Amazon Quick and Bedrock Add Real-Time Access Checks for RAG Applications
Amazon Quick and Amazon Bedrock Knowledge Bases now enforce document-level permissions for Retrieval Augmented Generation (RAG) by verifying user access with authoritative data sources at query time, ensuring AI responses reflect current permissions and reducing security risk.
What changed?
Amazon Quick and Amazon Bedrock Knowledge Bases now implement a two-stage process for access control in Retrieval Augmented Generation (RAG) workflows. First, they filter documents using cached access control lists (ACLs). Second, before returning results, they verify user permissions in real time by querying the original source (such as Google Drive or SharePoint). Unauthorized documents are removed before being passed to the AI model. This ensures access decisions always reflect current permissions.

Additionally, Amazon Bedrock now offers responsible AI features, including content guardrails, grounding checks, and customizable safety policies.
Why does it matter to an everyday developer?
When building enterprise applications with AI that access business data from sources like SharePoint, Google Drive, or Confluence, permission enforcement is a core security requirement. Traditional approaches relied on pre-synced ACL data, which could quickly become outdated if a user’s permissions changed. This latency risked exposing confidential information through AI responses. The real-time verification process now available in Amazon’s services ensures that only documents a user is currently authorized to see are ever included in model context, even if access has changed moments earlier. This gives developers a clearer security model, confidence in compliance, and reduces the need to manually manage ACL synchronization schedules.
What can the developer do now?
Developers integrating Amazon Quick or Bedrock Knowledge Bases can take advantage of the new access control architecture immediately, requiring no manual polling or sync logic for permissions. This lets developers focus on building RAG-enabled chat and search applications without custom permission enforcement code. To get started, review the documentation and configure service account credentials for your knowledge sources. If your application or organization is subject to strict compliance policies, you can reference this built-in approach to satisfy requirements on access control and demonstrate best practices in AI safety and governance.
