RAG can expose information users could not access directly if document permissions are ignored.
DATA GOVERNANCEAI GOVERNANCE & RISK
RAG Data Governance
RAG governance covers source approval, authorization, freshness, ingestion, deletion and lineage of knowledge used by the model.
Retriever filters enforce user entitlements before context is assembled.
Does RAG preserve the source system's access model?
REMEMBERRetrieval must not become a permission bypass.
No uploads · No company data · No account required