Design per-user permissions for a RAG system over a company's documents. The CEO and an intern ask the same question.
The defining security design problem of enterprise RAG, and the reason Glean exists. Query-time ACL filtering, permission sync lag, and the leakage channels that survive naive designs: caches, citations, and the model itself.
Updated Aug 2026 · Grounded in real Forward Deployed Engineer interview loops and written to a senior-engineer editorial bar.
The defining security design problem of enterprise RAG, and the reason Glean exists. Query-time ACL filtering, permission sync lag, and the leakage channels that survive naive designs: caches, citations, and the model itself.
Lead with where the obvious approach breaks, because that is the judgment they are screening for — most candidates jump straight to the happy path and lose the room.
Then walk the failure back through the pipeline in order, naming the one metric the customer's exec sponsor actually cares about before you propose the fix.