
Retrieval Permissions Must Follow the User, Not the Service Account
Carry the effective user’s permissions through the entire RAG workflow. Enforce access before generation, preserve restrictions through caches and history, and test behavior when permissions change.