<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Row-level security for a RAG agent: what Unity Catalog enforces, and what you have to build in Community Articles</title>
    <link>https://community.databricks.com/t5/community-articles/row-level-security-for-a-rag-agent-what-unity-catalog-enforces/m-p/170276#M1620</link>
    <description>&lt;P&gt;I'd love to be able to update this, because I pressed reply too early&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2026 17:50:54 GMT</pubDate>
    <dc:creator>SvenRelijveld</dc:creator>
    <dc:date>2026-09-30T17:50:54Z</dc:date>
    <item>
      <title>Row-level security for a RAG agent: what Unity Catalog enforces, and what you have to build</title>
      <link>https://community.databricks.com/t5/community-articles/row-level-security-for-a-rag-agent-what-unity-catalog-enforces/m-p/170272#M1619</link>
      <description>&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Two colleagues ask the same chatbot the same question. Should they get the same answer, or&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;different ones because they are allowed to see different things? Every organisation that puts an AI&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;assistant on top of its own documents runs into this sooner or later.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Unity Catalog has a good implementation for that on calls to tables. Attach a row filter and a&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;column mask, and every reader gets their own view of the same object, evaluated against whoever is&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;asking. It does not have a type of grant for row filters &lt;/SPAN&gt;&lt;SPAN&gt;*inside*&lt;/SPAN&gt;&lt;SPAN&gt; a vector index. An AI Search&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;index is a Unity Catalog object with object-level grants, so you can allow or deny querying it, but&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;it has no row filters and no column masks. Filtering an index is a parameter you pass in the query,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;from your own application code.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Sep 2026 17:19:43 GMT</pubDate>
      <guid>https://community.databricks.com/t5/community-articles/row-level-security-for-a-rag-agent-what-unity-catalog-enforces/m-p/170272#M1619</guid>
      <dc:creator>SvenRelijveld</dc:creator>
      <dc:date>2026-09-30T17:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Row-level security for a RAG agent: what Unity Catalog enforces, and what you have to build</title>
      <link>https://community.databricks.com/t5/community-articles/row-level-security-for-a-rag-agent-what-unity-catalog-enforces/m-p/170276#M1620</link>
      <description>&lt;P&gt;I'd love to be able to update this, because I pressed reply too early&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2026 17:50:54 GMT</pubDate>
      <guid>https://community.databricks.com/t5/community-articles/row-level-security-for-a-rag-agent-what-unity-catalog-enforces/m-p/170276#M1620</guid>
      <dc:creator>SvenRelijveld</dc:creator>
      <dc:date>2026-09-30T17:50:54Z</dc:date>
    </item>
  </channel>
</rss>

