OPERATIVEOPS / HOW-IT-WORKS
READING ARC: 01 MECHANISM — THIS PAGE → 02 OPERATION → 03 TERMS
MECHANISM — NOT A METAPHOR
How a question becomes a cited, auditable answer.
Permission check, hybrid retrieval over your indexed documents, one model call at an endpoint you choose, an answer that cites its sources, and an audit record. In that order, every time. This page traces the path.
NO STEP IS OPTIONAL · NO STEP IS HIDDEN
THE ARTIFACT — EVERY ANSWER SHIPS LIKE THIS
Q: Which of our suppliers fall under the NIS2 reporting duty?
Two of the 14 suppliers in the register are classified as essential entities: Nordkraft Energie [1] and MedLog Pharma-Logistik [1]. The incident reporting duty applies to both contracts under the 2026 mapping [2].
WHAT PRODUCED IT — ANNOTATED
- SCOPE
- asked by m.weber · role member · check passed
- RETRIEVAL
- 2 passages · hybrid vector + keyword · 41 ms
- MODEL
- ollama://llama3.1-70b · inside the perimeter
- RECORD
- ledger #2026-4471 · appended 09:41:03
Four facts travel with every answer. None of them is decoration; each one is a row in the audit ledger.
FIG. 01 — REQUEST LIFECYCLE
One request, end to end.
Seven steps, one trust boundary. Exactly one line may cross it — and only if you configure a hosted model. Argue with the diagram; that is what it is for.
01–02 The asking user's role and scope grants are checked before any data is touched. A denial ends the request — and is itself logged.
03–04 Hybrid search (embeddings plus keyword) ranks passages from your own store, filtered to what this user may see. The prompt is the question, the passages, and the scope. Nothing else.
05–06 The model runs where you configured it — local by default. Each claim in the answer must resolve to a source path; a claim that cannot is dropped, not shipped.
07 The audit record is written before the answer renders. If the write fails, the answer does not ship.
Where step 05 runs — your metal, your cloud, or air-gapped — is a deployment decision, not a mechanism one. Self-hosted vs managed.
FIG. 02 — RETRIEVAL
Retrieval, honestly.
INGEST
What goes in
PDF, DOCX, Markdown, Confluence and Notion pages, tickets over MCP. Chunked by structure — headings and sections, not fixed character counts.
INDEX
How it is indexed
Twice: embeddings in your own vector store, and a keyword index. Hybrid, because names, SKUs and paragraph numbers defeat pure vectors.
SELECT
How a passage wins
Both rankings merge, duplicates collapse, and passages the asking user may not read are removed before the model sees anything.
CITE
How a citation resolves
Each passage keeps its source path and section. Clicking a citation opens that passage in the source system — access re-checked on open.
ANATOMY OF A CITATION — A REUSABLE OBJECT, NOT A FOOTNOTE
FIG. 03 — TOOL ACCESS
Tools over MCP. Permission first.
MCP is the open standard for connecting AI systems to tools. The connectors run inside your deployment, not on a vendor's server. The interesting part is not the plumbing — it is the permission model.
A REAL SCOPE GRANT
GRANT agent.ops → jira.write
- scope:
- project OPS · create + comment only
- granted-by:
- admin.km · 2026-08-12
- expires:
- 2026-11-12 · review required
- ledger:
- #2026-4102 — the grant is itself an entry
A REAL DENIED CALL
DENIED agent.ops → salesforce.read
- reason:
- outside granted scope
- effect:
- call never reaches the connector
- ledger:
- #2026-4472 · admin notified
- retry:
- requires a new grant, not a better prompt
A WRITE AWAITING APPROVAL
HOLD agent.eng → jira.delete OPS-1180
- rule:
- destructive writes need a human
- waiting-on:
- any Agent Manager
- timeout:
- 24 h, then auto-denied
- ledger:
- both the hold and the decision
SCOPES ARE ENFORCED AT THE MCP LAYER — NOT IN THE PROMPT.
FIG. 04 — AGENT SCOPE
An agent is its boundary.
Agents are role-scoped: distinct systems, distinct rights, nothing shared by default. The content of an agent is not a personality — it is this table.
| SYSTEM | AGENT.OPS | AGENT.ENG | AGENT.ANALYTICS |
|---|---|---|---|
| confluence:// | READ | READ | READ |
| jira:// | READ + WRITE | READ + WRITE | READ |
| slack:// | READ + POST | READ | — |
| salesforce:// | — | — | READ |
| hr-portal:// | — | — | — |
— means not reachable, even if asked nicely. Writes are logged; destructive writes wait for a human. Grants come from your admin and expire.
FIG. 05 — THE RECORD
The audit record is the payoff.
RECORD #2026-4471 — IN FULL
- asked-by
- m.weber · role member
- at
- 2026-08-17 09:41:02.114 UTC
- retrieved
- 2 passages · confluence(1) · notion(1)
- model
- ollama://llama3.1-70b · build 2026-06
- action
- none
- answer
- delivered 09:41:03 · citations [1][2]
- prev-record
- sha256:aa17f2…c90
- this-record
- sha256:9f3a71…b04
Every answer writes one.
Questions, actions, grants, denials — each becomes a record before its result is shown. There is no unlogged path through the system.
Chained, so gaps show.
Each record carries the hash of the previous one. Delete a record and the chain breaks visibly — for your auditor, in your favour.
Exportable.
CSV, JSONL, syslog — into your SIEM, on your schedule. Retention is your policy, on your disk.
A WRAPPER FORWARDS YOUR QUESTION. A SYSTEM OF RECORD CAN TESTIFY.