Departments can view different documents.
Neither retrieval nor citations may cross the boundary.
Choose two appropriate designs.
Apply user and document authorization to candidates, answers, and citations; similarity is not a substitute for authorization.
Detailed explanation
Only authorized documents become candidates.
Only authorized documents become candidates.
Citations must not create a separate leak.
Citations must not create a separate leak.
RAG must not bypass authorization.
RAG must not bypass authorization.
The access boundary disappears.
The access boundary disappears.
Try it yourself
An example you can run in a temporary verification environment.
Amazon Bedrock Knowledge Bases公式のメタデータフィルターとAWS IAM・AIF-C01 Domain 3.2を確認する。Expected result
検索・生成・出典の各段階でアクセス境界を維持する方法を説明できる。Key points
- Authorization
- Metadata
- Citation protection
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.