when considering wiring up an LLM to your app for consumer use, you should imagine the LLM is actually a hacker and restrict access to data access as you would for the human villain - there's no difference

In this case, the human had valid access to the data.