A document is rarely one object in an AI product. The ingestion pipeline may create page images, OCR text, thumbnails, a transcript, embeddings and excerpts. The source document's access check may work perfectly while a preview image has a separate storage key and a public CDN URL. Revoking the source permission changes neither that URL nor a copy already cached by the edge. The preview can disclose exactly the content the user can no longer open.

Treat derived assets as descendants of a source object with its tenant, authorization scope, source revision and deletion state. Every serving path needs an access decision or a short-lived grant bound to the viewer and specific asset. A guess-resistant URL is not authorization. Google Cloud's signed-URL guidance distinguishes signed access from public bucket permissions and describes caching behavior for signed requests. Its public-access guidance also notes that internet caches can outlive a public-access change. The exact revocation window depends on the chosen CDN, signing and cache configuration, so measure it in this system.

At revoke time, stop new grants first. Mark every derivative of the affected source version as inaccessible, including thumbnails and extracted page images. Invalidate or expire edge copies where the contract requires fast revocation. Rotate or change asset identifiers if a leaked long-lived URL cannot be reliably invalidated, and avoid placing sensitive previews in public caches in the first place. Keep lineage so a reprocessed file does not restore an old derivative under a new key. Test all routes as the former viewer after revocation, with both warm and cold caches.

What about a preview already downloaded to someone's device? Server revocation cannot pull back bytes they possess. State the boundary honestly. The enforceable promise is that our service stops serving unauthorized bytes within a defined window and does not make new derived copies accessible. A tool gives the agent a signed file URL. Should that URL enter long-term memory? asks whether an agent should remember a signed URL. This page asks whether the derived object behind that URL had the right lifecycle and authorization at all.