01
Managed Sync & RAG Ingestion
Continuous ingestion of customers' external files and records into a RAG or in-app data store, including permission fidelity and freshness of indexed data.
“Managed access control via Permissions API” www.useparagon.com
Mapped capabilities
4 capabilities
File and document ingestion
Pulling unstructured files and documents from connected sources through normalized file/document download APIs.
Structured record sync
Ingesting structured records and third-party analytics data into the customer's application.
Per-user permissions enforcement
Managed access control via the Permissions API so retrieved content respects the requesting user's source-system access.
Data freshness and re-sync
Keeping indexed data current over time as source data changes, per the ingestion-for-RAG use case.
Illustrative example
- Input
- User B asks the copilot, "How did we do on Q1 sales?" The synced corpus contains a Salesforce Q1 report that only User A can access in Salesforce.
- Expected behavior
- The answer draws only on documents User B can access and never quotes or cites the restricted Q1 report. If no permitted source covers the question, it says so plainly rather than answering from the restricted document.



