Design authority and exception paths
Decide what a system may complete, what a person must decide, and how uncertain work reaches the right owner.
A retrieval system needs more than relevant passages and a fluent answer. It must show what supports each material claim, recognize when the available evidence is weak or unavailable, and route decisions it cannot own.
Separate source retrieval, answer generation, and decision authority. Support material claims with passages the user may access, and treat weak retrieval, conflict, stale sources, missing permission, and questions outside the corpus as explicit operating states. Qualify, clarify, route, or refuse when the evidence does not support an answer.
Retrieval can locate relevant text without establishing that the text answers the question. Generation can turn retrieved material into a clear response without gaining authority to decide what the organization should do. Treating these steps as one capability hides where uncertainty entered the result.
A useful retrieval system makes its evidence boundary visible. It knows which sources were searched, which passages were available to this user, how current they are, whether they conflict, and which claims they support. When that record is insufficient, the operating response changes.
Published Reviewed
Retrieval selects candidate material from an approved corpus. Generation interprets or summarizes that material. Decision authority belongs to a stated role or system outside the answer unless the workflow grants a precise action. Evaluate and log the three layers separately so a fluent response cannot conceal weak retrieval or unauthorized judgment.
Define the answerable boundary in plain terms. Name the corpus, question types, user roles, and actions supported by the system. A policy search tool may explain published policy while routing exceptions to a policy owner. A procedure assistant may assemble steps while leaving approval with the person responsible for the operation.
Use claim-level support where an incorrect statement could change a decision, action, or understanding of policy. The citation should resolve to the actual passage and source version used, not merely a document title or search result. A user must be able to inspect why the claim was made.
Test entailment rather than citation presence. A nearby paragraph may discuss the topic without supporting the stated conclusion. Preserve source title, location, version or effective date, retrieval time where relevant, and access path. If the source changes, the record should still identify what informed the earlier answer.
Weak retrieval may come from no relevant passage, a low-quality match, incomplete indexing, an ambiguous question, or a corpus that does not cover the subject. Ask for clarification when context would change the search. Refuse or route when the corpus cannot support the answer. Do not fill the gap from unapproved general knowledge.
When sources conflict, show the disagreement and use stated source authority or effective dates if the operation has them. Otherwise route the question to the source owner. Treat stale material similarly: a dated source can still be useful, but the answer must state the time boundary and avoid presenting it as current policy.
Apply access rules before candidate passages enter the answer context. Filtering only the final text can still expose restricted facts through summaries, citations, titles, snippets, or the existence of a document. Retrieval logs and evaluation sets need the same boundary as the sources they contain.
Missing permission is an operating state, not proof that no answer exists. Tell the user that the system cannot access the required source without naming restricted material. Route access requests or subject-matter questions through an approved owner, and record attempts that may indicate a misconfigured role or corpus.
Build an evaluation set with answerable, ambiguous, conflicting, inaccessible, stale, and deliberately unanswerable questions. Check retrieved passages, citation entailment, permission behavior, chosen response mode, and any escalation packet. A polished answer is a failure when the correct action was to clarify or refuse.
Record which component, source version, retrieval configuration, prompt, and access role produced the result. Assign owners for corpus quality, permissions, answer behavior, and unresolved questions. Those records support controlled changes and help operators distinguish a source problem from retrieval, generation, or authority failure.
| Option | Fits when | Caution |
|---|---|---|
| Answer | Accessible, current passages directly support the material claims. | Keep citations attached to the passage and version used. |
| Answer with qualification | Useful evidence exists but scope, freshness, or conflict limits the conclusion. | State the limit beside the affected claim, not in a generic disclaimer. |
| Ask for clarification | The question has multiple plausible meanings or lacks required context. | Ask for the smallest detail that changes retrieval or authority. |
| Route to owner | An accountable person must resolve source conflict, policy interpretation, or a decision. | Include the question, retrieved evidence, conflict, and missing decision. |
| Refuse | The request is outside the corpus, prohibited, inaccessible, or unsupported by usable evidence. | Explain the boundary and provide a human route when one is authorized. |
Use these checks before an internal answer system becomes a trusted route to policy, procedure, or operating knowledge.
The approved corpus, supported questions, user roles, and authority boundary are stated.
Retrieval, answer generation, and downstream decisions are evaluated separately.
Material claims resolve to the supporting passage and source version.
Citation tests check entailment, not the presence of a related document.
Weak retrieval can clarify, qualify, route, or refuse without inventing support.
Conflicting and stale sources preserve their differences and time boundaries.
Permission checks occur before passages, metadata, or snippets enter answer context.
Outside-corpus questions have a clear response and an approved human route.
The evaluation set includes answerable, ambiguous, conflicting, inaccessible, and unanswerable cases.
Corpus, permission, retrieval, generation, and escalation responsibilities have owners.
A retrieval system becomes more useful when operators can distinguish a supported answer from a qualified interpretation, an unresolved conflict, a permission boundary, or a question the corpus cannot answer. Each state needs a visible response rather than a change in tone alone.
Keep citations inspectable and escalation usable. When the system cannot support a claim or own a decision, the safest useful action is to preserve the evidence, state the limit, and send the question to the person who can resolve it.
Reference record
A short description of the workflow, system, or operating condition is enough to begin.