Journal of Advances in Developmental Research
E-ISSN: 0976-4844
•
Impact Factor: 9.71
A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal
Plagiarism is checked by the leading plagiarism checker
Call for Paper
Volume 17 Issue 2
2026
Indexing Partners
SENTINEL: Retrieval-Time Governance for Enterprise RAG A Controlled Red-Team Benchmark for Policy-Aware Retrieval, Privacy Enforcement, and Audit Replay
| Author(s) | Sandeep Nutakki |
|---|---|
| Country | United States |
| Abstract | Retrieval-augmented generation (RAG) systems expose proprietary documents through embedding indexes, rerankers, prompts, and generated answers, yet many enterprise deployments govern only the source repository or redact final text after generation. This paper presents SENTINEL, a governance and privacy architecture for enforcing authorization, purpose limitation, retention, legal hold, and sensitive-data controls inside the retrieval path. SENTINEL combines policy-aware retrieval, embedding provenance, typed sensitive-data classification, prompt-injection filtering, and an append-only audit ledger. We evaluate SENTINEL on a standalone benchmark spanning 1.2 million policy-labeled retrieval requests, 480,000 documents, 12 sensitive-data types, 7 policy classes, and 14 red-team attack families across supply-chain, healthcare, and financial workflows. In this controlled benchmark, SENTINEL reduced unauthorized context exposure from 3.84% under ungoverned dense retrieval to 0.00% observed events (one-sided 95% CI upper bound 0.00025%, McNemar p < 0.001). It achieved 99.2% sensitive-data leakage recall and 97.4% precision, blocked 98.6% of prompt-injection exfiltration attempts, and added 38 ms p95 retrieval latency over a policy-free vector-search baseline. The results support retrieval-time governance as a measurable control for enterprise RAG systems evaluated under known policy labels and red-team attacks, not as evidence of regulatory certification or universal protection. |
| Keywords | retrieval-augmented generation, enterprise RAG, data governance, privacy engineering, access control, prompt injection, auditability, policy-aware retrieval, red-team evaluation |
| Field | Engineering |
| Published In | Volume 17, Issue 1, January-June 2026 |
| Published On | 2026-06-25 |
| DOI | https://doi.org/10.71097/IJAIDR.v17.i1.2041 |
Share this

Crossref DOI prefix of IJAIDR is 10.71097/IJAIDR
Downloads
All research papers published on this website are licensed under Creative Commons Attribution-ShareAlike 4.0 International License, and all rights belong to their respective authors/researchers.