AIToday
Large Language ModelsAI Business & IndustryAmazon AI BlogPublished: Oct 8, 2026, 04:00 JST

Amazon Quick adds real-time permission checks to AI search

Amazon Quick adds real-time permission checks to AI search

3 Key Points

  1. What happened

    Amazon Quick and Amazon Bedrock Knowledge Bases now verify document permissions with the authoritative source at query time, adding a real-time check on top of existing pre-retrieval filtering.

  2. Why it matters

    A revoked employee loses access in AI answers within moments, not hours or days, closing the gap between scheduled permission syncs that the post describes as a security risk.

  3. What to watch

    The two-stage design still relies on pre-retrieval filtering for speed, so the real-time check only runs on candidate documents; whether that holds at scale across many data sources is the open question.

WHO IT HITSThis lands on enterprise security and compliance teams who must approve AI assistants over internal document stores, and on IT administrators who currently manage connector sync schedules for SharePoint, Google Drive, and Confluence.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Retrieval Augmented Generation, the technique of letting an AI assistant pull passages from company documents before answering, has become a common way for enterprises to mine knowledge held in Microsoft SharePoint, Google Drive, and Atlassian Confluence. The catch the post highlights is that those same sources are governed by layered permission structures — inheritance hierarchies, group memberships, conditional access policies, and deny rules — that differ from one product to the next.

The prior standard relied on data connectors that copied permission lists during scheduled syncs and stored them as index attributes, then matched the logged-in user against those stored attributes at query time. The post argues this leaves three openings: the AI system becomes the enforcer without being the authoritative source, permission lists go stale between syncs, and new permission features in a source can create mapping gaps until a connector is updated.

The AWS answer is a hybrid: cached permission lists still drive the initial semantic search for speed, then a second stage calls the source directly to confirm the user may see each candidate document. If this holds up across many connectors and large document volumes, the appeal for security and compliance reviewers is clear — but the benefit depends on the real-time check staying fast and accurate at scale, and on connectors keeping pace as each source's permission model changes.

FAQ
How does the real-time check actually work?
Amazon Quick first runs a semantic search using permission lists already stored in the index, then verifies those candidate documents by calling the source's APIs, such as Google Drive, using administrator-provided service account credentials to generate user-specific access tokens.
What problem did the older approach have?
The replicate-and-filter approach copied permission lists during periodic syncs, so between syncs a user whose access was revoked might still receive AI answers from documents they should no longer see, and sources like Confluence do not emit an event when group membership changes.
Who is already using it?
Mondelēz International has deployed Amazon Quick for its over 35,000 employees across four regions, according to Jamahl Wiggins, Sr. Specialist – M365 Innovation at the company.
Amazon AI BlogRead Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleKore.ai puts Autoloop live to keep tuning enterprise agents