RAG that respects access control
Permissions are the hard part of enterprise retrieval, and the part most designs defer. Four approaches, and why the index has to know who is asking.
Read insightinsights
Practical thinking on operational AI, architecture, integration, and platform engineering for organizations with real complexity and regulatory weight.
Permissions are the hard part of enterprise retrieval, and the part most designs defer. Four approaches, and why the index has to know who is asking.
Read insightTwenty questions per system, grouped by what they imply for the architecture. Use it to find the gaps before someone else does.
Read insightThree Danish public authorities, three levels of competence, the same failure: none of them can produce a record of what an AI system did with a citizen's data. That record is no longer optional.
Read insightTwo things get called the same name, and only one of them puts an AI system into the customer's estate. Which one you mean decides who has to govern it.
Read insightWe built an in-house service that works the backlog of small, deferred defects while the office is empty, using computing capacity the organisation has already paid for. What makes it usable is not the model. It is the narrow scope, the team's own tests, and the review queue waiting at 08:00. The more interesting property is that the loop from report to released fix can close — which makes autonomy a decision about which changes you trust, rather than an engineering leap.
Read insightThe Open Knowledge Format describes a corpus. Retrieval finds things in one. What each contributes when they run together, what the pair does that neither does alone, and how to tell which of the three shapes your problem needs.
Read insightA trustworthy AI system should not merely retain an answer. It should let you return to that interaction and inspect the evidence, decisions, configuration, and controls behind it.
Read insightA directory of markdown files with YAML frontmatter, published by Google Cloud as an open specification. What OKF requires, what its trust fields record, and which of your problems it leaves untouched.
Read insightAn agent filling a form today reads the rendered page and infers. WebMCP lets the page declare the same capability as a named tool with a schema. Two attributes on the form, one per field, and no script. The demonstration below runs in this article.
Read insightThere is a widely held expectation that web pages end up as a prompt box. WebMCP is the more modest version of that future: the application stays visible, and a prompt is added as a second way to operate it. Two things have to exist for that to work. Only one of them is yours to build, and whether you build the second one as well is the decision about who controls the agent.
Read insightA form completed through WebMCP should run the same authentication, authorization and business rules as one filled in by hand. The security question WebMCP actually raises is not whether the backend needs to change. It is whether the action a valid, authorized agent just took is the action the user meant.
Read insightOne internal interface between your applications and whichever model serves them. What belongs in that layer, and the point at which not having one starts to cost you.
Read insightAround 90% of developers use AI daily, more distrust its accuracy than trust it, and its security pass rate has not moved in a year. Read together, the 2025-2026 evidence says the constraint has shifted from writing software to owning it, and that is a specification and accountability problem rather than a tooling one.
Read insightMost organizations buying or building on AI are deployers rather than providers. That distinction decides which obligations land on you, and most of them are architectural.
Read insightThe choice is usually settled by data residency and contracts, not by cost or model quality. Here is what each option costs you in practice.
Read insightThe term covers four separable properties, and vendors tend to sell the cheapest one. Which of them you actually need depends on what you are protecting against.
Read insightFrontier models can accelerate implementation, but only when they are used inside a disciplined delivery method: clear architecture, review, testing, security, and production ownership.
Read insightA business-built prototype proves intent and interaction. It does not prove architecture, security, data integrity or operational readiness. Treat it as an executable specification: preserve intent by default, and preserve generated code only where evidence justifies it.
Read insightA working demo is not a working system. The difference between AI that ships and AI that stalls is operational integration, not model quality.
Read insightData residency and modern AI are not mutually exclusive. A governed model gateway and on-premises deployment let regulated organizations use AI on their terms.
Read insightNewsletter
A short email when we publish something worth your time. Architecture, integration, and operational AI in regulated organizations. No cadence promises, no forwarding your address.