> Probably via a Zanzibar-based system ...
> ... a search index that respects access control
This is the exactly the part I want to understand. How are you modifying your search index, so that it respects the access control.
There are some ways I can think of, but want to learn more from others on how they are doing it:
* each object stores metadata of which access groups can access this data, at the search query time, first I fetch groups user belongs to and send it as part of search query
* fetch all matching objects and hope that list is not huge and for each item assess at run time if object can be accessed by this user, if not, remove from results
* ...
You either compute at query time, which might be costly or you pre-compute it at write time, but then you need to keep at least 2 data sources in sync objects (who can access can change on object level) and groups (group can get more permissions or less)