See the system
Build an explicit authorization boundary around managed search and verify the full path to the answer.
Understand the managed search lifecycle
Databricks documentation now uses AI Search for the capability formerly called Vector Search. Keep both names in your vocabulary, and verify current SDK/API syntax rather than renaming imports mechanically. Source tables, index configuration, embeddings, and synchronization form a connected lifecycle.
Choose an index approach based on the documented update model, query needs, and environment support. Record cloud, region, permissions, and feature state. A local search implementation teaches retrieval logic but is not a substitute for managed-platform evidence.
Establish identity and entitlements
Authentication identifies the caller; authorization determines what that caller may access. The application must derive entitlements from a trusted identity source, not from a department field supplied in a chat message.
Decide whether access is enforced through a documented platform mechanism, an application filter, separated indexes, or a combination. Verify the actual behavior of the chosen configuration. Do not assume source-table row policies automatically apply identically to every index query path.
Filter before context reaches the model
A forbidden document must not enter retrieval results consumed by the model. Asking the model to “ignore restricted content” is too late. Enforce filtering in trusted code or a verified platform boundary, and validate results against the user’s permissions.
Access can leak through snippets, titles, citations, caches, and traces even if the final answer omits the body. Include these surfaces in testing. A cache shared across users needs keys and invalidation consistent with the access policy.
Keep the index consistent with the corpus
A document update may change text, metadata, and access. A permission revocation must affect future requests within the application’s defined guarantee. Index lag and caches can complicate that guarantee.
Track source and index versions or freshness signals where supported. Test synchronization failures, document removal, and entitlement changes. Decide whether to fail closed for sensitive queries when freshness or authorization cannot be established.
Produce evidence of the boundary
A convincing access test includes allowed and denied users, direct API calls, malformed filters, unknown identities, stale permissions, and untrusted document instructions. Test both retrieval output and what reaches the generator.
Preserve safe traces showing the policy decision without copying forbidden content into a broadly accessible log. Report the tested scope honestly: passing a finite suite is useful evidence, not a universal proof that leaks are impossible.
Worked scenario
Alice belongs to Support A and Bob to Support B. Both ask “What is the escalation allowance?” Each department has a different restricted policy. The answer must derive identity from the session, return only authorized evidence, and avoid cross-user cached responses. Changing the prompt cannot grant Alice access to B.
Practical assignment
- Use the local lab’s Alice/Bob fixtures to practice the boundary.
- Record the additional managed-platform setup required.
- Create an entitlement matrix and negative cases.
- Test retrieval, citations, caches, and traces.
- Simulate a revocation and define index/cache handling.
- Mark managed checks unverified until run in the real workspace.
What to submit
Submit the artifacts named above, a short explanation of your decisions, and evidence of the checks you performed. Distinguish measured results from estimates and designs from executed integrations.
| Review dimension | Submission evidence |
|---|---|
| Correctness | Show the expected behavior and a meaningful counterexample. |
| Reproducibility | State setup, inputs, versions, and what was actually executed. |
| Delivery judgment | Explain the client impact, alternative, and unresolved assumption. |
| Operational boundary | Identify permissions, failure behavior, and any resource cleanup. |
Knowledge check
Answer guide
- Before restricted content reaches the model. The retrieval/context boundary must enforce policy independently of model behavior.
- No, use trusted identity information. User-supplied claims are not an identity authority.
- Results, context, citations, caches, and logs. Sensitive information can leak through multiple surfaces.
References & next step
Platform examples are environment-dependent. Start with the official documentation in the reference library and verify the exact cloud, region, privileges, and versions you use.
Open the official reference library
Editorial edition: 5 October 2026. The local reference lab is executed locally; this course does not claim a live Databricks deployment.