Finding it
A fabricated citation is worse than no answer at all.
It survives being checked by anybody who does not check it, which is almost everybody. And the first time somebody does check, they stop trusting every answer the system has ever given them.
The way out is structural: do not let the answer choose its own sources.
Grounding
The citations are the documents retrieval returned.
Not references the answer produced and the system then tried to match up — the list of what was actually read. A citation therefore cannot be invented, because nothing in the answering step is allowed to create one.
Retrieval runs through the same search everything else uses, so it inherits the workspace filtering, the module filtering and your own permissions for free. It cannot reach a document you could not open yourself.
- Three distinguishable kinds of nothing —
Nothing found, retrieval running in a reduced mode, or the model unavailable — each its own flag, so the screen can say which rather than showing one shrug.
- Citations arrive before the answer does —
Streamed first, deliberately, so you see which documents are being read within a moment instead of watching a spinner.
- It is told not to invent product names or settings —
And given a refusal to use when the sources do not carry the answer.
- Where it can use tools, they are filtered to your permissions —
And re-checked at the moment of use rather than only at the start, so a permission removed mid-session applies to the next question.
What it costs, and what it will not do
Recorded per question, in whole units, with input and output priced apart.
Because output costs several times input, collapsing them would misattribute a retrieval-heavy question against an answer-heavy one. The roll-up reports totals, the heaviest askers and a daily series.
Being straight about the limits: there is no spending cap — cost is recorded and nothing enforces a ceiling, and the only throttle is per person per hour. There is no separate permission for asking, so granting search grants this. And there is no chunking: a long policy contributes its opening rather than the passage that happened to be relevant.
›Does it remember the conversation?
Each question is answered on its own, so put the context you need into the question.
›Which model, and where does our content go?
Only what a given question needed is sent, retrieved under your own permissions. The vendor and model belong in a security review where they can be answered properly and kept current, rather than on a marketing page.
›Can it answer about the product itself?
If the help material has been indexed for your workspace. That is an explicit action rather than something that happens on its own — worth confirming during setup, because without it product questions have nothing to stand on.
›Can it do anything other than answer?
Where tools are available it can take a small number of additive actions — and nothing destructive exists to be offered, because the registry refuses to accept such a tool at all.