- 01
- Source attribution by default. Every internal answer carries a citation back to the document, the revision, and the paragraph it came from. No opt-out, no exceptions. The chain is unbroken from retrieval to UI to audit log.
- 02
- Two clearly separated modes. Internal knowledge intelligence (source-linked answers) and external drafting (AI-assisted, marked draft top-to-bottom, refused as citable fact downstream). Users always know which mode they are in.
- 03
- Five design controls govern every interaction. Access control, data classification, source awareness, human oversight, use-case separation. Each documented, each verifiable from the audit log.
- 04
- Hash-chained audit log. Every query, source match, draft, and approval written to an append-only log with a verifiable hash. Tampering becomes visible by construction; the chain is the same one a regulator would request.