TL;DR: Building a production-style RAG pipeline with multi-tenant permissions depends on matching retrieval to relationship-based access, not just adding embeddings and vector search, according to Authzed. The identity lesson is that authorization must travel with the data path or the LLM will surface context the user should never see.
Editorial analysis by NHI Mgmt Group, based on content published by Authzed: “Build a Multi-Tenant RAG with Fine-Grain Authorization using Motia and SpiceDB”.
Key questions
Q: What breaks when retrieval permissions are too broad in RAG?
A: Broad retrieval permissions collapse data separation.
Q: Why do embeddings not replace authorization in RAG pipelines?
A: Embeddings capture similarity, not entitlement.
Q: How do teams prevent tenant data leaks in multi-tenant RAG systems?
A: Carry tenant and ownership metadata from ingestion through chunking, indexing, and query-time retrieval.
Practitioner guidance
- Enforce permissions at retrieval time Check relationship-based access before chunks are returned to the LLM, not after the answer is generated.
- Preserve tenant metadata on derived chunks Attach farm, organisation, and user context to every embedding and chunk so access decisions can be re-evaluated downstream.
- Separate ranking from authorisation Use vector similarity to rank content, but require a permission check against the source object before any context is exposed.
Bottom line: RAG pipelines create an access problem as much as a model problem when retrieval is shared across tenants without permission checks.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Fine-grained retrieval authorization is now part of the data plane, not a wrapper around it. RAG systems do not fail only at prompt time. They fail when retrieval is allowed to cross tenancy boundaries before the LLM is even invoked, which means the authorisation model must sit on the retrieval path itself. For practitioners, this shifts authorization from an API concern to a core part of the knowledge access architecture.
A question worth separating out:
Q: What is the difference between semantic search and authorized retrieval?
A: Semantic search finds the most relevant text, while authorised retrieval finds the most relevant text the caller is permitted to access. In RAG, those are separate decisions, and only the second one protects multi-tenant data boundaries.
👉 Read our full editorial: Fine-grained authorization for RAG pipelines needs identity controls