Amo.ng curated workflow

Assess Enterprise Knowledge and RAG Readiness

Assess knowledge freshness, retrieval configuration, authorization boundaries, and sensitive-context propagation before expanding or releasing an enterprise RAG capability.

Workflow ID
AMO-W-000016
Steps
4
Published
Download Markdown

Copy workflow includes every step and the full linked Prompt content. Use with AI copies a shorter guide with Prompt links; neither action runs the Workflow.

Outcome

A readiness package containing a corpus freshness policy and revalidation queue, retrieval experiment or evidence boundary, authorization exposure assessment, sensitive-context lineage, and a Ready, Restricted, Revalidate, or Hold decision.

Before you begin

Have all or some of the following available before you start. The more relevant context you can provide, the stronger the workflow output will be.

  • Knowledge use case, decision risk, users, owners, corpus scope, and current RAG architecture
  • Source inventory, ownership, effective dates, review history, ingestion records, and change evidence
  • Representative documents, query logs or benchmark questions, retrieval configuration, and answer standards
  • Identity, tenant, purpose, region, document ACL, cache, citation, and data-flow evidence
  • Sensitive data classifications, memory and tool boundaries, retention rules, release constraints, and incident history

Ordered sequence

Workflow steps

Complete the steps in order. For each step, provide the listed context, carry its result into the next step, and pause wherever a review note is shown.

  1. Step 1 Assess corpus freshness and knowledge decay

    Map decision-critical knowledge assets to source change, effective date, review evidence, usage and retrieval exposure, accountable ownership, decay risk, and revalidation triggers.

    Prompt: Enterprise Knowledge Corpus Freshness and Decay Review

    Input for this step

    Supply the source inventory, content and decision uses, ownership, authoritative systems, ingestion dates, source changes, review history, usage or retrieval exposure, and known stale-content incidents.

    Carry forward

    Carry the freshness policy map, decay-risk register, revalidation queue, source authority gaps, and owner assignments into retrieval design review.

    Review note

    The knowledge owner and domain owner confirm which sources are authoritative and which stale or unowned assets must be restricted pending revalidation.

    Open prompt
  2. Step 2 Validate chunking and metadata choices when material

    Define a controlled experiment when chunking or metadata choices lack decision-grade evidence or are changing. If current configuration is already supported by current representative evidence, record that evidence and mark a new experiment Not applicable.

    Prompt: Retrieval Chunking and Metadata Experiment Design

    Input for this step

    Provide the freshness findings, representative documents, current and candidate chunking or metadata configuration, query logs or benchmark questions, answer standards, source-version fields, and constraints.

    Carry forward

    Carry the experiment plan or verified configuration boundary, query slices, metrics, guardrails, acceptance criteria, and untested assumptions into authorization review.

    Review note

    The retrieval owner, data owner, and domain owner approve the evidence standard and any configuration selected for further testing or release.

    Open prompt
  3. Step 3 Test retrieval authorization boundaries

    Investigate whether identity, tenant, purpose, region, document ACL, ingestion, embedding, cache, retrieval, citation, or response behavior can cross authorized boundaries.

    Prompt: RAG Access-Control Leakage Investigation

    Input for this step

    Use the corpus and retrieval findings with authorization models, ACL exports, query and response traces, ingestion records, cache evidence, tenant or region design, and known leakage scenarios.

    Carry forward

    Carry the identity-to-document map, confirmed and potential leakage paths, affected scope, containment needs, regression matrix, and unresolved authorization evidence into context-lineage review.

    Review note

    The security reviewer, data owner, and product owner decide which content, users, queries, caches, or environments must remain restricted.

    Open prompt
  4. Step 4 Trace sensitive context beyond retrieval

    Trace sensitive context from source and retrieval through agent handoffs, prompts, memory, tools, logs, shared workspaces, and downstream outputs. Reconcile propagation findings with freshness and authorization evidence.

    Prompt: Sensitive Context Propagation and Cross-Agent Contamination Audit

    Input for this step

    Provide data classifications, RAG and agent flow, representative payloads, memory and tool configuration, logs, retention rules, tenant and purpose boundaries, and prior-step findings.

    Carry forward

    Produce the final Ready, Restricted, Revalidate, or Hold record with freshness work, retrieval evidence, authorization and context-lineage findings, owners, restrictions, regression criteria, and re-review triggers.

    Review note

    The knowledge owner, data owner, security and privacy reviewers, product owner, and release owner approve the readiness disposition and residual risk.

    Open prompt

Completion criteria

The workflow is complete when:

  • Decision-critical knowledge has a freshness status, owner, review trigger, and revalidation priority.
  • Retrieval configuration is supported by measured evidence or an explicit controlled experiment; unchanged verified configuration may be marked Not applicable.
  • Authorization and sensitive-context findings are traceable across ingestion, retrieval, cache, citation, memory, tools, logs, and handoffs.
  • The final readiness state is Ready, Restricted, Revalidate, or Hold with measurable conditions and owners.
  • Uninspected systems, unrun experiments, and unavailable evidence remain explicit.
Browse Workflows
AMO-W-000012 5 steps

Investigate an AI Agent Security Incident

Reconstruct an AI agent incident, trace delegated authority and sensitive context, conditionally investigate memory or RAG authorization, and prepare evidence-based containment and recovery gates.

Was this useful?