Amazon Quick 与 Amazon Bedrock 重新思考 RAG 的访问控制
Rethinking access control for RAG with Amazon Quick and Amazon Bedrock
AWS 为 Amazon Quick 和 Amazon Bedrock Knowledge Bases 引入实时 ACL 强制执行,在查询时直接向权威数据源(如 Google Drive、SharePoint)核验权限。
Enterprise organizations are adopting Retrieval Augmented Generation (RAG) to unlock insights from company knowledge sources like Microsoft SharePoint, Google Drive, and Atlassian Confluence. However, these knowledge sources contain sensitive information governed by complex permission structures. Making sure that AI-generated answers respect those permissions is one of the hardest challenges in enterprise AI.
In this post, we explore how Amazon Quick and Amazon Bedrock Knowledge Bases solve this challenge through real-time access control list (ACL) enforcement, verifying permissions directly with authoritative sources at query time.
The business problem
Consider this scenario: A SharePoint site owner creates a knowledge base for their organization. Team members across multiple departments use an AI assistant to get answers from this knowledge base. The critical requirement is that each team member must only receive AI-generated insights from documents they’re authorized to access.
This is a universal enterprise challenge. Organizations want to democratize access to AI-powered insights without compromising their existing security posture. A single unauthorized document surfaced in an AI response could expose confidential strategy documents, unreleased financial data, or sensitive HR information.
Why existing approaches fall short
A common approach to RAG access control uses a replicate-and-filter approach to enforce document-level permissions. Here’s how it typically works:
- A data source connector (for example, SharePoint connector) pulls ACLs as part of a periodic sync job.
- The ACLs are replicated from the data source and stored as attributes in an index.
- At query time, the AI system maps the logged-in user to the stored ACL attributes and filters results accordingly.
While this approach seems reasonable on the surface, it has three fundamental weaknesses.
Problem 1: The AI system isn’t the source of truth
In this model, the AI system takes sole responsibility for enforcement without being the authoritative source of permissions. This requires data connectors to accurately replicate complex, source-specific ACL logic across various data sources. Each data source has its own unique permission models. Mapping inheritance hierarchies, group memberships, conditional access policies, and deny rules across dozens of connectors is an error-prone undertaking.
Problem 2: Stale permissions create security gaps
In general, data connectors support pull-based syncs that run on demand or on a customer-defined schedule. The ACLs in these AI solutions are a snapshot in time from when the last sync ran. Some solutions use event-based updates, but this doesn’t work universally. For example, a data source like Confluence doesn’t emit an event when group membership changes. Between syncs, a user who had their access revoked might still receive AI answers from documents they should no longer see.
Problem 3: Evolving data source capabilities
Data sources regularly change or introduce new mechanisms to control access to content. A new permission feature in SharePoint or a change to the Google Drive sharing model could create gaps in the ACL mapping logic. This can expose content until the connector is updated.
How AWS solves this: Real-time ACL enforcement
To address these challenges, we implemented real-time ACL checks as an additional layer of security on top of existing pre-retrieval ACL filtering for Amazon Quick and Amazon Bedrock Knowledge Bases. This makes sure the system enforces the most current access controls by checking permissions directly with the authoritative source at query time. This avoids relying on potentially stale or incorrectly mapped ACL data.
Architecture overview
The following diagram illustrates our hybrid approach that delivers both semantic search performance and real-time security capabilities.
Figure 1: Real-time ACL enforcement architecture for Amazon Quick and Amazon Bedrock Knowledge Bases, combining pre-retrieval filtering (Stage 1) with real-time verification against authoritative sources (Stage 2)
How it works: A Google Drive example
When a user submits a query to an Amazon Quick agent that uses a Google Drive knowledge base, the system enforces access controls in two stages:
Stage 1: Pre-retrieval filtering
Amazon Quick performs a semantic search against the vector index to find the most relevant document passages. The system applies access control lists that are already stored in the index. This produces a preliminary set of candidate documents. This stage is necessary because real-time API calls for every document in the index would be too costly at scale.
Stage 2: Real-time verification
Amazon Quick verifies the candidate documents in real time by calling the Google Drive APIs. It uses the service account credential that the administrator provided to generate user-specific access tokens through impersonation. Google Drive maintains the source of truth for access control lists associated with each document. Documents the user is not authorized to access are excluded from the retrieved result set. Only the verified and authorized document passages are passed to the large language model (LLM) as context. The model uses this knowledge to generate a response.
This two-stage approach balances performance with security. It uses cached ACLs for efficiency while facilitating correctness through real-time checks. In addition to ACL enforcement, Amazon Bedrock provides responsible AI controls. These include Amazon Bedrock Guardrails for content filtering, grounding checks to reduce hallucinations, and configurable safety policies to help organizations deploy generative AI applications responsibly.
Why this matters for your organization
This approach delivers three key benefits:
- Always-current permissions – No more security gaps between sync cycles when you are using a RAG product. If an employee’s access is revoked, the change is reflected in AI responses within moments, not hours or days.
- Confidence to scale – Organizations can expand their knowledge base coverage knowing that real-time ACL checks verify permissions with the authoritative source for every query, regardless of data source.
- Reduced operational burden – You don’t need to worry about sync frequency.
What customers are saying about this
“When we set out to evaluate AI solutions for our organization, our security and compliance teams were clear about their top priority: ensuring that colleagues would only ever see information they’re authorized to access. It’s a fundamental requirement, but one that many platforms struggle to address in a meaningful way. Amazon Quick’s approach to real-time access control answered that question definitively and demonstrated a level of rigor that stood out throughout our evaluation. It gave our internal review board the confidence to move forward and set a strong foundation for how we think about AI governance going forward.”
— Jamahl Wiggins, Sr. Specialist – M365 Innovation, Mondelēz International
Mondelēz International has deployed Amazon Quick for their over 35,000 employees across four regions.
Conclusion
In this post, we talked about how Amazon Quick and Amazon Bedrock Knowledge Bases implement real-time ACL enforcement to solve a critical security challenge for enterprises. The dual-layer ACL architecture verifies permissions directly with authoritative sources at query time. This makes sure AI-generated answers include only content a user is authorized to access.
To get started, visit Amazon Quick and Amazon Bedrock Knowledge Bases.
About the authors
来源:AWS Machine Learning Blog · aws.amazon.com
