Rethinking access control for RAG with Amazon Quick and Amazon Bedrock
Amazon Web Services Amit Choudhary
AWS says Quick and Bedrock can check permissions live before an AI answer appears. That’s meant to stop stale access lists from leaking private docs.
Based on reporting by Amazon Web Services, Amit Choudhary — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Enterprises want AI to answer from SharePoint, Google Drive, and Confluence without turning security into a suggestion box. That’s the problem AWS is tackling in Amazon Quick and Amazon Bedrock Knowledge Bases: keep RAG useful, but make sure the model only sees what the user can actually see.
The usual method is to copy access control lists into an index during sync, then filter results later. AWS says that breaks down in three places. The AI system is not the source of truth, the copied permissions can go stale between syncs, and the connectors have to keep up every time a data source changes how permissions work.
So AWS is layering real-time checks on top of the usual pre-retrieval filtering. In the Google Drive example, Amazon Quick first does a semantic search against the vector index and narrows the field using ACL data already stored there. Then it verifies the candidate documents live by calling Google Drive APIs with user-specific access tokens created through impersonation using the service account credential the administrator provided.
Only the verified passages reach the large language model. That matters because it keeps the expensive live permission checks focused on a smaller set of documents, rather than trying to hit every item in the index. AWS also says Bedrock adds guardrails, grounding checks, and configurable safety policies on the responsible AI side.
Mondelēz International is already using Amazon Quick for more than 35,000 employees across four regions, according to the post. The company’s quote makes the pitch pretty clear: if security and compliance teams care first about who can see what, then live permission checks are the feature, not the footnote.
My take — AI-written commentary, not fact-checked reporting
This is the right call. Copying permissions into an index and hoping they stay correct is the kind of plan that looks tidy right up until someone sees a document they shouldn’t. The industry keeps selling “enterprise AI,” but enterprises mostly want enterprise permissioning with a chatbot on top.
Read more about this at: Amazon Web Services