01Question, identity, purpose, and audience
Bind each request to the current tenant, user or service identity, role, purpose, session, device, requested audience and permitted action; clarify ambiguous scope; and reject identity, delegation or purpose that cannot be verified.
Required evidence: Tenant, subject and service identity, authentication context, role and attributes, team, purpose, session, device posture where applicable, delegated scope, requested audience, question text, clarification, sensitivity candidate, action class, policy decision, denial reason and expiry.
02Source authority, permission, and currency
Inventory approved sources with owner, classification, access policy, authoritative scope, version and effective period; enforce source-native and system policy at retrieval; track change, supersession and invalidation; and distinguish technical recency from business validity.
Required evidence: Repository and object identifiers, owner, source type, authoritative question class, classification, access-control version, source-native decision, version, digest, author, created, modified, effective, reviewed, indexed, expired, superseded and invalidated times, retention state and coverage gap.
03Retrieval, claims, citations, and uncertainty
Retrieve a minimum permission-safe evidence set; preserve exact locations and structured values; separate source text from transformation and synthesis; test supporting and contradicting evidence; and produce claim-level citations, qualifications, refusals or named gaps.
Required evidence: Query and filter, corpus snapshot, retrieval and reranking versions, source passage, page, cell, row, field or time range, exact quote digest, claim identifier, derivation, deterministic transform, support and contradiction links, uncertainty, missing source, refusal, citation display and answer version.
04Review, release, feedback, and correction
Route consequential interpretation, source conflict and sensitive aggregation to qualified owners; recheck identity, permission and source state before release; collect evidence-specific feedback; and propagate corrections, revocation, deletion and supersession without rewriting history.
Required evidence: Review trigger, reviewer role and scope, cited evidence, decision and rationale, permission recheck, source-state recheck, approved audience, release receipt, user challenge, issue class, correction, source-owner response, affected answers, withdrawal, supersession, deletion handling and incident record.