Feature

Role-Based Access Control

Retrieval is strictly role-scoped so users only see chunks and documents allowed by ACL mappings.

What this includes

  • Document ACLs are enforced during retrieval using JWT role claims.
  • Ingestion policies map source paths to roles for consistent access control.
  • Workspace roles align with Keycloak roles to keep retrieval boundaries clear.