Prompt
I need a vector store with metadata filtering and permission-aware retrieval
Latest observation
Oct 9, 2026
OpenAI APIWeb search: off
For metadata filtering + permission-aware retrieval, you want a vector store that can:
- store embeddings,
- attach structured metadata to each chunk/document,
- filter during search,
- enforce access control before results are returned.
Good options
1. PostgreSQL + pgvector
Best if you want a flexible, production-friendly setup.
Why it fits:
- Store vectors and metadata in the same DB
- Strong SQL filtering on metadata
- Easy to implement permission checks with joins / row-level security
- Good for “permission-aware retrieval” because access rules can be enforced in the database
Typical pattern:
documentstable withembedding,metadata,tenant_id,acl, etc.- Query with vector similarity +
WHEREclauses for allowed users/roles/projects
Pros
- Very strong filtering
- Easy ACL integration
- Familiar tooling
- Great for multi-tenant apps
Cons
- May need tuning for very large scale
2. Pinecone
Good managed vector database with metadata filtering.
Why it fits:
- Native metadata filters
- Scales well
- Simple API
Permission-aware retrieval
- Usually handled by encoding permissions into metadata and filtering by user/tenant/group
- Works well, but true complex ACL logic may need an app-side authorization layer
Pros
- Easy to use
- Fast
- Managed
Cons
- Less flexible than SQL for complex access rules
- Costs can rise with scale
3. Weaviate
Strong choice if you want richer filtering and schema support.
Why it fits:
- Metadata filtering is built in
- Supports structured schema
- Can model tenant/user fields for access filtering
Pros
- Powerful filtering
- Good developer experience
- Open source + managed options
Cons
- More operational complexity than Postgres
- Permission logic still usually app-defined
4. Qdrant
Very good for payload-based filtering and access conditions.
Why it fits:
- Fast vector search
- Rich payload filtering
- Good for metadata-driven retrieval
Permission-aware retrieval
- Store ACL-related fields in payload
- Filter by user groups/tenant/document visibility
Pros
- Fast and lightweight
- Strong filtering
- Good self-hosted option
Cons
- ACL logic is still mostly implemented via filtering design
Best approach for permission-aware retrieval
If permissions matter a lot, I’d recommend:
Postgres + pgvector
because you can:
- join against a permissions table,
- enforce access in SQL,
- use row-level security,
- avoid accidentally returning restricted items.
Example idea:
docs(id, embedding, metadata, tenant_id, visibility)doc_acl(doc_id, principal_type, principal_id, permission)- Query only docs where the current user has access
If you want the simplest managed solution
Choose:
- Pinecone if you want managed and scalable
- Qdrant if you want strong filtering and self-hosting
Recommendation by use case
- Strict enterprise permissions / multi-tenant app → Postgres + pgvector
- Managed SaaS with moderate ACL needs → Pinecone
- Open source + rich filtering → Qdrant or Weaviate
- Complex authorization logic → Postgres + pgvector
If you want, I can also give you:
- a comparison table,
- a recommended schema for ACL-based retrieval, or
- code examples for pgvector / Pinecone / Qdrant.