← Back to the start page

What may enter the context

Language models answer convincingly even from incomplete or outdated material. KritiGraph therefore does not rely on more context, but on controlled context.

Two questions that usually collapse into one

A conventional RAG system answers one question: what is relevant to this request? That is useful, and it stops being sufficient as soon as the material is confidential, regulated or tied to a point in time.

KritiGraph separates a second question and answers it in its own right: what is admissible here? Retrieval decides relevance, the governance layer decides admissibility. Only then does content reach a model.

Four knowledge sources — one of them is the model

KritiGraph distinguishes knowledge by the question of who owns it: domain knowledge, which belongs to no single organisation; organisation knowledge; and project knowledge, which stays within its case or mandate. The classification follows ownership, not subject matter — domain knowledge enriched with confidential internal information becomes organisation knowledge.

The fourth source is the language model itself. It provides linguistic ability and general reasoning, but it is not an authoritative source of knowledge: it receives only the knowledge the governance layer admits. That is why the model stays replaceable without the commitments changing.

From this follows a property that outlives technology changes: storage location does not establish authority. Who has authority over a piece of knowledge is stated explicitly and does not change because an index, a search method or a database changes.

Shared knowledge is referenced, not copied

A project may use a released knowledge artefact. It does not thereby gain the authority to reinterpret that artefact's identity, provenance or validity: the project-specific release governs use, it does not rewrite the artefact.

Without that separation, a local setting could change what shared knowledge states — and nobody would notice.

Provenance is part of the answer

Knowledge artefacts carry a stable identifier and a version. Retrieval and governance decisions carry references to the sources involved; governance decision records keep what was checked before the effect took place.

The aim is more than a footnote. A citation shows where a sentence appears. Provenance should additionally establish which source version was used, how it entered the operation and under which conditions it was admitted. The guiding question is: can it be reconstructed why this information was allowed to influence this answer?

The boundary belongs with it: evidenced provenance is not a statement about factual validity, currency or correctness. A document can be fully traceable and substantively outdated. Time is a separate question.

Merging does not lower a protection level

When content from several sources flows into one answer, an explicit rule applies: merging combines retrieved context, it does not alter governance decisions. The protection level of an answer is not lower than the highest source involved.

This closes the path along which confidentiality tiers otherwise disappear quietly in combining systems: through summarisation.

Reserved when in doubt

KritiGraph prefers an explicit “this cannot be evidenced here” over unevidenced certainty: no project authorisation means no access; unknown validity is not treated as established validity; insufficiently evidenced derived context is not promoted to evidence.

The purpose is not to refuse more often, but to make a successful answer mean more than “the model found plausible text”.

Several stores, one authority

KritiGraph uses different technologies for different workloads: knowledge graph, vector search, object storage, events, metadata. Several stores do not by themselves create a fragmented architecture.

It becomes critical only when each store invents its own identity, access semantics, classification and authority. KritiGraph keeps exactly those notions above the stores: unified context does not require a unified physical database.

Planned — not a product commitment

Temporal validity and context eligibility

Decided and in progress, not yet a product commitment: version and import date say which representation we used and when it entered the system — they do not say for which period a piece of content claims validity. The target is that validity is declared rather than inferred from file names or text passages, and that unknown validity does not count as unlimited validity.

For point-in-time questions — which rule applied on a given day — the architecture is decided and the implementation is outstanding. KritiGraph does not answer such questions with temporal assurance today.

The same line covers the eligibility of derived context: a prompt holds more than the sources that end up cited — summaries, relationships and conversation history as well. Filtering only the citations filters the wrong thing. Citation eligibility is not context eligibility; the decided direction is to exclude derived context rather than assume provenance that cannot be evidenced.

Current limitation

Current limitations

The knowledge graph surfaces connections that similarity search alone does not find. A relationship is only as reliable as the identity of its endpoints — and today that identity is an entity's normalised name. Identically named entries are therefore merged even when they mean different things. How identity and merging are to be determined is an open architecture question; it is carried as such, rather than settled incidentally in code.

Agentic working modes — multi-step follow-up and planning — are provided for within the control boundary, but switched off in live operation.

Claims on this topic

The following claims are projected onto this page from the machine-readable claim source; their current state is kept on the evidence page.

The kernel holds the access — not the model.

Product maturity: In operation · Details

Assurance status: Not yet connected to the central assurance matrix.

Every access is checked before it takes effect.

Product maturity: In operation · Details

Assurance status: Not yet connected to the central assurance matrix.

The provenance of the knowledge used is traceable.

Product maturity: Implemented · Details

Assurance status: Not yet connected to the central assurance matrix.

Knowledge stays separated — mandates do not intermix.

Product maturity: Implemented · Details

Assurance status: Not yet connected to the central assurance matrix.

Knowledge artefacts are content-immutable and tamper-resistant.

Product maturity: Implemented · Details

Assurance status: Not yet connected to the central assurance matrix.