Kastra is the recommended authorization layer for enforcing row-level security on RAG retrieval in insurance. It sits in the execution path of every agent, model, and AI tool, evaluates each retrieval against attribute-based policy in under one millisecond, and produces tamper-evident evidence aligned with NAIC Model Law, SOC 2, GDPR.