Controlled ingestion, lineage, and permissions
Preserve source identity, classification, ownership, permission, version, and transformation lineage.
Establish source authority
For every source, record owner, approved purpose, classification, authoritative location, permission model, retention and deletion rules, update frequency, and accountable contact. Acquisition should reject sources that lack an approved owner or purpose.
Preserve lineage
Assign stable identifiers to source objects and transformed outputs. Record source version, acquisition time, extractor and configuration, chunking and enrichment steps, embedding model, index version, failures, and destination. A retrieved chunk should resolve back to the exact source version and transformation path.
Permission lifecycle
Carry source authorization attributes or a reliable reference through chunking and indexing. Define reconciliation for membership changes, source permission updates, classification changes, deletion, and failed synchronization. Measure maximum staleness.
Never rely on a prompt to hide unauthorized content. Build the permitted candidate set before ranking, and apply the same rule to hybrid search, reranking, caches, previews, citations, and administrative interfaces.
Failure and quarantine
Quarantine malformed, encrypted, unsupported, unexpectedly sensitive, or policy-violating content. Do not silently index partial documents when the missing parts change meaning or permissions. Record rejection reason, owner notification, remediation, and reprocessing evidence.