Every answer has a citation
A citation can point to an approved document while the cited passage does not entail the generated answer.
Does the evidence establish source support, not just citation presence?
Epistamate examines the evidence behind the control claims organisations rely upon across their GenAI workflows.
An initial engagement begins with one consequential workflow, keeping every conclusion tied to a defined system, use, configuration, population and period.
You may have a GenAI policy, named owners, defined controls and a review cycle. Those are necessary foundations. They do not, by themselves, establish how reliably the controls operate, whether the evaluation is valid, or whether evidence gathered before a material change still applies.
A citation can point to an approved document while the cited passage does not entail the generated answer.
Does the evidence establish source support, not just citation presence?
An approval record shows that a person acted. It does not show which errors the person reliably detects.
What has reviewer performance actually demonstrated?
A score can be consistent without validly identifying the policy inconsistency or material error management cares about.
What criterion was the evaluator validated against?
Monitoring can report what it was designed to see while retrieval, ingestion or escalation failures remain silent.
What is observable, and what could fail without an alert?
A defined input is processed using GenAI, reviewed or acted upon, converted into an output or decision, and subsequently monitored, escalated and changed.
RAG is a mechanism inside a workflow. A policy describes what should happen. A control is intended to reduce a risk. A control claim states what management relies upon that control to achieve. Evidence determines whether that claim is supportable.
The technology can differ. The review follows the consequential path, including the controls, people, evidence and changes around it.
A message is classified, product or policy material is retrieved, an answer is generated, reviewed or sent, and the outcome is monitored.
Business consequence: cost to serve, response quality, retention and complaint risk.
Equipment history, manuals and service records are used to recommend troubleshooting steps or produce the customer work report after an intervention.
Business consequence: downtime, first-time fix, repeat visits and customer evidence of work.
Approved credentials, product facts, requirements and prior language are retrieved to draft an external response that may create a commitment.
Business consequence: bid capacity, turnaround, consistency and unsupported commitments.
An assistant interprets a customer's need, retrieves catalogue, product or policy information, recommends an option and may hand off or initiate an action.
Business consequence: conversion, self-service, consistent guidance and unsuitable recommendations.
Examples are illustrative. Suitability depends on the workflow boundary, materiality, evidence access and specialist requirements. Regulated individual decisions, medical or legal advice and safety-critical workflows are not automatically accepted.
An initial engagement normally covers one intended-use population, one immediate decision context, one configuration and period, and three to six material control propositions.
Confirm the workflow, intended use, material failure, decision to be informed, configuration and any defined tolerance or decision criterion. Broad requests such as “review our AI governance” are narrowed before evidence is assessed.
Translate policies, control descriptions and management assertions into specific propositions about retrieval, human review, automated evaluation, monitoring or change control.
Map samples, logs, configurations, incidents, validation records and changes to each proposition. Assess whether the evidence is direct, valid, independent, complete and current enough for the claim.
Separate supported claims, demonstrated weaknesses and unestablished assurance. Identify the smallest additional evidence or test that could change each unresolved conclusion.
Every conclusion remains tied to the reviewed workflow, evidence set, configuration and period. The report can be useful even when the available evidence cannot support management's original claim.
The decision the evidence supports, the important limitation, and what management should not overstate.
Three to six exact control claims, their evidence, conclusion, scope and current-applicability conditions.
Demonstrated operational weaknesses kept separate from missing evidence, uncertainty and interaction hypotheses.
Prioritised tests, records or validation work that could resolve the material uncertainty without creating a generic programme.
Source, date, period, provenance, proposition mapping and integrity limitations for the records relied upon.
The assessed system condition, evidence cut-off, material changes and permitted use of the conclusions.
The available evidence establishes the bounded proposition for the reviewed conditions.
The evidence demonstrates a material weakness against the proposition.
The claim may be true, but the available evidence does not justify relying upon it.
The work follows the operation and evidence, not the volume of governance documentation. The engagement route depends on what the organisation can actually show.
The client can provide a workflow boundary, control descriptions and relevant operating evidence. The engagement can move directly into proposition and evidence assessment.
The workflow is first reconstructed from interviews, configurations and operating records. If only policies and assertions exist, the output may be evidence readiness rather than an effectiveness conclusion.
A model, prompt, retrieval corpus, evaluator, reviewer population or external research finding can change what an earlier conclusion means. Epistamate can separately track research relevant to the mechanisms examined and flag developments that may warrant another look.
It tells the client what changed in the research and which reviewed proposition may be affected.
The original conclusion remains a dated record of the workflow and evidence reviewed at that time.
An applicability review or reassessment is separately scoped when the client can provide the changed configuration, logs or supplemental evidence.
It is a bounded review of whether the available evidence supports the specific claims management relies upon about controls within a defined GenAI workflow. It does not stop at confirming that policies, controls or review cycles exist.
A workflow is the bounded path from a defined input through GenAI processing, review or action, to a consequential output, together with its monitoring, escalation and change controls. A customer-support drafting process may be one workflow. The organisation's entire use of GenAI is not.
No. Policies help reconstruct what should happen and identify intended controls. The review examines operational evidence about what those controls actually did within the selected workflow and period.
The workflow may first be reconstructed from interviews, configurations and operating records. If only policies and assertions exist, an effectiveness conclusion may not be possible, but an evidence-readiness output may still identify exactly what is missing.
The client receives an executive decision brief, proposition-level findings linked to evidence, demonstrated weaknesses, assurance limitations, applicability conditions, an evidence-development roadmap and a technical evidence register.
Yes. The initial engagement begins with one workflow so the conclusions remain bounded and defensible. Additional workflows can be separately scoped if the first review proves useful.
No. An alert can identify research that may affect a reviewed mechanism. A refreshed conclusion requires a separately scoped applicability review or reassessment using the current workflow and evidence.
Timing and fee are proposed after a short scoping conversation confirms the workflow boundary, evidence access and any specialist requirements. This keeps the proposal tied to the review effort the workflow actually requires.
No. It is a founder-led professional evidence review, not an audit, certification, legal opinion, regulatory-compliance determination or general declaration that a system is safe or reliable.
The first conversation establishes whether the workflow is bounded, consequential and supported by enough access to make the review useful. Do not send confidential evidence through the public form.