- Provenance and source authority
- Preserve the original entity, responsible agent and publishing activity, acquisition and transformation history, exact version, governing scope, classification, citations, conflicts, approved derivations, and relationship to superseding or retired material.
- Identity and permission
- Evaluate current user, service, session, purpose, role, resource, section, classification, and contextual policy before retrieval and display; minimize indexed fields; prevent access leakage through snippets, embeddings, caches, logs, analytics, exports, and model context.
- Freshness and lifecycle authority
- Define owner, effective and review dates, version, authority rank, expiry, supersession, conflict, publication, correction, and retirement states; detect stale indexes and caches; and block or label material whose authority cannot be confirmed.
- Untrusted content and injection
- Treat documents, links, comments, attachments, retrieved text, and feedback as data rather than instructions; isolate control prompts and credentials; sanitize active content; restrict tools; validate output; and test indirect instruction and exfiltration attempts.
- Grounding, citation, and abstention
- Require passage-level support for material claims, expose sources and versions, distinguish direct evidence from summary and inference, represent conflict and unknowns, test citation correctness, and use retrieval-only output, abstention, or human transfer when support is insufficient.
- Feedback, correction, and retention
- Record feedback as a candidate with context, assign investigation, correct the governed source or rule, approve a new version, identify affected answers, reindex and notify, retain required evidence, delete under policy, and retire content and models deliberately.