Suppose the same cancellation rule appears in a help article, a contract, a resolved ticket, and a message from a product manager. Which one may the chatbot use? The newest item is not necessarily authoritative. The contract may vary by plan. The ticket may record an exception rather than a policy. The message may explain a planned change that never shipped.
Each useful source needs an owner, audience, status, effective date, and update path. Where documents conflict, the system needs a deliberate rule or a person who can settle the answer. Where the evidence is weak, the chatbot should ask, cite, abstain, or escalate rather than smooth the uncertainty into confident prose.
For an enterprise assistant, identity belongs in the same design. The user signs in, current entitlements constrain retrieval, and restricted material never enters model context. Hiding a citation after generation is too late. The model has already seen the source.