Permission-aware retrieval
Permission-aware retrieval is retrieval that applies each user's existing access rights at query time, so an AI answer can only be built from sources that user was already allowed to open.
The risk it addresses is specific. If content is indexed into one shared store and permissions are applied loosely, an assistant can summarise a document a user could never open, and the leak arrives as fluent prose with no obvious source.
Doing it properly means permissions are enforced on the way out, not just on the way in, and they follow the source system. When someone loses access to a folder on Monday, answers built from that folder stop being available to them on Monday, without a re-index.
It also constrains what a correct answer looks like. Two people can ask an identical question and receive different answers, and that is the system working rather than failing.