- AWS says AI assistants using stored copies of document permissions can give stale answers. It describes adding a live check with the source system on top of the stored copy.
- The claims are AWS's own, with no independent test, and the worked example covers only Google Drive. The idea still applies to any assistant that reads company files.
- Ask vendors how quickly revoked access takes effect, whether they check the source live, and who controls any impersonation credential. Test it by revoking a test user's access.
A stored permission list ages; a live check confirms it
Think of a building that prints its guest list each morning and hands it to the front desk. By afternoon, someone has been fired and someone else has been added. The desk still follows the morning list. Nothing was stolen. The list was simply old.
That is the risk AWS describes in a post on its machine learning blog, published October 7, 2026. It concerns AI assistants that answer questions from company documents. The lesson here is that a permission is an answer to a question asked right now. A copy of it is only a record of the past. AWS does not drop the copy. It keeps the copy for speed and adds a live check for the final say.
What AWS says goes wrong with copied permissions
AWS calls a common design replicate-and-filter. A connector pulls each document's access control list, the record of who may open it, during a scheduled sync. The tool stores those lists in its index. When someone asks a question, it matches the user to the stored lists and filters the results.
AWS names three weaknesses in this design.
First, the AI tool is not the source of truth. Connectors must reproduce each system's rules, including inheritance, group membership, conditional access and deny rules. AWS calls that error-prone across dozens of connectors.
Second, the stored lists are a snapshot from the last sync. AWS says some systems cannot signal changes. Its example is Confluence, which does not emit an event when group membership changes. Between syncs, a user whose access was revoked might still get answers drawn from documents they should no longer see.
Third, source systems change. A new SharePoint permission feature or a change to Google Drive sharing could create gaps in the mapping. AWS says content could be exposed until the connector is updated.
How the two-stage check works
AWS says it has added a live check to Amazon Quick and Amazon Bedrock Knowledge Bases, on top of the stored lists. Its example uses a Google Drive knowledge base. The post gives no launch date.
In stage one, the system runs a semantic search of the index. That means it finds passages by meaning, not exact keywords. It applies the stored access lists and produces a shortlist of candidate documents. AWS says it stops here for the first pass because a live call for every document in the index would cost too much at scale.
In stage two, the system asks Google Drive directly about each shortlisted document. To do that, it acts as the person who asked the question. An administrator sets up a service account, which is a login that belongs to software rather than a person. The system uses it to create access tokens tied to one user at a time. Google Drive holds the authoritative lists. Documents the user cannot open are dropped. Only the verified passages go to the large language model as context.
What the post claims, and what it leaves open
AWS claims that if an employee's access is revoked, the change shows up in AI answers "within moments, not hours or days." This is the vendor's own description. The post offers no independent test and no figures on speed or cost.
AWS quotes one customer. Jamahl Wiggins of Mondelēz International says the approach gave the company's internal review board confidence to proceed. The post says Mondelēz has deployed Amazon Quick for over 35,000 employees across four regions.
Some limits are worth stating. The worked example covers Google Drive. The post does not say how the check works for every connector. By AWS's description, stage two removes documents. It does not add any back. The shortlist still starts from stored lists, so those lists still matter.
Questions to put to your team and your vendors
The idea applies to any AI assistant that reads company files, not only AWS's. Start with these questions.
When someone loses access in SharePoint, Drive or Confluence, how long before the assistant stops using that document for them? Ask for a number and how it was measured.
Does the tool check the source system at question time, or does it rely on a stored copy? If it uses a copy, how often does it sync? Which of your systems cannot signal changes?
What happens when a source system adds a new permission feature? Who tests the connector, and how fast?
If a live check uses a service account to impersonate users, who holds that credential? How is it scoped, logged and reviewed? The post says administrators supply it. It does not describe the controls around it.
Finally, test it yourself. Revoke access for a test user, then ask the assistant a question only that document could answer.
A permission list is only as trustworthy as its age. Ask your vendors how old theirs is.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: AWS.





