RAG that respects access control
Permissions are the hard part of enterprise retrieval, and the part most designs defer. Four approaches, and why the index has to know who is asking.
Read insightinsights
Practical thinking on operational AI, architecture, integration, and platform engineering for organizations with real complexity and regulatory weight.
Filtered by AI governance · clear
Permissions are the hard part of enterprise retrieval, and the part most designs defer. Four approaches, and why the index has to know who is asking.
Read insightTwenty questions per system, grouped by what they imply for the architecture. Use it to find the gaps before someone else does.
Read insightThree Danish public authorities, three levels of competence, the same failure: none of them can produce a record of what an AI system did with a citizen's data. That record is no longer optional.
Read insightTwo things get called the same name, and only one of them puts an AI system into the customer's estate. Which one you mean decides who has to govern it.
Read insightWe built an in-house service that works the backlog of small, deferred defects while the office is empty, using computing capacity the organisation has already paid for. What makes it usable is not the model. It is the narrow scope, the team's own tests, and the review queue waiting at 08:00. The more interesting property is that the loop from report to released fix can close — which makes autonomy a decision about which changes you trust, rather than an engineering leap.
Read insightA trustworthy AI system should not merely retain an answer. It should let you return to that interaction and inspect the evidence, decisions, configuration, and controls behind it.
Read insightA directory of markdown files with YAML frontmatter, published by Google Cloud as an open specification. What OKF requires, what its trust fields record, and which of your problems it leaves untouched.
Read insightOne internal interface between your applications and whichever model serves them. What belongs in that layer, and the point at which not having one starts to cost you.
Read insightMost organizations buying or building on AI are deployers rather than providers. That distinction decides which obligations land on you, and most of them are architectural.
Read insightThe term covers four separable properties, and vendors tend to sell the cheapest one. Which of them you actually need depends on what you are protecting against.
Read insightA working demo is not a working system. The difference between AI that ships and AI that stalls is operational integration, not model quality.
Read insightNewsletter
A short email when we publish something worth your time. Architecture, integration, and operational AI in regulated organizations. No cadence promises, no forwarding your address.