Excellent point. I completely agreeauthorization, tenant isolation, and document lifecycle should never depend on model-derived filters. Those are hard server-side constraints and should always fail closed. I also like the idea of logging candidate counts after each hard filter. It makes debugging empty retrieval results much more transparent instead of leaving everyone guessing. Thanks for the valuable addition!