← Production & reliability

FREE AI FDE PRACTICE / PRODUCTION & RELIABILITY

Keep one customer's evidence out of another's answer

Advanced 10-min practiceEditorial review: 2026-10-05

YOUR SCENARIO

How would you approach this?

A shared RAG service stores documents for several customers. The model supplies a tenant_id argument when requesting a search, and a shared response cache keys only on the question text. Review the design.

This is an illustrative practice scenario. State any additional assumptions in your answer.

Make your case first.

Clarify the goal, identify the biggest uncertainty, outline an approach, and explain how you would test it. Spend about 10 minutes before opening the reference.

Your notes are not submitted or saved. Keep a copy before leaving this page.

Reveal reference approach Clarifying questions, decisions, and tradeoffs

Clarify before designing.

  • Where does the trusted user and tenant identity originate?
  • Do retrieval, source links, caches, logs, and tools all enforce the same access policy?

One defensible approach

  1. 01

    Move authority outside the model

    Derive identity from verified server context and enforce resource authorization at every data boundary. The model's requested tenant is not trusted authority. Use supported isolation or mandatory filters and ensure every retrieval path applies them.

  2. 02

    Scope derived artifacts

    Scope response caches to all correctness and access dimensions, including tenant, authorization state, and relevant data version, or avoid caching protected answers. Recheck citation access. Keep logs and traces from becoming a second unprotected data store.

  3. 03

    Test with conflicting fixtures

    Create two tenants with the same question but different private answers. Test direct access, semantic search, cache hits, revoked access, and malicious tool arguments. Confirm unauthorized records never enter the model context.

Explain the tradeoff

Physical isolation can simplify some boundaries at greater operating cost. Shared storage requires consistently enforced policy across every access path; a prompt instruction cannot substitute for it.

Common mistakes

  • Filtering unauthorized text only after the model has seen it.
  • Reusing an answer across users because their questions look similar.

KEEP THE CONVERSATION GOING

Try the follow-ups.

  1. How do permission changes affect cached answers?
  2. What if a background ingestion job forgets the tenant field?

Review your own answer.

Tick the points you covered. This is a reflection checklist, not an automated score or a hiring prediction.

Check the underlying concepts.

The scenario and reference approach were written for SaveMyToken. These sources support the technical concepts; they do not report this question being asked by an employer.

Qdrant: Filtering ↗Anthropic: Writing effective tools for agents ↗