Knowledge Entitlement Drift Review
Reconcile authoritative access policy with effective permissions across source, ingestion, index, cache, retrieval, citation, and response layers.
Use in AI
Choose an AI tool to copy the current Prompt with a short usage note. Nothing is sent to that tool.
Review whether effective access to enterprise knowledge has drifted from authoritative entitlement policy anywhere between the source system and the final retrieval response. Provide: - Approved subject, group, tenant, region, purpose, document, field, and time-bound access rules: [Authoritative entitlement policy] - Source repositories, ingestion, transformations, embeddings, indexes, namespaces, caches, retrievers, rerankers, citations, response filters, and identity propagation: [Knowledge architecture and identity flow] - Current ACLs, groups, policies, index filters, namespace rules, token claims, cache keys, and configuration exports: [Effective permission and configuration evidence] - Sanitized query/access traces, denials, sampled results, recertification records, deployments, migrations, and permission changes: [Retrieval access and change logs] - Data classification, privacy, residency, incident, availability, knowledge-owner, identity-owner, security-reviewer, and service-owner constraints: [Risk constraints and accountable owners] Do not claim a leakage event from configuration drift alone, and do not treat absence of logged leakage as proof of correct enforcement. Do not claim live access tests unless supplied. Distinguish observed evidence from inference, as well as authoritative policy, configured control, effective access, observed use, and confirmed exposure. Preserve uncertainty where identities or document lineage cannot be joined. Review: 1. Define authoritative entitlement contracts. Translate policy into subject-resource-action-context rules, including inheritance, deny precedence, purpose, tenant, region, embargo, expiry, field-level, and break-glass conditions. 2. Trace identity and entitlement propagation. Map how the caller identity and claims reach source filtering, ingestion metadata, index namespaces, retrieval filters, caches, citations, and response controls. Flag stages where identity is dropped, transformed, defaulted, or cached. 3. Reconcile effective controls. Compare authoritative rules with source ACLs, indexed metadata, filter logic, namespace membership, cache partitioning, service credentials, and post-retrieval controls. Account for stale groups, deleted users, broad service accounts, and shared indexes. 4. Build a drift register. Classify differences as Stale grant, Missing grant, Metadata loss, Filter mismatch, Namespace error, Cache-key weakness, Inherited expansion, Migration residue, Exception, or Not assessable. Record potential exposure and confirmed use separately. 5. Assess change and time behavior. Measure supplied lag between source permission changes and downstream propagation. Review revocation, role change, tenant move, embargo, and expiry handling. Do not invent propagation time. 6. Define the smallest safe correction. Recommend targeted re-indexing, metadata repair, filter correction, cache invalidation, token/session refresh, service-account restriction, or temporary serving restriction. Preserve availability and forensic evidence. 7. Design recertification proof. Specify positive and negative access cases, identity/tenant/region slices, document lineage checks, revocation timing, cache isolation, monitoring, and owner approval. Required deliverable: # Knowledge Entitlement Drift Review ## Authoritative Entitlement Matrix | Subject/context | Resource/class | Allowed/denied action | Condition/expiry | Policy evidence | Owner | |---|---|---|---|---|---| ## Propagation Map | Stage | Identity/entitlement input | Transformation | Enforcement | Evidence | Gap | |---|---|---|---|---|---| ## Drift Register | Drift | Classification | Policy state | Effective state | Potential exposure | Observed use | Confidence | Owner | |---|---|---|---|---|---|---|---| ## Correction and Restriction Plan | Priority | Smallest safe action | Affected layer | Availability effect | Authorization | Verification | |---|---|---|---|---|---| ## Recertification Gate | Test slice | Positive expectation | Negative expectation | Evidence source | Owner | Status | |---|---|---|---|---|---| ## Decision - Entitlement state: Aligned / Aligned with exceptions / Drift present / Not assessable - Serving restrictions: - Required corrections: - Unresolved exposure: - Revalidation trigger: Completion requires policy-to-response traceability for material knowledge classes, explicit separation of drift from confirmed exposure, and negative access evidence before removed permissions are considered effective.
Variables to Replace
Replace each listed value in the Prompt with information relevant to your task.
- Authoritative entitlement policy
- Knowledge architecture and identity flow
- Effective permission and configuration evidence
- Retrieval access and change logs
- Risk constraints and accountable owners
How to Use This Prompt
Use Claude with the source access policy, ACL and group exports, index metadata rules, identity and cache architecture, permission-change history, and sanitized retrieval samples. Do not provide credentials or sensitive document bodies where identifiers suffice. Have the identity and knowledge owners validate policy, and the security reviewer approve restrictions and negative tests.
Example Use Case
After a department reorganization, source document ACLs are correct but a shared vector index retains old group metadata for several days. The review quantifies drift without claiming exposure, restricts affected namespaces, and defines revocation-lag and cache-isolation tests.
Was this useful?