CogLake User Guide

Security for users

Understand how CogLake applies roles, resource access, source permissions, and secure original downloads.

CogLake evaluates access at several layers before returning knowledge.

Access layers

1Authenticate account
2Check product permission
3Check resource scope
4Verify source ACL
5Return allowed content
  1. Your account must be active and authenticated.
  2. Your role must include the product permission for the requested action.
  3. Your role must have access to the selected workspace or connector.
  4. Imported source permissions must allow one of your user, group, or domain principals.
  5. Deleted and revoked source items are removed from visible retrieval paths.

Search provider filters improve performance, but the API verifies permission again before returning results or documents.

Original files

Original files are downloaded through the CogLake API. Object storage is not exposed directly to the browser or an agent. Temporary original-file URLs remain bound to the authenticated access path.

Notes

Notes attached to a file inherit that file's access boundary. The interface records the author and update time and exposes recent note versions for review.

Model egress

Administrators can keep embeddings, reranking, generated answers, OCR, vision, document processing, and transcription on local endpoints. Hosted processing is denied by default and can be enabled per capability for the active tenant. The policy applies to new requests immediately and does not create role-specific indexes.

Administrators

Administrative permissions allow configuration and troubleshooting. They do not automatically bypass an original source ACL. Use the role preview in Discover to verify what a role would see without changing another user's account.

On this page