@hackproduct9: 🔍 Building AI search over your company wiki? Retrieval isn't the hard part. Permissions are. One real question — "what is our refund policy for enterprise?" — through the whole graph: 👤 AUTHENTICATE → Raja · eng · US ◇ ALLOWED? → yes 🌈 PLAN → one lookup, no multi-hop 📦 RETRIEVE TOP-K → 8 chunks ◇ ANY HE CAN SEE? → ACL filter cuts 8 down to 3 🌈 DRAFT + CITE → every claim tied to a chunk ◇ ALL CITED? → no. Retry once. ◇ ALL CITED? → yes ✅ ANSWER → 3 sentences, 2 links 📊 LOG → query · docs · verdict · cost 👀 That fifth node is the whole product. If your vector store doesn't carry per-document ACLs, and you don't filter by the ASKING user's permissions at query time, you didn't build search. You built a polite data-exfiltration tool. And filtering after retrieval isn't enough — the chunks already left the store. THE ACL FILTER IS THE PRODUCT. ⚠️ Two more: the retry is bounded (one pass, then a human at #ask-legal), and the citation gate means it says "I don't know" instead of inventing a policy. Count the nodes: 10. Only 2 are the model. 📸 Screenshot it. Save it before your next "can we just point an LLM at Confluence" meeting. Follow @hackproduct ⚡ . . #AIengineering #softwareengineering #RAG #enterprisesearch