Access Control

March 6, 2026 · View on GitHub

🧭 Quick Return to Map

You are in a sub-page of Enterprise_Knowledge_Gov.
To reorient, go back here:

Think of this page as a desk within a ward.
If you need the full triage and all prescriptions, return to the Emergency Room lobby.

Guardrails and fix patterns to ensure that enterprise knowledge bases are segmented, secured, and retrievable without silent leaks. Use this page when failures look like “permissions bug” but root cause is schema drift, missing contracts, or evaluation blind spots.


When to use this page

  • Agents or LLMs retrieve snippets that a user role should not see.
  • Answers omit key passages even though data is present in the KB.
  • Knowledge base permissions collapse after re-index or migration.
  • Citation shows content from a restricted section without a trace.
  • External connectors expose more fields than expected.

Core acceptance targets

  • ΔS(question, retrieved) ≤ 0.45, with access role enforced.
  • Coverage ≥ 0.70 for the allowed scope, and <0.05 for disallowed scope.
  • λ remains convergent across three paraphrases and two seeds.
  • All snippets carry explicit role_scope, section_id, and source_hash.

Typical access problems → exact fix

SymptomLikely causeOpen this
Leaked restricted snippetMissing role tag or weak contractdata-contracts.md, retrieval-traceability.md
Role upgrade not reflectedCache or index skewbootstrap-ordering.md, deployment-deadlock.md
Over-blocking (user sees nothing)Schema mismatch or λ collapselogic-collapse.md
Citations missing access tagParser or contract driftocr-parsing-checklist.md, data-contracts.md

Fix in 60 seconds

  1. Measure ΔS for the retrieved vs allowed anchor.
  2. Check role_scope — ensure every snippet has an explicit scope.
  3. Rebuild contract — enforce schema: {snippet_id, section_id, role_scope, hash}.
  4. Re-index if role tags missing, with explicit normalization.
  5. Verify λ stability across paraphrases with access role locked.

Copy-paste schema (YAML)

snippet_id: "KB-12345"
section_id: "SEC-42"
role_scope: "finance_analyst"
source_hash: "sha256:..."
text: "..."

Every snippet must carry these fields, and retrieval probes must validate them before citation.


Escalate when

  • ΔS remains ≥ 0.60 even with contracts enforced.
  • Citations show cross-scope bleed.
  • Index mismatch recurs after two re-indexes.

Escalation path: rebuild with chunking-checklist.md and validate via eval_rag_precision_recall.md.


Explore More

LayerPageWhat it’s for
⭐ ProofWFGY Recognition MapExternal citations, integrations, and ecosystem proof
⚙️ EngineWFGY 1.0Original PDF tension engine and early logic sketch (legacy reference)
⚙️ EngineWFGY 2.0Production tension kernel for RAG and agent systems
⚙️ EngineWFGY 3.0TXT based Singularity tension engine (131 S class set)
🗺️ MapProblem Map 1.0Flagship 16 problem RAG failure taxonomy and fix map
🗺️ MapProblem Map 2.0Global Debug Card for RAG and agent pipeline diagnosis
🗺️ MapProblem Map 3.0Global AI troubleshooting atlas and failure pattern map
🧰 AppTXT OS.txt semantic OS with fast bootstrap
🧰 AppBlah Blah BlahAbstract and paradox Q&A built on TXT OS
🧰 AppBlur Blur BlurText to image generation with semantic control
🏡 OnboardingStarter VillageGuided entry point for new users

If this repository helped, starring it improves discovery so more builders can find the docs and tools.
GitHub Repo stars