Feature
Role-Based Access Control
Retrieval is strictly role-scoped so users only see chunks and documents allowed by ACL mappings.
What this includes
- Document ACLs are enforced during retrieval using JWT role claims.
- Ingestion policies map source paths to roles for consistent access control.
- Workspace roles align with Keycloak roles to keep retrieval boundaries clear.