← All thesis proposals
AI & software · S7 · Spring 2027

Access control for coding assistants

Build permission-aware search, or study how developers understand what an AI assistant can access.

Bachelor’sMaster’sProposal
Download brief ↓
Software-development information-system concept: An assistant that knows its boundaries
Concept illustration · AI-generated
ONE TOPIC. TWO POSSIBLE APPROACHES.

Choose your track

Your choice is remembered in this browser.

The lists below describe what your thesis may include. Agree a feasible selection for one track, rather than completing both.

Choose one track. Master’s proposals target Spring 2027. Final scope and programme approval are agreed with the supervisor; bachelor scopes are suggested adaptations.

TRACK 01 · IMPLEMENTATION INCLUDED

Technical track

Develop a working solution and test whether it addresses the problem.

Possible research question

How can repository-aware access controls preserve useful AI assistance while preventing cross-project information leakage?

Suggested tasks

  • Read research on permission boundaries for coding assistants and compare existing solutions.
  • Identify one problem faced by developers and information owners.
  • Write a research question and define what the solution should do.
  • Create a few fictional repositories and define which roles can read each part.
  • Build an assistant that checks permissions before retrieving information and shows the sources used in an answer.
  • Compare it with a simple repository-level access filter. Test information leaks, correct answers and how clearly users understand access limits.
  • Explain what worked, what did not, and how the results compare with earlier research.
Evaluation, degree scope and deliverables

Study and evaluation

Compare the implemented solution with an otherwise identical assistant with a simple repository-level filter. Combine reproducible technical tests with an appropriate empirical evaluation.

  • Cross-boundary leakage in adversarial tests
  • Task usefulness on permitted information
  • Users’ understanding of access restrictions

Degree scope

Bachelor’s

Implement permission-aware search over fictional repositories and test denied access, source visibility and role changes.

Master’s

Evaluate retrieval and generation boundaries under adversarial prompts, alongside usefulness and developer understanding.

Background

  • Programming
  • Access control and retrieval
  • Basic secure-development practices

Possible deliverables

  • A focused literature review, justified problem and research question
  • A working prototype with source code and setup instructions
  • A reproducible comparison and an appropriate study of use
  • A report explaining design lessons, results and limitations
TRACK 02 · NO IMPLEMENTATION REQUIRED

Non-technical track

Study existing systems, information or work practices. You do not need to develop software.

Possible research question

How do developers and information owners understand and govern coding assistants’ access across repositories?

Suggested tasks

  • Read earlier studies of permission boundaries for coding assistants.
  • Choose one problem and write a research question the study can answer.
  • Review access policies and documentation for a small authorised or fictional multi-project setting.
  • Use interviews or scenario tasks to examine expectations about permitted sources and derived answers.
  • Analyse mismatches between policy, user mental models and everyday development practices.
  • Analyse the interviews, observations or documents using a clearly described method. Look for disagreements as well as common patterns.
  • Explain the findings, compare them with earlier research and suggest practical improvements.
Evaluation, degree scope and deliverables

Study and evaluation

Use a bounded empirical study of permission boundaries for coding assistants. Justify case selection, recruitment and the analysis method. Distinguish observed behaviour from participants’ perceptions; use triangulation or a comparison where it serves the research question.

  • Understanding of access restrictions and information ownership
  • Governance gaps, trust and perceived usefulness
  • Evidence for the findings, conflicting cases and limits of the study

Degree scope

Bachelor’s

Study one case or a small set of existing materials. Agree the interviews, documents or scenario tasks with the supervisor. Describe the method, analyse the findings and give practical recommendations.

Master’s

Use a clear research question and relevant IS theory. Justify the cases, participants and analysis method. Explain what the findings add to earlier research and where they may apply. No software development is required.

Background

  • Literature review and academic writing
  • Qualitative or quantitative research methods
  • Interest in permission boundaries for coding assistants; no programming prerequisite

Possible deliverables

  • A literature review and research question
  • A study plan and approved research material
  • An analysis supported by interviews, observations, documents or scenario results
  • A thesis with findings, recommendations and limitations

Scope and access

Use synthetic repositories with planted test secrets, never real credentials. Enforce permissions before retrieval and test caches and derived answers as well as source files. These implementation-related limits apply when developing or testing a technical solution. For a non-technical study, agree access to participants or existing materials early, use approved or fictional cases where appropriate, and distinguish perceptions from observed outcomes.

Agree access to data, participants or existing materials and any required ethics or privacy review before committing. A non-technical track needs a systematic study, not a working prototype.

Full academic proposal

Working topic

Permission-Aware AI Assistance Across Software Repositories

Brief outline

This proposal examines permission boundaries for coding assistants in the work and information needs of developers and information owners. The technical track combines a literature review and justified gap with requirements, design, implementation and evaluation of a bounded solution. The non-technical track investigates practices, experiences or organisational conditions through a systematic study of existing systems, documents or scenarios, without requiring implementation. Choose one track and agree the final research question, degree scope and contribution with the supervisor.

Programme fit

Information Systems. These are suggested research approaches, not a statement of confirmed programme policy. Agree the final title, track, degree scope and contribution with the supervisor and programme.

Shared research foundation

Review the literature; identify and justify a gap; formulate research questions; conduct a systematic study; analyse the evidence; explain the contribution relative to prior research and discuss limitations. The technical track additionally includes requirements, design, implementation and evaluation of an artifact.