Skip to content

Releases: poppycoderr/grounded-access

v0.1.0-alpha.1 — tenant-isolated retrieval with a published evaluation

Choose a tag to compare

@poppycoderr poppycoderr released this 01 Oct 15:45

The first tagged pre-release. It covers milestones M0, M1a and M1b: a walking skeleton with tenant isolation, an evaluation baseline, and hybrid retrieval with a published verdict.

Authorization

  • The tenant predicate is compiled once per request and embedded in every retrieval query. AuthorizedChunkQuery is the only reader of the chunk table, and an architecture test enforces that.
  • Only tenant isolation is enforced. Clearance, department and project rules are milestone M2.
  • Demo identities are JWTs signed with a published demo key. They are for local use only.

Retrieval

  • Three strategies: sparse-only (PostgreSQL full-text search), dense-only (exact pgvector search) and hybrid-rrf (reciprocal rank fusion with deduplication of overlapping chunks).
  • Every response carries the hash of its retrieval plan. Scores and per-channel ranks are returned to tokens with the debug scope only.
  • A hybrid query that cannot be embedded is answered from the sparse channel and marked degraded.

Ingestion

  • Asynchronous jobs: 202 and polling, a SKIP LOCKED worker with leases, bounded retry and resume after the last recorded document.
  • Content-hash idempotency, an atomic switch between document versions, and version numbers that are never reused.
  • Documents can be disabled and deleted; the change applies to the next query, and a background job removes unreachable versions.
  • Markdown and plain-text chunking with sentence-level splitting and overlap inside a section.

Evaluation

  • 70 hand-checked cases over 21 fictional documents, with paraphrases, hard negatives and cross-tenant probes, split into dev and test.
  • Evidence is labelled as a document version plus a quote, so chunking strategies are compared on the same labels.
  • Bootstrap confidence intervals, paired comparisons, an offline BM25 reference row, and a security gate that fails CI on any unauthorized result.
  • Published result (report, analysis): dense beats PostgreSQL full-text search on MRR@10, full-text search is measurably below BM25, and hybrid shows no detectable difference from dense.

Not in this release

Label-based access rules, audit events, existence-leakage guarantees beyond retrieval, reranking, answer generation with citations, and tracing. See the milestones.

Try it

git clone --branch v0.1.0-alpha.1 https://github.com/poppycoderr/grounded-access.git
cd grounded-access
docker compose up -d --build --wait
./scripts/load-demo
./scripts/benchmark

This is a demo benchmark on a small fictional corpus. It shows that the method is reproducible; it says nothing about production retrieval quality.