Journal of Advances in Developmental Research

E-ISSN: 0976-4844     Impact Factor: 9.71

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 17 Issue 2 July-December 2026 Submit your research before last 3 days of December to publish your research paper in the issue of July-December.

SENTINEL: Retrieval-Time Governance for Enterprise RAG A Controlled Red-Team Benchmark for Policy-Aware Retrieval, Privacy Enforcement, and Audit Replay

Author(s) Sandeep Nutakki
Country United States
Abstract Retrieval-augmented generation (RAG) systems expose proprietary documents through embedding indexes, rerankers, prompts, and generated answers, yet many enterprise deployments govern only the source repository or redact final text after generation. This paper presents SENTINEL, a governance and privacy architecture for enforcing authorization, purpose limitation, retention, legal hold, and sensitive-data controls inside the retrieval path. SENTINEL combines policy-aware retrieval, embedding provenance, typed sensitive-data classification, prompt-injection filtering, and an append-only audit ledger. We evaluate SENTINEL on a standalone benchmark spanning 1.2 million policy-labeled retrieval requests, 480,000 documents, 12 sensitive-data types, 7 policy classes, and 14 red-team attack families across supply-chain, healthcare, and financial workflows. In this controlled benchmark, SENTINEL reduced unauthorized context exposure from 3.84% under ungoverned dense retrieval to 0.00% observed events (one-sided 95% CI upper bound 0.00025%, McNemar p < 0.001). It achieved 99.2% sensitive-data leakage recall and 97.4% precision, blocked 98.6% of prompt-injection exfiltration attempts, and added 38 ms p95 retrieval latency over a policy-free vector-search baseline. The results support retrieval-time governance as a measurable control for enterprise RAG systems evaluated under known policy labels and red-team attacks, not as evidence of regulatory certification or universal protection.
Keywords retrieval-augmented generation, enterprise RAG, data governance, privacy engineering, access control, prompt injection, auditability, policy-aware retrieval, red-team evaluation
Field Engineering
Published In Volume 17, Issue 1, January-June 2026
Published On 2026-06-25
DOI https://doi.org/10.71097/IJAIDR.v17.i1.2041

Share this