Prompt
Do I need to filter vector search by tenant and permissions?
Latest observation
Oct 10, 2026
OpenAI APIWeb search: off
Yes — in a multi-tenant or permissioned system, you should always filter vector search by tenant and access permissions.
Why
Vector search can return semantically similar matches from anywhere in the index. Without filtering, you risk:
- Cross-tenant data leakage
- Unauthorized document retrieval
- Incorrect or noisy results
- Compliance/security violations
Best practice
Use metadata filters alongside vector similarity search, for example:
tenant_id = current_tenantaccess_level/acl/allowed_users/allowed_groups- any other domain-specific constraints
Typical pattern
- Narrow candidates with metadata filters
- Run vector similarity search within that restricted set
- Optionally rerank results
Important note
Permissions should be enforced at query time, not just at ingestion time. Even if you store separate indexes per tenant, still validate access control in the retrieval layer.
If you’re using RAG
This is especially important, because retrieved chunks may be shown to users or used to generate answers. A retrieval mistake can become a data exposure.
If you want, I can show you:
- a sample schema for tenant + ACL filtering,
- examples for Pinecone/Weaviate/Qdrant/FAISS,
- or a secure retrieval pattern for RAG.