Article chapter 06 of 08
Get the model to cite, qualify and decline
The generation step gets the user's question, the authorised passages, the source metadata and instructions about the answer contract. The application around the model, more than the prompt wording, enforces access and keeps track of the evidence used.
Ask the model to answer from the supplied passages and attach citations to the claims they support. Build the citations from source metadata the application controls, so the model isn't making them up, and if the interface numbers passages, keep a direct mapping from each number to the source identifier and location.
Tell the model what to do when sources conflict. It might show the conflicting statements with their dates and status, or prefer the source marked current under an approved metadata rule. What you don't want is the model settling an organisational disagreement with the most fluent compromise. Conflicts can also raise an item for the source owner.
Retrieved documents can contain text that looks like a command, including instructions to ignore earlier rules or expose other information. Keep source text separate from system instructions and treat it as untrusted evidence. The model uses it to answer, while tool access, permissions and response policy stay outside the retrieved text.
If the product only allows summarisation, don't let the model add procedures from general knowledge. If general knowledge is allowed, show that boundary in the interface and avoid citations that make the extra material look sourced.
Spell out what a decline looks like: no relevant approved source was found, here's the closest material, or a question asking for a missing qualifier that would change retrieval. Put unanswerable and underspecified questions in the evaluation set, because a fluent answer to them can look fine when it shouldn't.
Keep consequential actions out of the first answer path unless they've got their own validation and approval. Drafting a response from a procedure is a different job from changing an account or sending advice, so if an answer later triggers a tool, pass validated, structured fields into a separate action step with a visible confirmation.
Show enough provenance to review the answer: document title, version or date, location and a way to open the permitted source. A citation pointing at a file the user can't open, or one that's been superseded, doesn't help them check anything.