control what each AI application can read, cite, and answer from.
See AI access policies