SovAIHub
ModulesSAI-230
SAI-230 table of contents
Concept1 min readPrototype

Controlled ingestion, lineage, and permissions

Preserve source identity, classification, ownership, permission, version, and transformation lineage.

Last content review 2026-08-03Included in SAI-230

Establish source authority

For every source, record owner, approved purpose, classification, authoritative location, permission model, retention and deletion rules, update frequency, and accountable contact. Acquisition should reject sources that lack an approved owner or purpose.

Preserve lineage

Assign stable identifiers to source objects and transformed outputs. Record source version, acquisition time, extractor and configuration, chunking and enrichment steps, embedding model, index version, failures, and destination. A retrieved chunk should resolve back to the exact source version and transformation path.

Permission lifecycle

Carry source authorization attributes or a reliable reference through chunking and indexing. Define reconciliation for membership changes, source permission updates, classification changes, deletion, and failed synchronization. Measure maximum staleness.

Never rely on a prompt to hide unauthorized content. Build the permitted candidate set before ranking, and apply the same rule to hybrid search, reranking, caches, previews, citations, and administrative interfaces.

Failure and quarantine

Quarantine malformed, encrypted, unsupported, unexpectedly sensitive, or policy-violating content. Do not silently index partial documents when the missing parts change meaning or permissions. Record rejection reason, owner notification, remediation, and reprocessing evidence.