Suppose a search index stores small child chunks for ranking. It returns a paragraph the user may read. The RAG layer then replaces that paragraph with its larger parent document to give the model context. Somewhere in that parent is a section restricted to another team. The search filter did its job for the child. The expansion changed the object being disclosed.

Authorization has to hold for every piece of text that actually enters the prompt, not just the hit that selected it. A parent ID is a retrieval pointer, not evidence that all its descendants share one access rule. If permissions vary within a file, indexing the whole file as one authorized parent is the wrong security unit. Split content at permission boundaries, or expand only into spans independently authorized for this user. If the complete parent has a single ACL, recheck that ACL on the parent fetch and keep its permission version tied to the fetched content. Azure AI Search's security filtering guidance is explicit that a query must apply its identity filter to the documents it returns.

The tricky implementation detail is the join. A child might carry allowed_groups=["all-staff"] while its parent is fetched by ID from an object store with a service credential. The object store cannot tell which end user is asking unless the application passes their identity or checks the returned content itself. A cached parent keyed only by document ID can widen the leak further. Search-time ACL filtering does not automatically protect that later object-store read.

I would test with two children under one parent that have different permissions. Log the IDs and permission decisions for both the matched child and every expanded span, then assert that the final model context and citations contain only allowed text. Include permission changes and cached expansion in the test. Do not expose a restricted title or snippet in a citation either.

If the interviewer suggests filtering the final answer instead, that is too late. The model has already consumed the private material, and a text filter cannot reliably undo that exposure. Make the authorization boundary the assembled context, including any parent expansion and tool fetch, before generation starts.