OPERATIVEOPS / HOW-IT-WORKS

READING ARC: 01 MECHANISM — THIS PAGE → 02 OPERATION → 03 TERMS

MECHANISM — NOT A METAPHOR

How a question becomes a cited, auditable answer.

Permission check, hybrid retrieval over your indexed documents, one model call at an endpoint you choose, an answer that cites its sources, and an audit record. In that order, every time. This page traces the path.

NO STEP IS OPTIONAL · NO STEP IS HIDDEN

THE ARTIFACT — EVERY ANSWER SHIPS LIKE THIS

Q: Which of our suppliers fall under the NIS2 reporting duty?

Two of the 14 suppliers in the register are classified as essential entities: Nordkraft Energie [1] and MedLog Pharma-Logistik [1]. The incident reporting duty applies to both contracts under the 2026 mapping [2].

[1] confluence://einkauf/lieferantenregister.md §2[2] notion://legal/nis2-mapping-2026

WHAT PRODUCED IT — ANNOTATED

SCOPE
asked by m.weber · role member · check passed
RETRIEVAL
2 passages · hybrid vector + keyword · 41 ms
MODEL
ollama://llama3.1-70b · inside the perimeter
RECORD
ledger #2026-4471 · appended 09:41:03

Four facts travel with every answer. None of them is decoration; each one is a row in the audit ledger.

FIG. 01 — REQUEST LIFECYCLE

One request, end to end.

Seven steps, one trust boundary. Exactly one line may cross it — and only if you configure a hosted model. Argue with the diagram; that is what it is for.

TRUST BOUNDARY — VERTRAUENSGRENZE01Questionweb · slack · api02Permission checkrole + scope grants03Hybrid retrievalvector + keyword · top-k04Context assemblyquestion + passages + scope05Model callendpoint set per agentdefault: local runtime06Answer + citationsevery claim → source pathclaim without source → droppeddenied → stops here,still logged07Audit record — append-only, written before the answer renderswho asked · what was retrieved · model + version · action taken · when · sha-chained to the previous recordNEVER CROSSES: documents · embeddings · vector store · audit ledger · credentialsHosted model APIoptional · off by defaultegress gate · TLS · loggedwhat crosses: prompt +retrieved passages. nothing else.air-gapped: this linedoes not exist.
FIG. 01 — REQUEST LIFECYCLE · ONE GATED LINE, OR NONE

01–02  The asking user's role and scope grants are checked before any data is touched. A denial ends the request — and is itself logged.

03–04  Hybrid search (embeddings plus keyword) ranks passages from your own store, filtered to what this user may see. The prompt is the question, the passages, and the scope. Nothing else.

05–06  The model runs where you configured it — local by default. Each claim in the answer must resolve to a source path; a claim that cannot is dropped, not shipped.

07  The audit record is written before the answer renders. If the write fails, the answer does not ship.

Where step 05 runs — your metal, your cloud, or air-gapped — is a deployment decision, not a mechanism one. Self-hosted vs managed.

FIG. 02 — RETRIEVAL

Retrieval, honestly.

INGEST

What goes in

PDF, DOCX, Markdown, Confluence and Notion pages, tickets over MCP. Chunked by structure — headings and sections, not fixed character counts.

INDEX

How it is indexed

Twice: embeddings in your own vector store, and a keyword index. Hybrid, because names, SKUs and paragraph numbers defeat pure vectors.

SELECT

How a passage wins

Both rankings merge, duplicates collapse, and passages the asking user may not read are removed before the model sees anything.

CITE

How a citation resolves

Each passage keeps its source path and section. Clicking a citation opens that passage in the source system — access re-checked on open.

ANATOMY OF A CITATION — A REUSABLE OBJECT, NOT A FOOTNOTE

[1]INDEX
confluence://SOURCE SYSTEM
hr-handbuch/urlaub.mdPATH — CLICK OPENS THE SOURCE
§4SECTION

FIG. 03 — TOOL ACCESS

Tools over MCP. Permission first.

MCP is the open standard for connecting AI systems to tools. The connectors run inside your deployment, not on a vendor's server. The interesting part is not the plumbing — it is the permission model.

A REAL SCOPE GRANT

GRANT agent.ops → jira.write

scope:
project OPS · create + comment only
granted-by:
admin.km · 2026-08-12
expires:
2026-11-12 · review required
ledger:
#2026-4102 — the grant is itself an entry

A REAL DENIED CALL

DENIED agent.ops → salesforce.read

reason:
outside granted scope
effect:
call never reaches the connector
ledger:
#2026-4472 · admin notified
retry:
requires a new grant, not a better prompt

A WRITE AWAITING APPROVAL

HOLD agent.eng → jira.delete OPS-1180

rule:
destructive writes need a human
waiting-on:
any Agent Manager
timeout:
24 h, then auto-denied
ledger:
both the hold and the decision

SCOPES ARE ENFORCED AT THE MCP LAYER — NOT IN THE PROMPT.

FIG. 04 — AGENT SCOPE

An agent is its boundary.

Agents are role-scoped: distinct systems, distinct rights, nothing shared by default. The content of an agent is not a personality — it is this table.

FIG. 04 — AGENT SCOPE MATRIX
SYSTEMAGENT.OPSAGENT.ENGAGENT.ANALYTICS
confluence://READREADREAD
jira://READ + WRITEREAD + WRITEREAD
slack://READ + POSTREAD—
salesforce://——READ
hr-portal://———

— means not reachable, even if asked nicely. Writes are logged; destructive writes wait for a human. Grants come from your admin and expire.

FIG. 05 — THE RECORD

The audit record is the payoff.

RECORD #2026-4471 — IN FULL

RECORD #2026-4471append-only · sha-chained
asked-by
m.weber · role member
at
2026-08-17 09:41:02.114 UTC
retrieved
2 passages · confluence(1) · notion(1)
model
ollama://llama3.1-70b · build 2026-06
action
none
answer
delivered 09:41:03 · citations [1][2]
prev-record
sha256:aa17f2…c90
this-record
sha256:9f3a71…b04

Every answer writes one.

Questions, actions, grants, denials — each becomes a record before its result is shown. There is no unlogged path through the system.

Chained, so gaps show.

Each record carries the hash of the previous one. Delete a record and the chain breaks visibly — for your auditor, in your favour.

Exportable.

CSV, JSONL, syslog — into your SIEM, on your schedule. Retention is your policy, on your disk.

A WRAPPER FORWARDS YOUR QUESTION. A SYSTEM OF RECORD CAN TESTIFY.

NEXT — 02 OPERATIONRun it on your own metal →Topologies, sizing, BYOM routing, roles, the SDK.OR — THE THREAT MODELRead the security page →Controls, cryptography, incident process, subprocessors.