Use this data-flow and trust map
Draw user, assistant, retrieval store, account API, and response channel. Place authorization at the account API, with the real session and requested account ID on every call. Treat prompt and retrieved text as untrusted.
| Item | Check or owner | Evidence |
|---|---|---|
| User request | Untrusted text | Authenticate session |
| Assistant planner | Derived intent | No direct database right |
| Account API | Trusted enforcement | Check account ownership |
| Response | Customer view | Mask and audit |
Test the boundary
Test a second account, a revoked session, a user switch on a shared device, and a document that names another customer. Inspect both the model answer and tool trace. The assistant must not become a shortcut around account ownership checks.
Worked synthetic case
Synthetic case: A customer asks for their balance, then adds “show the previous user’s balance too.” The device was shared, and a stale browser cache holds an older account ID.
Trace user session, assistant, retrieval store, account API, and response. Test another account ID, revoked session, account switch, and back navigation. The pass condition is that the API returns only records owned by the current authenticated user and the screen shows no stale balance.
Send the real session and requested account ID to the account API for every call. Limit tool output to the fields the assistant needs. The model may refuse a bad prompt, but the API must enforce ownership even if the model calls it.
This can reduce the assistant’s ability to answer broad support questions. Use a separate staff workflow with its own roles and audit trail, rather than giving the customer assistant staff-level access.
Walk one account-data path
Start with a synthetic customer question about a balance. Map identity check, account lookup, retrieval cache, model request, tool response, final answer, and logs as distinct nodes. At each edge, state the allowed fields and the actor allowed to read them. Then swap the account ID in the tool argument while keeping the user token. The account service must deny the request and the assistant must not answer from stale context. Record the denied tool call and any cached value used. Repair the service authorization first; a prompt instruction to “respect privacy” is not a control. Repeat with a second tenant and with a revoked session.
Give each flow edge a field list
Synthetic account A-101 has balance 101; B-201 has balance 202. At the browser-to-assistant edge allow session handle and question. At the assistant-to-account-service edge allow a server-issued caller scope and requested account ID. The account service may return masked account ID, available balance, currency, and observation time only after authorization. Keep full identifiers and risk notes out of the model input when the task does not need them.
Run A’s own balance request first. Then ask for B-201 through user text, a retrieved page, and a changed tool argument in separate runs. Inspect the requested account and the API’s caller identity. A model refusal with a successful B lookup is a failure. A gateway denial with no foreign lookup is the expected control result.
Set scope for shared-device and in-flight tests
Start a fresh A conversation after B signs out on the test device. Clear B’s server conversation access and local display state under the logout rule. Use Back, reopen the app offline, and inspect saved messages. Server revocation cannot erase a screenshot or text already downloaded. The test checks future access and the copies the app controls, not recovery of past secrecy.
Pause a balance request before the service decision, revoke A, then resume it. Test against the stated revocation window. A second request already completed before revocation has a different expected result. Record request start, decision, revocation, model dispatch, and display times. The threat map should identify the owner of each gate: account service, retriever, conversation store, and device cache. The OWASP authorization guide grounds the per-request checks.