Restricted HR document exposed
The assistant retrieved a restricted compensation document because the vector index did not preserve file-level access control metadata.
An internal knowledge or RAG assistant helps employees ask questions across documents, policies, wikis, support notes, manuals, contracts, tickets, and internal knowledge systems.
Buyer question
Can this internal assistant help employees find information without exposing restricted documents, trusting hidden instructions, or giving outdated guidance?
Scenario
An organization wants employees to ask natural-language questions across internal documents and receive answers with useful context. The assistant may connect to SharePoint, Google Drive, Confluence, Slack exports, Notion, ticketing systems, policy repositories, engineering docs, contracts, or vector databases. This can improve productivity and reduce tribal knowledge. But it can also create a company-wide search engine that surfaces information employees should not see, mixes stale and current policy, or trusts malicious instructions hidden in retrieved documents.
Why it matters
RAG systems are often trusted because they appear to answer from company sources. But retrieval does not automatically mean authorization, freshness, correctness, or safety. A RAG assistant can expose restricted files, cite weak sources, or become manipulated by documents that were never meant to act as instructions.
Risk surface
Assessment scope
Mythos projects
Athena
maps data sources, permissions, identity paths, vector index boundaries, sensitive repositories, logging, and evidence.
Achilles
tests retrieval behavior, permission boundaries, citation quality, refusal behavior, stale-source handling, and prompt injection resistance.
Minotaur
may support internal-only adversarial document generation, hidden instruction tests, conflicting policy tests, and restricted-source scenarios.
Illustrative findings
Illustrative examples of what a Mythos assessment may surface. They are representative patterns, not findings from a specific customer.
The assistant retrieved a restricted compensation document because the vector index did not preserve file-level access control metadata.
A general employee query returned excerpts from an executive strategy document because source restrictions were not enforced before retrieval.
A Confluence page contained instruction-like language that caused the assistant to ignore normal answer rules.
The assistant answered from a superseded policy without warning the user that a newer policy existed.
The assistant cited a policy document, but the cited section did not support the generated conclusion.
Deliverables
Decision
Whether the assistant should remain in sandbox, support a department pilot, access only approved public-internal sources, expand to sensitive repositories, or be blocked from broad employee rollout.
Recommendation
An internal RAG assistant should be treated as an access and evidence problem, not just a search feature. Mythos should help the customer prove that authorization happens before retrieval, sources are current and grounded, sensitive documents stay protected, and answers remain reviewable before broad rollout.

Mythos AI Security
Evidence-first AI deployment assurance.
Authorized. Scoped. Human-controlled.
Start the Assessment
Tell Mythos what you are building, connecting, or preparing to release. We will help identify the right assessment path.