Rethinking access control for RAG with Amazon Quick and Amazon Bedrock
Document-level access control just became real-time in RAG. Amazon Quick and Bedrock Knowledge Bases now verify permissions at query time — not at indexing.

Why it matters
Enterprise RAG has a permission problem: knowledge bases ingest documents from SharePoint, Google Drive, Confluence with complex ACLs, but retrieval systems have historically enforced access after the fact or not at all. Amazon's real-time verification pattern closes that gap for practitioners building governed RAG systems.
The key facts
11 to knowDocument-level access controls enforced at query time, not indexing time
Permissions verified directly with authoritative sources (SharePoint, Google Drive, Confluence)
Amazon Quick and Amazon Bedrock Knowledge Bases are the enabling products
Solves enterprise RAG governance without re-indexing on permission changes
No pricing, quota, or GA/preview status disclosed in blog summary
Amazon Quick and Amazon Bedrock Knowledge Bases enforce document-level access controls in real time
Permissions verified directly with authoritative sources at query time (not at indexing)
Supports SharePoint, Google Drive, Confluence as knowledge sources
Addresses complex permission models in enterprise knowledge bases
No pricing, GA status, or consumption units disclosed
Operational mechanism: query-time authorization verification pattern
Go to the source
AWS Machine Learning Blogaws.amazon.com
Publisher excerpt: Enterprise RAG unlocks insights from knowledge sources like SharePoint, Google Drive, and Confluence, but those sources carry complex permissions. Learn how Amazon Quick and Amazon Bedrock Knowledge Bases enforce document-level access controls in real time, verifying permissions directly with…