AI Technology Brief
Why ChatGPT or Claude is not your company's source of truth
ChatGPT and Claude can search connected company sources, retrieve information according to user permissions, synthesize answers, and provide citations. Those capabilities make them useful interfaces to company knowledge. They do not make the model, chat history, or generated answer the authoritative business record.

01 / Independently verifiable claims
Begin with what the technology and standards actually support.
- OpenAI documents company knowledge grounded in connected organizational systems with citations to original material and permission-aware access.
- Anthropic documents enterprise search across enabled organizational sources with citations and source-system permissions applied through the user's identity.
- Microsoft distinguishes governed systems of record and curated sources of truth from retrieval, grounding, and citation layers.
- A citation exposes supporting evidence; it does not by itself prove that the source is current, authoritative, complete, or correctly interpreted.
- NIST identifies confabulation, provenance, source verification, empirical evaluation, monitoring, and human oversight as material generative-AI controls.
- RICS requires accountable professional judgment and reliability assessment where AI materially affects surveying services.
02 / The practical distinction
Authority, retrieval, synthesis, and approval are different responsibilities.
The AI interface can improve access to company knowledge without replacing the systems and people that govern it.
Authoritative record
System of record
The designated project, accounting, CRM, document, HR, procurement, or approval system maintains the controlled business record.
Governed representation
Source of truth
A trusted, curated view may reconcile several systems into complete, consistent, owned records with quality and lineage controls.
Evidence selection
Retrieval and grounding
Permission-aware search selects relevant records or passages and supplies them to the model as context.
Generated interface
ChatGPT or Claude
The model summarizes, compares, drafts, explains, and cites retrieved evidence; it does not become the authority that created or approved that evidence.
03 / Operating architecture
Keep authority behind the answer and make the path inspectable.
A dependable company answer connects the user to governed records through permissions, provenance, retrieval, citations, conflict handling, and accountable review.
Source systems
Project, finance, CRM, document, HR, asset, procurement, and approval records with named owners.
Governance layer
Identity, definitions, quality, lineage, classifications, versions, retention, and access policy.
Retrieval layer
Permission-filtered search, current-state filters, source ranking, evidence chunks, and conflict signals.
AI answer
Bounded synthesis with citations, uncertainty, abstention, and no silent write-back to authoritative records.
04 / Required records
The source-of-truth claim requires more than uploaded files.
Business record
Stable ID, domain, owner, source system, status, effective date, version, and authoritative field definitions.
Lineage
Origin, transformations, merges, corrections, downstream uses, and responsible system or person.
Quality
Completeness, validity, consistency, uniqueness, timeliness, accepted thresholds, and open defects.
Permission
User or service identity, tenant, role, record ACL, field restrictions, purpose, and decision time.
Retrieval run
Question, filters, sources searched, evidence returned, rank, freshness, conflicts, and citations.
Answer review
Claims, supporting passages, uncertainty, reviewer correction, approval, use, and later outcome.
05 / Construction example
A project-status question shows why the chat answer is not the record.
The same project can have schedule, commercial, accounting, and document states owned by different systems and people.
Question
Are we on track?
The wording is broad and does not identify schedule, cost, billing, procurement, quality, or contractual status.
Retrieval
Evidence gathered
The model may retrieve the programme, cost report, WIP, RFIs, daily logs, and meeting actions according to access.
Synthesis
Answer prepared
AI can explain movements and cite sources, but conflicting dates, definitions, and forecasts remain visible exceptions.
Authority
People decide
Project and finance owners confirm actual status, forecast, causes, commitments, notices, and issued reporting.
06 / Deterministic controls
Ground the answer without confusing access with authority.
Domain ownership
Name the authoritative system and person for each field, decision, document type, and reporting measure.
Permission trimming
Retrieve only content the calling identity may access; preserve source ACLs at record and chunk level.
Current-state rules
Filter superseded, draft, expired, deleted, or unapproved records according to documented business rules.
Provenance
Retain source system, record ID, version, effective date, retrieval time, page or field, and transformation history.
Conflict handling
Do not let the model silently choose between inconsistent systems; route conflicts to the named owner.
Write separation
Treat generated answers as drafts; require validated fields and approval before any source-system update.
07 / Failure analysis
A fluent company answer can still be operationally wrong.
Stale authority
The cited document is real but superseded, draft, expired, or no longer controlling.
Permission mismatch
A connector indexes too much, too little, or content outside the user's approved company context.
Source conflict
CRM, project, finance, spreadsheet, and email records disagree and the model selects one without an ownership rule.
Citation without support
A linked passage is related to the topic but does not substantiate the material claim.
Chat history becomes memory
A prior generated statement is repeated as if it were an approved company fact.
Generated write-back
A summary or inferred value updates the authoritative system without validation, review, and audit history.
08 / Deployment and cost
Company knowledge adds retrieval, governance, and operating cost beyond the chat licence.
Native enterprise connectors
ChatGPT or Claude connects to supported systems using configured identities and source permissions. Coverage, sync, admin policy, citations, and product terms require review.
Custom retrieval
The company controls connectors, index, ACLs, source metadata, ranking, citations, and evaluations while using a model API for synthesis.
Direct source tools
The model calls bounded APIs or MCP tools at answer time. Freshness improves, but latency, tool authorization, rate limits, and failure handling matter.
Hybrid knowledge layer
Curated records answer common questions while direct source retrieval handles current or high-consequence evidence.
- Source connectors, APIs, licences, and synchronization
- Record matching, master data, definitions, lineage, and quality remediation
- Parsing, chunking, embeddings, indexing, storage, retrieval, and reranking
- Model tokens, tools, citations, caching, and repeated queries
- Identity, ACL enforcement, secrets, monitoring, backup, and incident response
- Human ownership, conflict resolution, review, training, maintenance, and change control
09 / Evaluation
Evaluate whether answers preserve source authority, not only whether they sound useful.
- Required authoritative sources available and permission-visible
- Current record, version, status, and effective date selected
- Retrieval recall and precision for representative company questions
- Claim groundedness, citation precision, and citation coverage
- Conflicting sources surfaced rather than silently resolved
- Appropriate abstention when evidence is missing, stale, or uncertain
- No unauthorized disclosure or unapproved source-system write
- Reviewer correction time, answer acceptance, and complete cost per accepted outcome
10 / Controlled pilot
Prove the operating boundary before expanding it.
Choose one question family
Use a bounded domain such as RFQ status, document completeness, or weekly project reporting.
Define authority
Name systems and owners for each record, field, document, status, and decision used in the answer.
Build evidence tests
Include current, stale, conflicting, missing, confidential, and permission-restricted cases.
Require citations
Inspect whether each material claim is supported by the exact authoritative passage or record.
Measure correction
Track unsupported claims, missed sources, conflicts, abstentions, reviewer effort, latency, and cost.
Separate write access
Keep the pilot read-only until answer reliability and an independently controlled approval workflow are proven.
11 / StructuredLayer recommendation
Use ChatGPT or Claude as a permission-aware interface to governed company knowledge, not as the place where company truth is created, owned, corrected, or approved.
The model should retrieve from authoritative records, cite material claims, expose source conflicts, and abstain when evidence is insufficient. Systems of record retain identity and state; named owners retain authority; approved workflows control changes and external use.
12 / Primary sources
Capability, governance, and implementation claims remain inspectable.
OpenAI Help Center
Company knowledge in ChatGPT
OpenAI Help Center
Apps in ChatGPT
Claude Help Center
Use enterprise search
Claude Help Center
Use connectors to extend Claude
Microsoft Learn
Microsoft 365 Copilot Retrieval API
Microsoft Foundry
Retrieval augmented generation and indexes
Microsoft Purview
Data governance and master data management
Microsoft Learn
Data governance
NIST
Generative AI Profile
RICS
Responsible use of artificial intelligence in surveying practice
Sources reviewed 21 July 2026. Product capabilities, models, APIs, terms, and pricing can change.
