MA
← Selected systemsENGINEERING CASE STUDY

Enterprise claims · evidence governance

TrustFlow

A claim-integrity workflow that binds generated answers to approved, current evidence; routes sensitive assertions through policy and human review; and tracks how source changes affect previously approved claims.

InvariantNo evidence, no external claim
Authorityapproved evidence + claim policy + human review
Differentiatorsource-change impact analysis across previously approved claims
CORE QUESTION
Can we substantiate this claim?
Owns · External enterprise claim integrity

Claim invariant

No evidence, no external claim.

QUESTIONCLAIMEVIDENCE?POLICYREVIEWEXPORT

System model

Evidence lineage survives generation and review.

Source-change impact

The differentiator appears after the answer was approved.

SOURCE v12Encryption policyapproved evidence
DEPENDENT CLAIMSCustomer A · Q18Customer B · Q41RFP C · Q07
SOURCE v13Policy changedmark dependent claims for review

Engineering decisions

The governed object is the external assertion.

DECISION 01

The claim is the governed object

The risk is an externally asserted organizational commitment, not merely a generated document.

DECISION 02

Evidence eligibility includes freshness and scope

A once-correct source can become stale or be inapplicable to the claim being made.

DECISION 03

Source changes propagate impact, not silent rewrites

Previously approved claims need explicit re-evaluation when their evidence changes.

Capability surface

Evidence, provenance, policy, review, and impact.

01Evidence registry
02Claim provenance
03Claim classification
04Sensitivity rules
05Evidence freshness
06Conflict detection
07Unsupported-claim blocking
08Evidence-bounded generation
09Review workflow
10Safe document round-trip
11Claim ledger
12Source-change impact
13Claim invalidation
14Reusable approved-answer memory
15Cross-questionnaire consistency
16Coverage/reviewer analytics
17Connector architecture
18Export policy

Benchmark surface

What the system is designed to measure.

MEASUREMENT CONTRACT

Automation is useful only when every external assertion stays traceable to approved, current, non-conflicting evidence.

Questionnaire fixture suites, intentionally stale/conflicting evidence, source-version mutation tests, reviewer replay, and export round-trips.
01Unsupported claimsclaims without valid evidence
02Citation recallsupporting evidence surfaced
03Conflict detectioncontradictory evidence blocked
04Stalenessexpired evidence rejected
05Impact recallclaims found after source change
06Export fidelitydocument round-trip integrity

Evidence

Publicly defensible claim-governance boundaries.

SignalEvidenceInterpretation boundary
Evidence registryOwner · version · approval · effective/expiry dates · sensitivity · scopeSupportedEvidence metadata governs eligibility; it does not make the underlying source true by itself.
Claim provenanceEvery asserted answer can retain exact supporting evidence lineageSupportedUnsupported or conflicting evidence blocks automatic assertion.
Review policyauto-eligible · review · blockSupportedSensitive claim classes can require human review regardless of generated confidence.
Change impactSource changes can identify dependent approved claims for re-reviewSupportedImpact detection marks potential staleness; it does not silently rewrite historical answers.
Export boundaryCustomer-facing output is separated from internal evidence payloadsSupportedSensitive internal evidence is not automatically copied into external documents.

Explicit boundaries

TrustFlow is not a generic document chatbot.

Not generic RAGNot a document chatbotNot a full GRC suiteNot generic knowledge management