Skip to content

Checks whether a user has access to a specific document by verifying against the ingested access control list (ACL) in a knowledge base

Description

Checks whether a user has access to a specific document by verifying against the ingested access control list (ACL) in a knowledge base. Use this operation to validate that document-level access control is working as expected after ingestion. To use this operation, you must have the bedrock:CheckIngestedDocumentAcl permission.

Usage

bedrockagentruntime_check_ingested_document_acl(dataSourceId,
  documentId, knowledgeBaseId, userContext)

Arguments

  • dataSourceId

[required] The unique identifier of the data source that contains the document.

  • documentId

[required] The unique identifier of the document to check access for.

  • knowledgeBaseId

[required] The unique identifier of the knowledge base that contains the document.

  • userContext

[required] The context object containing identity information for access control filtering, including user ID and optional group memberships used to evaluate the document access control list (ACL).

Value

A list with the following syntax:

list(
  hasAccess = TRUE|FALSE
)

Request syntax

svc$check_ingested_document_acl(
  dataSourceId = "string",
  documentId = "string",
  knowledgeBaseId = "string",
  userContext = list(
    userId = "string"
  )
)