Securing the Agent: Vendor-Neutral, Multitenant Enterprise Retrieval and Tool Use

📅 2026-05-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses critical security risks in enterprise retrieval-augmented generation (RAG) and agent systems under multi-tenancy, where cross-tenant data leakage and unsafe tool invocations arise due to relevance-based ranking that disregards access control. To resolve this, the authors propose a hierarchical isolation architecture that deeply integrates attribute-based access control (ABAC) into the entire RAG and agent pipeline. By introducing policy-aware data ingestion, retrieval-time gating mechanisms, and server-side multi-turn agent orchestration, all security-critical operations are centralized on the server. This design ensures strict tenant isolation and regulatory compliance while preserving client-side flexibility and low-latency responsiveness. Experiments based on the OGX framework demonstrate that the proposed approach completely eliminates cross-tenant data leakage with negligible performance overhead.
📝 Abstract
Retrieval-Augmented Generation (RAG) and agentic AI systems are increasingly prevalent in enterprise AI deployments. However, real enterprise environments introduce challenges largely absent from academic treatments and consumer-facing APIs: multiple tenants with heterogeneous data, strict access-control requirements, regulatory compliance, and cost pressures that demand shared infrastructure. A fundamental problem underlies existing RAG architectures in these settings: retrieval systems rank documents by relevance--whether through semantic similarity, keyword matching, or hybrid approaches--not by authorization, so a query from one tenant can surface another tenant's confidential data simply because it scores highest. We formalize this gap and analyze additional shortcomings--including tool-mediated disclosure, context accumulation across turns, and client-side orchestration bypass--that arise when agentic systems conflate relevance with authorization. To address these challenges, we introduce a layered isolation architecture combining policy-aware ingestion, retrieval-time gating, and shared inference, enforced through server-side agentic orchestration. This approach centralizes security-critical operations--tool execution authorization, state isolation, and policy enforcement--on the server, creating natural enforcement points for multitenant isolation while allowing client-side frameworks to retain control over agent composition and latency-sensitive operations. We validate the proposed architecture through an open-source implementation in OGX, a vendor-neutral framework that implements an OpenAI-compatible, open-source Responses API with server-side multi-turn orchestration. We evaluate it empirically and show that ABAC gating eliminates cross-tenant leakage while introducing negligible overhead.
Problem

Research questions and friction points this paper is trying to address.

multitenant
authorization
retrieval-augmented generation
data leakage
access control
Innovation

Methods, ideas, or system contributions that make the work stand out.

multitenant isolation
retrieval-augmented generation
attribute-based access control
agentic AI
server-side orchestration
F
Francisco Javier Arceo
Red Hat AI
V
Varsha Prasad Narsing
Red Hat AI