Implement permission-aware search over fictional repositories and test denied access, source visibility and role changes.
Access control for coding assistants
Build permission-aware search, or study how developers understand what an AI assistant can access.

Choose your track
Your choice is remembered in this browser.
The lists below describe what your thesis may include. Agree a feasible selection for one track, rather than completing both.
Choose one track. Master’s proposals target Spring 2027. Final scope and programme approval are agreed with the supervisor; bachelor scopes are suggested adaptations.
Technical track
Develop a working solution and test whether it addresses the problem.
How can repository-aware access controls preserve useful AI assistance while preventing cross-project information leakage?
Suggested tasks
- Read research on permission boundaries for coding assistants and compare existing solutions.
- Identify one problem faced by developers and information owners.
- Write a research question and define what the solution should do.
- Create a few fictional repositories and define which roles can read each part.
- Build an assistant that checks permissions before retrieving information and shows the sources used in an answer.
- Compare it with a simple repository-level access filter. Test information leaks, correct answers and how clearly users understand access limits.
- Explain what worked, what did not, and how the results compare with earlier research.
Evaluation, degree scope and deliverables
Study and evaluation
Compare the implemented solution with an otherwise identical assistant with a simple repository-level filter. Combine reproducible technical tests with an appropriate empirical evaluation.
- Cross-boundary leakage in adversarial tests
- Task usefulness on permitted information
- Users’ understanding of access restrictions
Degree scope
Evaluate retrieval and generation boundaries under adversarial prompts, alongside usefulness and developer understanding.
Background
- Programming
- Access control and retrieval
- Basic secure-development practices
Possible deliverables
- A focused literature review, justified problem and research question
- A working prototype with source code and setup instructions
- A reproducible comparison and an appropriate study of use
- A report explaining design lessons, results and limitations
Non-technical track
Study existing systems, information or work practices. You do not need to develop software.
How do developers and information owners understand and govern coding assistants’ access across repositories?
Suggested tasks
- Read earlier studies of permission boundaries for coding assistants.
- Choose one problem and write a research question the study can answer.
- Review access policies and documentation for a small authorised or fictional multi-project setting.
- Use interviews or scenario tasks to examine expectations about permitted sources and derived answers.
- Analyse mismatches between policy, user mental models and everyday development practices.
- Analyse the interviews, observations or documents using a clearly described method. Look for disagreements as well as common patterns.
- Explain the findings, compare them with earlier research and suggest practical improvements.
Evaluation, degree scope and deliverables
Study and evaluation
Use a bounded empirical study of permission boundaries for coding assistants. Justify case selection, recruitment and the analysis method. Distinguish observed behaviour from participants’ perceptions; use triangulation or a comparison where it serves the research question.
- Understanding of access restrictions and information ownership
- Governance gaps, trust and perceived usefulness
- Evidence for the findings, conflicting cases and limits of the study
Degree scope
Study one case or a small set of existing materials. Agree the interviews, documents or scenario tasks with the supervisor. Describe the method, analyse the findings and give practical recommendations.
Use a clear research question and relevant IS theory. Justify the cases, participants and analysis method. Explain what the findings add to earlier research and where they may apply. No software development is required.
Background
- Literature review and academic writing
- Qualitative or quantitative research methods
- Interest in permission boundaries for coding assistants; no programming prerequisite
Possible deliverables
- A literature review and research question
- A study plan and approved research material
- An analysis supported by interviews, observations, documents or scenario results
- A thesis with findings, recommendations and limitations
Scope and access
Use synthetic repositories with planted test secrets, never real credentials. Enforce permissions before retrieval and test caches and derived answers as well as source files. These implementation-related limits apply when developing or testing a technical solution. For a non-technical study, agree access to participants or existing materials early, use approved or fictional cases where appropriate, and distinguish perceptions from observed outcomes.
Agree access to data, participants or existing materials and any required ethics or privacy review before committing. A non-technical track needs a systematic study, not a working prototype.
Full academic proposal
Working topic
Permission-Aware AI Assistance Across Software Repositories
Brief outline
This proposal examines permission boundaries for coding assistants in the work and information needs of developers and information owners. The technical track combines a literature review and justified gap with requirements, design, implementation and evaluation of a bounded solution. The non-technical track investigates practices, experiences or organisational conditions through a systematic study of existing systems, documents or scenarios, without requiring implementation. Choose one track and agree the final research question, degree scope and contribution with the supervisor.
Programme fit
Information Systems. These are suggested research approaches, not a statement of confirmed programme policy. Agree the final title, track, degree scope and contribution with the supervisor and programme.
Shared research foundation
Review the literature; identify and justify a gap; formulate research questions; conduct a systematic study; analyse the evidence; explain the contribution relative to prior research and discuss limitations. The technical track additionally includes requirements, design, implementation and evaluation of an artifact.


