Retrieval is readily scoped into a review as a data quality question: whether the knowledge base is accurate, whether it is current, and whether the agent cites it correctly. Those questions are reasonable and they leave the control question untouched. Retrieval is a read capability with a scope, and it is simultaneously an input channel into the model’s context window. Each half carries a distinct risk, and the two are addressed by different controls.
Whatever the retrieval index contains, the agent can surface, because the index is the boundary and anything inside it is reachable by some phrasing. The distinction between what the agent may surface if asked correctly and what it can surface does not survive contact with a system whose phrasing is chosen at run time.
Indexes grow by inclusion rules, and an inclusion rule is written to capture what the agent needs rather than to exclude what it should not reach. A connector is pointed at a documentation space because that space holds the service procedures. The same space holds the pages the team keeps for itself, such as escalation thresholds, fraud-hold criteria, and the internal note about which merchant categories receive extra scrutiny. Where the connector indexes attachments, a spreadsheet attached to a page three years ago, carrying three hundred rows of live case data, becomes retrievable by anyone able to hold a conversation with the assistant.
Four questions establish the read boundary, and each of them is answered from configuration rather than from a description. What the index contains, and how each source came to be included in it. Whether the connector indexes attachments and nested spaces, since both extend the boundary without any further decision. And whether retrieval is scoped to the entitlement of the person in the conversation or to the entitlement of the agent. The last of these is the identity-binding question that governs every other tool, and where the answer is the agent, retrieval scope is a fixed boundary for every member rather than one that narrows per requester.
The second half is the one that is easier to overlook, because it does not look like a capability at all. Retrieved content enters the model’s context window, and the model has no reliable mechanism for distinguishing text retrieved as reference material from text instructing it what to do. Both arrive as the same kind of object, in the same window, from the same channel.
That makes write access to the knowledge base equivalent to influence over the agent’s behaviour. Where forty people in member servicing can edit those pages and edits are not reviewed, the population able to attempt to steer the agent is those forty people together with anyone who compromises one of their accounts. Where an indexed source accepts content from outside the organization, such as support tickets or inbound email, that population is unbounded.
The reframing is what turns an observation into a finding, because it names a control objective rather than a condition. A statement that the knowledge base contains sensitive data is true and is closed by moving a document. The finding is that an unreviewed content store is an unreviewed input to a system holding transaction authority, and no control connects the two. Content governance and agent security are one control objective addressed by two functions, and where they are owned separately neither owner has the whole condition in view.
The connector configuration, showing which sources, spaces, sub-spaces, and attachment types are indexed. The index inventory, or a sample of it, which establishes what is reachable rather than what was intended to be reachable. The write-access list for every indexed source, with a count, because the size of that population is the size of the population that can influence the agent. And the review workflow governing edits to those sources, where one exists.
Then connect the two halves in the report, because separately each reads as a lesser finding. Retrieval scope determines what can be disclosed, and write access determines who can influence what the agent does. Where neither has been established, the behaviour of a system holding a refund function is governed by a content store that was built for people reading with judgment.
This brief is one of ten behind Module 1, The tool surface, a free guided walkthrough of an AI agent assessment at a credit union. The same engagement can be run unassisted, with the check questions above put to you against evidence rather than against a description.
NexNith advises boards and audit committees on exactly this work. How we work