Article chapter 06 of 08
Make generation cite, qualify and decline
The generation step should receive the user's question, authorised passages, source metadata and clear instructions about the answer contract. Prompt wording helps, but the surrounding application must enforce access and preserve the evidence used.
Ask the model to answer from the supplied passages and attach citations to the claims they support. Citations should be generated from source metadata controlled by the application rather than invented by the model. If the interface numbers passages, maintain a direct mapping from each number to the source identifier and location.
Tell the model what to do when sources conflict. It may present the conflicting statements with their dates and status, or prefer the source marked current by an approved metadata rule. It should not resolve an organisational disagreement by writing the most fluent compromise. Conflict detection can also create an item for the source owner to review.
Keep source text separate from system instructions. Retrieved documents can contain text that looks like a command, including instructions to ignore prior rules or expose other information. Treat document content as untrusted evidence. The model should use it to answer the question, while tool access, permissions and response policy remain controlled outside the retrieved text.
The answer should distinguish supported statements from useful explanation. If the product allows summarisation only, do not let the model add procedures from general knowledge. If general knowledge is allowed, label that boundary in the interface and avoid citations that make the extra material look sourced.
Specify the forms a decline can take: state that no relevant approved source was found, name the closest material, or ask for a missing qualifier that changes retrieval. Include unanswerable and underspecified questions in the evaluation set because a fluent answer can otherwise look acceptable.
Keep consequential actions outside the first answer path unless they have their own validation and approval. Retrieving a procedure and drafting a response is different from changing an account or sending advice. If an answer later triggers a tool, pass structured, validated fields into a separate action step with visible confirmation.
Display enough provenance for review: document title, applicable version or date, location and a route to open the permitted source. A citation that reads well but points to an inaccessible or superseded file does not help the user verify anything.