Lesson 4 / 6 · 2 minute read
Bind retrieval to identity
Keep tenant identity outside model-selected search and tool arguments.
Enforce access to the current tenant’s records without breaking permitted retrieval.
- 01Authenticated tenant
- 02Query proposal
- 03Scoped retrieval
- 04Allowed records
- 05Answer
A filter is not authorization
A prompt telling the model to search only tenant A does not stop a query from requesting tenant B. Treat model-selected tenant identifiers as untrusted proposals. The retrieval service should derive the permitted tenant from the authenticated session.
Protect mixed requests
An attacker may ask for multiple records at once. Validate the entire request before returning data or applying a state change. Do not release an unauthorized record because another record in the batch was permitted.
Verify what was returned
Inspect record identifiers and data in the execution result. A response that says access was denied can still contain protected data. Include permitted retrieval as a control so that an empty result is not mistaken for a useful fix.
Check your understanding
Where should a search service get its permitted tenant?
Lesson completion is a self-recorded learning milestone on this device. Lab results are tracked separately.
Put it into practice
Make the boundary observable.
Start with an explicit action in the guided sandbox. Then explore the related mission’s execution mode and evidence.
Sources and further reading
These sources inform the concepts. Our examples and sandbox scenarios are original and synthetic.
OWASP LLM Top 10 — 2025 taxonomy ↗