# Metadata, Permissions and Hierarchies — Retrieval-Augmented Generation (RAG)

Source: https://www.geekswithgeeks.com/en/rag/i-metadata

> Attach fields that enable filtering, citations and access control.

## Filters before similarity

Each chunk should carry **metadata**: source document, page or section, date, version, language, product, author, department and, importantly, **who may read it**. Metadata allows hard filters ("only 2025 policies for India", "only documents this user can access") applied before or during search, which is more reliable than hoping similarity finds the right one. For **permissions**, enforce access control in the retrieval query itself, never only in the prompt. A **parent-child** design indexes small child chunks for precise matching but returns the larger parent section to the model for fuller context.

## A chunk record

A typical stored record; field names are your choice.

```json
{
  "id": "hr-policy-2025#leave#2",
  "text": "Unused leave up to 5 days can be carried over to the next year.",
  "source": "hr-policy-2025.pdf",
  "page": 4,
  "section": "Leave",
  "country": "IN",
  "effective": "2025-04-01",
  "allowed_groups": ["all-staff"],
  "parent_id": "hr-policy-2025#leave"
}
```

## Store the title path

Keep the full path such as "HR Policy > Leave > Carry over" in metadata. Showing it in citations helps users trust and verify answers.

**Quiz:** Where should access control be enforced in RAG?

- [x] In the retrieval query, before text reaches the prompt
- [ ] Only by telling the model to be careful
- [ ] After the answer is shown
- [ ] Nowhere

*Answer:* In the retrieval query, before text reaches the prompt. Text the user may not see must never be retrieved into the prompt.
