Skip to content
← Learning paths

Lesson 4 / 6 · 2 minute read

Bind retrieval to identity

Keep tenant identity outside model-selected search and tool arguments.

By the end

Enforce access to the current tenant’s records without breaking permitted retrieval.

Follow the boundary
  1. 01Authenticated tenant
  2. 02Query proposal
  3. 03Scoped retrieval
  4. 04Allowed records
  5. 05Answer

A filter is not authorization

A prompt telling the model to search only tenant A does not stop a query from requesting tenant B. Treat model-selected tenant identifiers as untrusted proposals. The retrieval service should derive the permitted tenant from the authenticated session.

Bind scope to identity in application code.

Protect mixed requests

An attacker may ask for multiple records at once. Validate the entire request before returning data or applying a state change. Do not release an unauthorized record because another record in the batch was permitted.

Evaluate each requested resource against the same server-owned authority.

Verify what was returned

Inspect record identifiers and data in the execution result. A response that says access was denied can still contain protected data. Include permitted retrieval as a control so that an empty result is not mistaken for a useful fix.

Inspect actual returned data and legitimate-task completion.

Check your understanding

Where should a search service get its permitted tenant?

Choose one answer

Lesson completion is a self-recorded learning milestone on this device. Lab results are tracked separately.

Put it into practice

Make the boundary observable.

Start with an explicit action in the guided sandbox. Then explore the related mission’s execution mode and evidence.

Sources and further reading

These sources inform the concepts. Our examples and sandbox scenarios are original and synthetic.

OWASP LLM Top 10 — 2025 taxonomy ↗