Ömer CoskunIT Services

Why permissions belong in front of the model, not in the prompt

Published

The short answer

Is it enough to tell an AI assistant in its prompt not to reveal confidential content?

No. An instruction in the prompt is a request to the language model, not a rule: what the model has read, it can repeat. Only a fixed, verifiable rule outside the model is reliable, one that decides before the search which documents a request can reach at all.

Everything in one index, a request in the prompt

An AI assistant should never know more than the person asking it. That sounds obvious. Yet the first knowledge search in many companies looks like this: every document goes into one shared index, and the prompt carries a line such as “Do not reveal confidential content”.

The model then sees the board minutes, the salary list and the price list alike. It is merely asked to keep quiet about some of them.

Three reasons the request is not enough

  1. A language model can be talked into things. Cleverly worded questions, or instructions hidden inside a document, can make it repeat what it has read. These attacks are called prompt injection; the OWASP GenAI Security Project ranks them first in its list of the top risks for applications built on language models, with the disclosure of sensitive information second.
  2. Summaries inherit the confidentiality of their sources. Whoever sees the summary of the board minutes has, in substance, seen the minutes, even if the document itself was never shown.
  3. When it matters, you need to prove who saw what. An instruction in the prompt leaves no record of which documents the model has read.

The alternative: a fixed rule in front of the model

What is reliable is a decision taken before the model sees anything. A fixed decision function checks identity, role, department and tenant for every request and determines which sources are searched at all. The others are never searched, not merely hidden.

Every hit is checked against the rule once more before it is handed to the model: a pre-filter in the search, a re-check of every candidate. When in doubt, the rule refuses. This can be built with proven means, for example row-level security in PostgreSQL, a policy engine such as Open Policy Agent and an interface following the OpenID Foundation's AuthZEN draft.

It also matters whose permissions count. An agent searching on behalf of a person may only work with knowledge that both the person and the agent are allowed to see.

Derived knowledge needs permissions too

An assistant constantly produces new material: summaries, entries in its memory, handovers to other agents. Classic access control decides who may open a document. It does not decide who may see what is made from it.

The rule for this is simple: derived material inherits the classification of its sources and never becomes a source of authority itself. A summary is as confidential as the most confidential document it was made from.

Every decision on record

Every decision of the rule is logged: who asked, which sources were allowed and which were blocked. Kept as a chain with Merkle proofs following RFC 9162, the log can later be checked to show that no entry was changed or removed after the fact.

So when it matters, you can prove which request reached which documents, instead of having to trust the behaviour of a model.

What this means for your project

Permissions first, then the code. The project starts with a written permission concept: who may see which sources, and which permissions are taken over from your existing systems. Only then is the search built.

I have written the approach up as a draft standard: AKAC, Agent Knowledge Access Control. It describes what AI agents in a company may know, derive, store and pass on.

Sources and evidence

  1. AKAC: Agent Knowledge Access Control, public overview
  2. OWASP GenAI Security Project: Top 10 risks for applications built on language models (2025)
  3. PostgreSQL documentation: Row Security Policies
  4. Open Policy Agent
  5. OpenID Foundation: AuthZEN Working Group
  6. RFC 9162: Certificate Transparency Version 2.0
  7. Work index: AKAC, specification and reference gateway(own evidence)

Knowledge search with cited sources: cite or declineThe principle on the home page

Planning something along these lines? Briefly describe your project and you will get an honest assessment.

More articles

All articles