Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

How One Filter and a Narrower AI Assistant Fixed a Major Azure OpenAI Retrieval Issue

Egiziago Cioffi, CEO of SynSphere Italia, faced a critical problem with his Azure OpenAI assistant: it returned sensitive SharePoint content to users without proper permission checks. Even though the assistant passed all quality evaluations, a low-privilege user could still access data they shouldn’t see because the retrieval pipeline used the indexer’s permissions, not the requester’s. This issue is common in many AI retrieval deployments where native document-level access controls are missing or incomplete. Azure AI Search now includes built-in ACL trimming for document access, but it isn’t universally applied, especially in custom pipelines like Cioffi’s. To fix this, Cioffi implemented a simple but effective query-time filter that checks user permissions before retrieval, narrowing the assistant’s scope without the need for a new identity platform. This filter allowed the assistant to continue resolving about 60% of inbound emails while enforcing proper access boundaries. The case highlights a blind spot in AI assistant evaluations—they usually check for correct answers but not whether responses respect access controls. The lesson is clear: AI retrieval systems must verify whose permissions they enforce at query time to prevent unauthorized data exposure. A straightforward two-account test comparing access levels can reveal this critical gap quickly and should become a standard security check before deploying any AI assistant.

Venturebeat
Venturebeat