A semantic search system has already crossed its security boundary before generation begins: if retrieval admits another customer's chunk, no prompt can make that access legitimate afterward. Short answer: in a multi-tenant ask-your-docs SaaS, derive the customer identity from authenticated serv...
Source: [Dev.to](https://dev.to/zylahmorn61835/adr-who-owns-scope-in-a-nodejs-multi-tenant-ask-docs-saas-lpj)