Role-scoped retrieval
The filter comes from trusted server state, so a prompt cannot reach documents outside the caller’s role.
A permission-aware support agent authenticates the caller, turns their role into a vector filter, and retrieves only the handbook records they are allowed to read. The question text can never widen the filter, and a similarity score is never an authorization decision.
Visibility is attached when documents are embedded, and enforced again on every request.
Validate documents at startup and embed them with flat visibility metadata.
Load the embeddings into a vector store your app owns.
Check the bearer token and the knowledge:read permission before anything else runs.
Derive a vectorFilter from the principal’s role and attach createVectorContext to a per-request agent.
The agent cites the handbook, or says the handbook is insufficient instead of inventing policy.
The filter comes from trusted server state, so a prompt cannot reach documents outside the caller’s role.
Every answer names its handbook source, or admits the handbook does not cover the question.
A bad token returns 401 before parsing, search, or completion. Invalid JSON, extra fields, and oversized bodies are rejected.
Start in memory, then move to pgvector, Qdrant, Chroma, or LanceDB for production.
The filter is decided by the principal, not the question.
1import { Agent, createVectorContext } from '@anvia/core/agent'2import { vectorFilter } from '@anvia/core/vector-store'34export function createSupportAgent(principal: Principal) {5 const filter = principal.role === 'manager'6 ? vectorFilter.or(7 vectorFilter.eq('visibility', 'agent'),8 vectorFilter.eq('visibility', 'manager'),9 )10 : vectorFilter.eq('visibility', 'agent')1112 return new Agent({13 id: 'customer-support-rag',14 model: completionModel,15 instructions: 'Answer only from the retrieved handbook documents.',16 context: [createVectorContext({17 store: knowledgeStore, model: embeddingModel, topK: 4, filter,18 })],19 })20}The example uses an in-memory store, which is not a production persistence strategy. For strong tenant isolation, add namespaces, database policy, or separate indexes on top of filters.
Start from the guide, run the example, or look at what else Anvia handles.