Operational system · isolated synthetic corpus · no client-result claim

Source-Backed Answer Desk

Give a customer or teammate an answer they can inspect—or review a short bilingual voice transcript before the same source contract decides whether to answer or hand off.

Inspect source governance
Outcome
Cited answer or explicit boundary
Retrieval
Tour: lexical · Operations: governed policy
Input channels
Guided · typed · optional voice
Last reviewed

Ask one policy question. Inspect every released claim.

Use fictional questions only. Do not enter names, addresses, account details, medical information, credentials, or real customer content.

Optional input channel / Integrated capability

Bilingual Voice Intake

Review the transcript and language before they become the Answer Desk question. The visible answer and evidence stay primary; speech is a separate final action.

Open optional channelClose optional channel
01 / Choose an input

Fixture first. Microphone only on request.

Starts only after this button is pressed, records for at most 15 seconds, and sends the stopped clip for transcription.

00:00.0 / 00:15.0 Checking browser microphone support…

Choose a guided transcript, use the microphone, or continue with the typed Answer Desk.

02 / Review before retrieval

Correct the words and confirm the language.

Detected languageNot detected

This channel may retrieve approved general information. It does not decide eligibility, emergencies, diagnosis, legal or financial matters, pricing, availability, booking, or commitments; those stop at a fixed person-led escalation.

Voice run diagnostics
Capture
Not started
Transcription
Not started
Source retrieval
Not started
Spoken output
Not requested
Input origin
Not selected
Provider mode
Fixture ready · public-tour provider not invoked
Audio duration
Not available
Cost / tokens
Not applicable in the isolated public tour
Policy version
Loading

Guided questions

Choose the boundary you want to inspect.

The UI keeps each standalone run in page state until reset, replacement, or page close.
Ask a bounded fictional question

Markup and control characters are rejected. This public tour accepts no links, files, customer records, or operational conversation history.

Evidence statusReady

Ready. Choose a guided question or enter bounded fictional text.

Tour mode
Deterministic lexical
Language
Not selected
Accepted sources
0
Rejected sources
0
Public-tour memory
Page state only · standalone request

Question + release decision

Answer

Not run
Fictional question

No question has been submitted.

Release state

Waiting for a question

A supported answer or a clear abstention will appear here.

    No question or contact detail is sent by this demo action.

    Technical retrieval trace
    Trace ID
    Not created
    Retrieval method
    Deterministic lexical sections
    Config version
    Not loaded
    Source IDs
    None
    Latency
    Not measured
    Token usage
    Unavailable in fixture mode
    Boundary reason
    Not applicable
    Question retention
    Not persisted · current page state only · trace uses a one-way fingerprint

    Portfolio evidence ledger

    Evidence, production controls, and release assurance.

    Isolated public tour · fictional or synthetic data · operational controls verified separately.

    Exact role
    Designed and implemented the bilingual source-governance contract, immutable workspace registry, claim-level citation validation, deterministic abstention states, encrypted conversation and handoff records, reviewed voice-input channel, technical trace, signed delivery, and reproducible evaluation harness.
    Human boundary
    A person resolves missing, stale, conflicting, sensitive, pricing, availability, emergency, or otherwise unsupported material. Voice transcripts must be reviewed before retrieval, and speech can repeat only the approved text already visible on screen.

    Evidence in the build

    Answer release
    Claim-level support requiredA positive answer is replaced by a deterministic abstention if any material claim lacks a valid current citation.
    Source governance
    Visible owner, version and statusThe source inspector exposes the metadata needed to understand why a passage can or cannot support an answer.
    Retrieval method
    Governed retrieval policyThe public tour is deterministic lexical retrieval; operational configuration can require a hybrid ranker and fails closed if it is unavailable.
    Memory boundary
    Encrypted operational threadsBounded subject history survives restart but remains separate from evidence; the public tour reads no operational conversation.
    Voice boundary
    Review before retrievalA recorded question does not enter the source contract until the transcript and language are visible and correctable.
    Commercial result
    Not claimedSynthetic-corpus evaluation results describe the test environment only, not customer, support, revenue, or labor outcomes.

    Tests actually run

    1. 44/44Pinned Answer Desk evaluation

      All five release gates passed with zero case failures and no external provider call.

    2. 287/287Final Voice-integration unit suite

      Completed on the final Task 04 tree containing the parent Answer Desk.

    3. 20/20Dedicated voice browser scenarios

      Covered the optional reviewed bilingual voice-input channel.

    4. 12/12Parent Answer Desk browser scenarios

      Covered supported and fail-closed answers, evidence inspection, recovery, accessibility, and reflow.

    5. 27/27Migration, project, and adjacent regressions

      Completed alongside the final Voice integration gate.

    Production controls implemented

    • An authenticated workspace registry stores encrypted source payloads as immutable versions, authenticates its event chain, and permits answers only from current, approved, same-language policy.
    • Encrypted subject-scoped threads preserve bounded conversation continuity across restart; every audit event is HMAC chained and verified before history is returned.
    • An external ranker receives only a frozen encrypted corpus snapshot reserved before the request, with a stable provider ID, a hard deadline, approved region and zero-retention policy, and fail-closed recovery.
    • Unsupported, partial, conflicting, or expired evidence creates a durable staff handoff with role checks, audit events, retention, and signed idempotent delivery.
    • Voice intake stores no raw audio, holds every transcript for explicit review or correction, and permits speech only as a separate user action after a supported answer is visible.
    • Workspace isolation, salted role credentials, private database files, source-version citations, deletion, generation-consistent backup, and fail-closed provider behavior are enforced in the service layer.

    Enforced production activation gates

    • Operational answers require an owner-approved bilingual corpus, authenticated staff roles, source review dates, and an approved human-handoff destination.
    • The fictional public tour remains isolated from account history, operational sources, staff queues, credentials, and live downstream effects.
    • Voice and external ranking activate only when provider region, privacy handling, zero-content-retention, no-training, recording, and timeout approvals match the validated workspace configuration.

    The useful answer is the one the team can defend.

    Buyer

    A U.S. home or property service operator whose staff and customers ask the same service, coverage, hours, appointment, warranty, safety, and privacy questions in English and Spanish.

    Controlled outcome

    Current policy becomes a short cited answer. Missing, stale, conflicting, hostile, or wrong-language evidence becomes a durable review-queue handoff instead of an improvised promise.

    A small corpus with an owner, a date, and a stopping rule.

    Canonical sectionOwnerLanguagesRelease rule
    Services + exclusionsService OperationsEN / ESCurrent approved policy only
    Service areaDispatch OperationsEN / ESCoverage facts, never availability
    Operating hoursCustomer CareEN / ESPublished hours + holiday boundary
    Appointments + estimatesScheduling LeadEN / ESNo price or slot invention
    Warranty + follow-upQuality LeadEN / ESCurrent terms or abstain
    Emergency + safetySafety ReviewEN / ESEscalation language, no diagnosis
    Privacy + contactPrivacy OwnerEN / ESMinimum-data contact policy
    Approved + current

    May support a claim only in the requested language, with its exact visible excerpt.

    Draft / expired

    May appear in the inspector as rejected evidence, but cannot support a positive answer.

    Conflict

    Two disagreeing current policies stop release until their owner resolves the source-of-truth decision.

    Hostile source text

    Retrieved text remains untrusted data. Instruction-like source content is rejected, never followed.

    Release claims come from the pinned test set—not a confidence score.

    Measured July 20, 2026 with deterministic fixtures; no external provider calls. The report is generated from the pinned task-specific dataset.

    Dataset
    44 cases
    Supported pass rate
    100%
    Abstention correctness
    100%
    Claim citation coverage
    100%
    Citation validity
    100%
    Language-parity failures
    0
    Local latency p50 / p95
    0.08 / 1.75 ms
    Reproduction record
    Evaluation clock
    2026-07-20T12:00:00.000Z
    Answer config
    source-backed-answer-contract.v1
    Dataset SHA-256
    88c2c709973ea448f5a582a51833b54479d64dc863bb4d36decb14a9a9d89595
    Corpus SHA-256
    006a05c0719fdd7efec9b9ccb88d680537b166baaf717a596d3b22da0b148109
    Measured test scope
    • These metrics cover the pinned synthetic corpus and deterministic provider fixtures; customer-specific acceptance uses its own approved corpus and questions.
    • The latency value is local contract-evaluation time; deployed latency is recorded by the operational monitoring path.
    • Authorization, retention, durable audit, and reviewer operations are verified by the operational service suite rather than counted in this fixture metric.

    The source contract stays in front of the provider boundary.

    1. 01

      Authenticate + validate

      Bind the request to one workspace and subject, then enforce the bounded bilingual question contract.

    2. 02

      Select

      Search only the immutable approved corpus snapshot with the configured lexical or hybrid retrieval policy.

    3. 03

      Govern

      Reject draft, superseded, expired, conflicting, hostile, or wrong-language material before answer assembly.

    4. 04

      Support + remember

      Require current source citations for every material claim and keep encrypted thread history separate from evidence.

    5. 05

      Release or hand off

      Persist the cited answer or create an authenticated, auditable, idempotent person-led handoff.

    Production controls

    • Immutable source versions are encrypted and scoped to one workspace; only current, approved, same-language records enter a frozen operational corpus snapshot.
    • Viewer and operator access is read-bounded; reviewers answer and manage handoffs; administrators publish sources; salted role credentials and HMAC-verified event chains protect every governance operation.
    • Questions, answers, bounded thread history, and reserved ranker snapshots are encrypted at rest; prior turns never become evidence and cannot cross subject or workspace boundaries.
    • Unsupported, partial, conflicting, or expired material creates a durable handoff that leaves through signed, idempotent HTTPS delivery with bounded backoff and a durable receipt.
    • Voice audio is never persisted, transcripts require explicit review, and speech remains a separate action over the already-visible supported answer.

    Map the approved-answer boundary

    Find the question your current sources cannot safely answer.

    Start with the policy gap, source owner, and human handoff before choosing a retrieval or model provider.

    Get a 3-point lead-flow review