What retrieval-augmented generation actually does
RAG is a method for adding retrieved information to a model’s working context before it generates an answer. A typical system prepares documents for search, finds passages related to the user’s question and supplies selected passages alongside instructions.
The model then writes using that context. It has not necessarily absorbed the whole document collection into its trained parameters. Uploading a handbook to a retrieval system and training a model on that handbook are different operations.
OWASP’s RAG Security Cheat Sheet treats the document pipeline as part of the system’s security boundary. Trust matters before generation: where a document came from, whether it belongs in the index and who may retrieve it. A careful final prompt cannot compensate for giving the model material that the user was never allowed to access.
Follow one question through a handbook chatbot
Imagine an invented company handbook with a general travel policy and a newer addendum for international trips. An employee asks whether a Friday hotel stay is reimbursable. The system searches for relevant passages and places the selected text in the model’s context.
A good answer identifies the condition in the policy, cites the relevant passage and flags any missing fact about the trip. If only the old handbook is retrieved, the answer may sound correct while missing the addendum. If both are retrieved without dates, the model may struggle to tell which governs.
Store meaningful document metadata, including version and effective date. Check retrieval itself when an answer fails: was the governing passage present? Rewriting the generation instruction will not repair an index that never included the updated rule. This example describes an architecture, not a DarkGPT company-handbook integration.

Three different ways a document answer can go wrong
| Failure | Where to investigate | Useful evidence |
|---|---|---|
| The answer misses the rule | Retrieval and document preparation. | The actual passages supplied to the model. |
| The passage is right but the conclusion is wrong | Generation and interpretation. | The cited condition compared with the answer. |
| The user receives restricted material | Authorization and index design. | Access rules applied before retrieval and generation. |
A citation proves that the system attached a reference, not that the conclusion follows from it. Open the passage and compare the claim. A reimbursement condition about business nights does not automatically cover a personal extension.
Also check the absence case. If the supplied documents do not answer the question, the chatbot should identify that gap. It should not fill it with a plausible policy and cite an unrelated paragraph. An honest “the supplied handbook does not specify this” can be the most useful result.
Documents provide evidence, not new authority
A document may contain instructions directed at a reader. In a RAG system, those words remain retrieved content unless the application has explicitly assigned them an authorized role. A passage cannot grant its author permission to change the chatbot’s tools or expose unrelated files.
Apply access controls before placing material into the model’s context. For a mixed collection, retrieval should respect the authenticated user’s actual access. Filtering only the final answer leaves restricted content inside the generation process.
OWASP highlights access control, document provenance and the risk of malicious retrieved content. Implement those controls in the surrounding application. A prompt asking the model to be careful is not an independent permission check. Keep tool access bounded so an untrusted passage cannot turn a handbook answer into an unrelated action.

Test with answers you can trace to the documents
Build a small evaluation set from permitted test documents. Include a direct answer, a rule with an exception, conflicting versions, a question with no answer and a document outside the test user’s access. Write down the expected evidence and permitted behavior for each.
Review retrieval and generation separately. The system should find the right permitted passage before you evaluate how well it explains it. Retain enough of the trace to identify whether an error came from preparation, search, interpretation or authorization.
RAG is useful when relevant evidence needs to accompany an answer. It is not a blanket cure for hallucinations or prompt injection. The practical question is whether this system retrieves the right authorized material and produces an answer the reviewer can verify. That is a stronger standard than a chatbot that simply says it has read your files.
Sources & further reading
Follow the original source to check its date and scope.
- What is retrieval-augmented generation?
IBM | retrieved context is distinct from training; grounding does not make a model error-proof.
- RAG Security Cheat Sheet
OWASP | protect document ingestion, retrieval permissions and the boundary around untrusted content.
Make it your next question
Try this prompt
Use this promptExplain a document-based chatbot for an invented company handbook. Show what retrieval supplies to the model and where access checks belong. Include a missing-answer case and a conflicting-version case. Do not infer permission from a prompt.
Opens chat with this prompt filled in. You choose when to send it.