Operational system · isolated synthetic corpus · no client-result claim
Source-Backed Answer Desk
Give a customer or teammate an answer they can inspect—or review a short bilingual voice transcript before the same source contract decides whether to answer or hand off.
- Outcome
- Cited answer or explicit boundary
- Retrieval
- Tour: lexical · Operations: governed policy
- Input channels
- Guided · typed · optional voice
- Last reviewed
Isolated public tour / 01
Ask one policy question. Inspect every released claim.
Use fictional questions only. Do not enter names, addresses, account details, medical information, credentials, or real customer content.
Optional input channel / Integrated capability
Bilingual Voice Intake
Review the transcript and language before they become the Answer Desk question. The visible answer and evidence stay primary; speech is a separate final action.
Open optional channelClose optional channel+
Optional input channel / Integrated capability
Bilingual Voice Intake
Fixture first. Microphone only on request.
Starts only after this button is pressed, records for at most 15 seconds, and sends the stopped clip for transcription.
Choose a guided transcript, use the microphone, or continue with the typed Answer Desk.
Correct the words and confirm the language.
This channel may retrieve approved general information. It does not decide eligibility, emergencies, diagnosis, legal or financial matters, pricing, availability, booking, or commitments; those stop at a fixed person-led escalation.
Voice run diagnostics
- Capture
- Not started
- Transcription
- Not started
- Source retrieval
- Not started
- Spoken output
- Not requested
- Input origin
- Not selected
- Provider mode
- Fixture ready · public-tour provider not invoked
- Audio duration
- Not available
- Cost / tokens
- Not applicable in the isolated public tour
- Policy version
Loading
Guided questions
Choose the boundary you want to inspect.
Ask a bounded fictional question
Ready. Choose a guided question or enter bounded fictional text.
- Tour mode
- Deterministic lexical
- Language
- Not selected
- Accepted sources
- 0
- Rejected sources
- 0
- Public-tour memory
- Page state only · standalone request
Question + release decision
Answer
No question has been submitted.
Release state
Waiting for a question
A supported answer or a clear abstention will appear here.
Optional output channel
Speak only the approved text already visible.
The one-use permission expires after two minutes and is bound on the server to the exact visible answer above. No arbitrary text is accepted and playback never starts automatically.
Spoken output has not been requested.
No question or contact detail is sent by this demo action.
Technical retrieval trace
- Trace ID
Not created- Retrieval method
- Deterministic lexical sections
- Config version
- Not loaded
- Source IDs
- None
- Latency
- Not measured
- Token usage
- Unavailable in fixture mode
- Boundary reason
- Not applicable
- Question retention
- Not persisted · current page state only · trace uses a one-way fingerprint
Portfolio evidence ledger
Evidence, production controls, and release assurance.
Isolated public tour · fictional or synthetic data · operational controls verified separately.
- Exact role
- Designed and implemented the bilingual source-governance contract, immutable workspace registry, claim-level citation validation, deterministic abstention states, encrypted conversation and handoff records, reviewed voice-input channel, technical trace, signed delivery, and reproducible evaluation harness.
- Human boundary
- A person resolves missing, stale, conflicting, sensitive, pricing, availability, emergency, or otherwise unsupported material. Voice transcripts must be reviewed before retrieval, and speech can repeat only the approved text already visible on screen.
Evidence in the build
- Answer release
- Claim-level support requiredA positive answer is replaced by a deterministic abstention if any material claim lacks a valid current citation.
- Source governance
- Visible owner, version and statusThe source inspector exposes the metadata needed to understand why a passage can or cannot support an answer.
- Retrieval method
- Governed retrieval policyThe public tour is deterministic lexical retrieval; operational configuration can require a hybrid ranker and fails closed if it is unavailable.
- Memory boundary
- Encrypted operational threadsBounded subject history survives restart but remains separate from evidence; the public tour reads no operational conversation.
- Voice boundary
- Review before retrievalA recorded question does not enter the source contract until the transcript and language are visible and correctable.
- Commercial result
- Not claimedSynthetic-corpus evaluation results describe the test environment only, not customer, support, revenue, or labor outcomes.
Tests actually run
- 44/44Pinned Answer Desk evaluation
All five release gates passed with zero case failures and no external provider call.
- 287/287Final Voice-integration unit suite
Completed on the final Task 04 tree containing the parent Answer Desk.
- 20/20Dedicated voice browser scenarios
Covered the optional reviewed bilingual voice-input channel.
- 12/12Parent Answer Desk browser scenarios
Covered supported and fail-closed answers, evidence inspection, recovery, accessibility, and reflow.
- 27/27Migration, project, and adjacent regressions
Completed alongside the final Voice integration gate.
Production controls implemented
- An authenticated workspace registry stores encrypted source payloads as immutable versions, authenticates its event chain, and permits answers only from current, approved, same-language policy.
- Encrypted subject-scoped threads preserve bounded conversation continuity across restart; every audit event is HMAC chained and verified before history is returned.
- An external ranker receives only a frozen encrypted corpus snapshot reserved before the request, with a stable provider ID, a hard deadline, approved region and zero-retention policy, and fail-closed recovery.
- Unsupported, partial, conflicting, or expired evidence creates a durable staff handoff with role checks, audit events, retention, and signed idempotent delivery.
- Voice intake stores no raw audio, holds every transcript for explicit review or correction, and permits speech only as a separate user action after a supported answer is visible.
- Workspace isolation, salted role credentials, private database files, source-version citations, deletion, generation-consistent backup, and fail-closed provider behavior are enforced in the service layer.
Enforced production activation gates
- Operational answers require an owner-approved bilingual corpus, authenticated staff roles, source review dates, and an approved human-handoff destination.
- The fictional public tour remains isolated from account history, operational sources, staff queues, credentials, and live downstream effects.
- Voice and external ranking activate only when provider region, privacy handling, zero-content-retention, no-training, recording, and timeout approvals match the validated workspace configuration.
Outcome + use case / 02
The useful answer is the one the team can defend.
Buyer
A U.S. home or property service operator whose staff and customers ask the same service, coverage, hours, appointment, warranty, safety, and privacy questions in English and Spanish.
Controlled outcome
Current policy becomes a short cited answer. Missing, stale, conflicting, hostile, or wrong-language evidence becomes a durable review-queue handoff instead of an improvised promise.
Evidence + source governance / 03
A small corpus with an owner, a date, and a stopping rule.
May support a claim only in the requested language, with its exact visible excerpt.
May appear in the inspector as rejected evidence, but cannot support a positive answer.
Two disagreeing current policies stop release until their owner resolves the source-of-truth decision.
Retrieved text remains untrusted data. Instruction-like source content is rejected, never followed.
Measured evaluation / 04
Release claims come from the pinned test set—not a confidence score.
Measured July 20, 2026 with deterministic fixtures; no external provider calls. The report is generated from the pinned task-specific dataset.
- Dataset
- 44 cases
- Supported pass rate
- 100%
- Abstention correctness
- 100%
- Claim citation coverage
- 100%
- Citation validity
- 100%
- Language-parity failures
- 0
- Local latency p50 / p95
- 0.08 / 1.75 ms
Reproduction record
- Evaluation clock
2026-07-20T12:00:00.000Z- Answer config
source-backed-answer-contract.v1- Dataset SHA-256
88c2c709973ea448f5a582a51833b54479d64dc863bb4d36decb14a9a9d89595- Corpus SHA-256
006a05c0719fdd7efec9b9ccb88d680537b166baaf717a596d3b22da0b148109
- These metrics cover the pinned synthetic corpus and deterministic provider fixtures; customer-specific acceptance uses its own approved corpus and questions.
- The latency value is local contract-evaluation time; deployed latency is recorded by the operational monitoring path.
- Authorization, retention, durable audit, and reviewer operations are verified by the operational service suite rather than counted in this fixture metric.
Architecture + operating controls / 05
The source contract stays in front of the provider boundary.
- 01
Authenticate + validate
Bind the request to one workspace and subject, then enforce the bounded bilingual question contract.
- 02
Select
Search only the immutable approved corpus snapshot with the configured lexical or hybrid retrieval policy.
- 03
Govern
Reject draft, superseded, expired, conflicting, hostile, or wrong-language material before answer assembly.
- 04
Support + remember
Require current source citations for every material claim and keep encrypted thread history separate from evidence.
- 05
Release or hand off
Persist the cited answer or create an authenticated, auditable, idempotent person-led handoff.
Map the approved-answer boundary
Find the question your current sources cannot safely answer.
Start with the policy gap, source owner, and human handoff before choosing a retrieval or model provider.
Get a 3-point lead-flow review