Terminated at 11:51. At 12:00 the company's private AI was still answering her questions.
That's Priya, a credit analyst in the synthetic European bank we built to stress-test enterprise RAG. Her termination webhook fired, the identity system knew, and it didn't matter. The retrieval layer in front of the LLM had stamped permissions onto the index when it was built, a week earlier. An ingestion-time snapshot never expires. The naive side of our demo kept serving her the documents she could see yesterday.
The fix wasn't a better model. We built RAGGUARD, a permission firewall of plain deterministic code that authorizes every retrieved document at query time, against her live identity, before anything reaches the model. Nine minutes after termination: 0 granted, 5 denied, reason code ALL_ACCESS_REVOKED_TERMINATION. On our 40-case golden authorization set the naive flat-ACL build leaked 10 times, this case among them. The firewall went 40 for 40. The clip below shows both sides.
For anyone running RAG over internal documents: when someone leaves, what actually cuts off the AI's retrieval, the next re-index or a check at query time?
#EnterpriseRAG #PrivateLLM #RBAC #AIGovernance
Published on Facebook · July 20, 2026
On social media