Every document arrives with its sources, its guesses, and a name
This is the mechanism, in the order it runs. It is built and in use at StreamBuild customers today. If you were sent this page by someone asking you to approve an AI tool, the four screens below are what you are approving.
LAST REVIEWED 01 SEP 2026Start with the thing itself
Not a diagram. This is a quarterly claim cover note as it appears in StreamBuild, with the three parts that make it approvable.
Please find attached the Q2 expense claim for the Ignite AI program, covering 1 April to 30 June 2026. Total claimed is $184,320 against an approved quarterly ceiling of $210,000. Two lines moved between budget categories under the reallocation memo of 3 July 2026.
Context manifest
Manifest 4c1f · 14 Aug 2026- S01FedNor contribution agreement, s.4PDF · 22 p
- S02Q2 expense workbook118 rows
- S03Travel reallocation memo, 3 Jul 2026DOCX · 2 p
- S04Q1 claim as filedPDF · 9 p
Assumptions the model had to make
- A01Contractor invoice 2041 belongs to the Q2 period.Dated 28 Jun 2026, paid 4 Jul 2026.medium
- A02Mileage is claimed at the 2026 federal rate.Rate not stated in the workbook.high
Three things travel with the document, and they are what a reviewer actually needs. The manifest tells you what the model was allowed to read, so you can see what it did not read. The assumption list tells you where it filled a gap, so you can check the two lines that matter instead of re-reading nine pages. The sign-off tells you who is answerable, by name, on a date.
None of this is generated prose about the document. It is recorded as the document is assembled, and it cannot be edited after the signature without voiding it.
The context manifest
A list of the exact records the model read, written at generation time. It is not a description of the data source. It is the records.
Context is assembled from a set you choose, not from everything in the tenant. Each entry names the record, its form, and its extent, so a reviewer can ask the one useful question: is anything missing from this list that should be on it.
Where a record was available and deliberately excluded, the manifest says so. An empty exclusion list is itself information.
- S01Named records onlyA document, a table, a row range, or a prior filed artifact. Never a whole drive.
- S02Extent is recordedPage counts, row counts, and revision dates, so the same manifest can be reproduced.
- S03Exclusions are listedRecords in scope that were withheld, with the reason. Here: one draft workbook, superseded.
- S04No open webThe model reads nothing outside the tenant unless a person adds a source by hand.
- S05Hash travels with the fileThe manifest hash is written into the exported PDF and any email that carries it.
Assumptions are extracted, then owned
A model that guesses is not the problem. A model that guesses silently is. Every gap it filled is pulled out of the prose and put in a list a person has to clear.
Open assumptions, Q3 claim draft
- A01Salary allocation for M. Okonjo is 40 percent to this program.Last stated in the Q1 claim. No 2026 letter on file.low
- A02The venue deposit is an eligible event cost.Agreement s.4.2 lists event costs without naming deposits.medium
- A03Reporting period ends 30 Sep 2026.Agreement schedule B.high
- A01Every assumption has a basisWhat the model read that led it there, or a note that it read nothing.
- A02Confidence is stated plainlyHigh, medium, low. There is no score, because a score invites a threshold.
- A03A person clears each oneAccept, correct, or strike. A struck assumption removes the sentence it supported.
- A04Nothing clears itselfThe model cannot resolve its own assumption, and neither can a second model.
Low confidence is common and is not a fault. In the draft above, the salary allocation is the one line a funder will question, and it took the reviewer forty seconds to find because the system put it at the top instead of burying it in paragraph six.
The filing gate
Nothing is exported, published, or sent from a draft state. The gate is the part of the mechanism that has teeth, so it is worth reading closely.
What this does not do
The claim is narrow on purpose. A board approving this should know where it stops.
See it run on your own reporting
A walkthrough uses one of your real documents, redacted if you prefer, and takes about forty minutes.