Releases: poppycoderr/grounded-access
Releases · poppycoderr/grounded-access
Release list
v0.1.0-alpha.1 — tenant-isolated retrieval with a published evaluation
The first tagged pre-release. It covers milestones M0, M1a and M1b: a walking skeleton with tenant isolation, an evaluation baseline, and hybrid retrieval with a published verdict.
Authorization
- The tenant predicate is compiled once per request and embedded in every retrieval query.
AuthorizedChunkQueryis the only reader of the chunk table, and an architecture test enforces that. - Only tenant isolation is enforced. Clearance, department and project rules are milestone M2.
- Demo identities are JWTs signed with a published demo key. They are for local use only.
Retrieval
- Three strategies:
sparse-only(PostgreSQL full-text search),dense-only(exact pgvector search) andhybrid-rrf(reciprocal rank fusion with deduplication of overlapping chunks). - Every response carries the hash of its retrieval plan. Scores and per-channel ranks are returned to tokens with the
debugscope only. - A hybrid query that cannot be embedded is answered from the sparse channel and marked
degraded.
Ingestion
- Asynchronous jobs:
202and polling, aSKIP LOCKEDworker with leases, bounded retry and resume after the last recorded document. - Content-hash idempotency, an atomic switch between document versions, and version numbers that are never reused.
- Documents can be disabled and deleted; the change applies to the next query, and a background job removes unreachable versions.
- Markdown and plain-text chunking with sentence-level splitting and overlap inside a section.
Evaluation
- 70 hand-checked cases over 21 fictional documents, with paraphrases, hard negatives and cross-tenant probes, split into
devandtest. - Evidence is labelled as a document version plus a quote, so chunking strategies are compared on the same labels.
- Bootstrap confidence intervals, paired comparisons, an offline BM25 reference row, and a security gate that fails CI on any unauthorized result.
- Published result (report, analysis): dense beats PostgreSQL full-text search on MRR@10, full-text search is measurably below BM25, and hybrid shows no detectable difference from dense.
Not in this release
Label-based access rules, audit events, existence-leakage guarantees beyond retrieval, reranking, answer generation with citations, and tracing. See the milestones.
Try it
git clone --branch v0.1.0-alpha.1 https://github.com/poppycoderr/grounded-access.git
cd grounded-access
docker compose up -d --build --wait
./scripts/load-demo
./scripts/benchmarkThis is a demo benchmark on a small fictional corpus. It shows that the method is reproducible; it says nothing about production retrieval quality.