Amo.ng curated workflow

Assess Enterprise Knowledge and RAG Readiness

Govern enterprise knowledge freshness, source authority, retrieval evidence, entitlements, and sensitive-context boundaries before expanding or releasing a RAG capability.

Workflow ID
AMO-W-000016
Steps
6
Published
Download Markdown

Copy workflow includes every step and the full linked Prompt content. Use with AI copies a shorter guide with Prompt links; neither action runs the Workflow.

Outcome

A Ready, Restricted, Revalidate, or Hold package containing corpus decay findings, freshness objectives, source-authority decisions, retrieval evidence, entitlement controls, sensitive-context lineage, and accountable revalidation work.

Before you begin

Have all or some of the following available before you start. The more relevant context you can provide, the stronger the workflow output will be.

  • Knowledge use case, decision risk, users, owners, corpus scope, and current RAG architecture
  • Source inventory, ownership, authority, effective dates, review history, ingestion records, and change evidence
  • Freshness expectations, incident history, current monitoring, and revalidation capacity
  • Representative documents, query logs or benchmarks, retrieval configuration, and answer standards
  • Identity, tenant, purpose, region, document ACL, index, cache, citation, and data-flow evidence
  • Sensitive-data classifications, memory and tool boundaries, retention rules, and release constraints

Ordered sequence

Workflow steps

Complete the steps in order. For each step, provide the listed context, carry its result into the next step, and pause wherever a review note is shown.

  1. Step 1 Assess corpus freshness and knowledge decay

    Map decision-critical knowledge assets to source change, effective date, review evidence, usage and retrieval exposure, accountable ownership, decay risk, and revalidation triggers.

    Prompt: Enterprise Knowledge Corpus Freshness and Decay Review

    Input for this step

    Supply the source inventory, content and decision uses, ownership, authoritative systems, ingestion dates, source changes, review history, usage exposure, and known stale-content incidents.

    Carry forward

    Carry the freshness map, decay-risk register, priority assets, authority gaps, and owner assignments into freshness-control design.

    Review note

    The knowledge owner and domain owner confirm which sources are decision-critical and which stale or unowned assets require restriction.

    Open prompt
  2. Step 2 Define retrieval freshness controls

    Turn the decay findings into risk-based freshness objectives, measurement rules, source-change triggers, breach responses, revalidation evidence, and sustainable ownership.

    Prompt: Retrieval Freshness SLO and Revalidation Design

    Input for this step

    Provide the freshness map, risk tiers, source-change cadence, ingestion and validation history, current monitoring, incident evidence, owner capacity, and operating constraints.

    Carry forward

    Carry the freshness SLO register, breach and exception rules, revalidation queue, evidence requirements, and owner commitments into source-authority review.

    Review note

    Knowledge and service owners approve risk tiers, achievable objectives, breach responses, and temporary restrictions.

    Open prompt
  3. Step 3 Resolve source authority and supersession conflicts

    Determine which conflicting or superseded sources govern each use by tracing authority, effective dates, scope, lineage, exceptions, and current downstream retrieval exposure.

    Prompt: Knowledge Source Supersession and Conflict Resolution Brief

    Input for this step

    Supply conflicting source versions, authority rules, effective dates, owners, lineage and ingestion records, retrieval or citation exposure, and decision constraints.

    Carry forward

    Carry the authority matrix, supersession chains, affected content and decisions, remediation or exception states, and unresolved conflicts into retrieval validation.

    Review note

    The domain and knowledge owners approve authoritative-source dispositions; legal or compliance reviewers decide requirements within their remit.

    Open prompt
  4. Step 4 Validate retrieval configuration when material

    Define a controlled experiment when chunking or metadata choices lack decision-grade evidence or are changing. If representative current evidence already supports the configuration, record it and mark a new experiment Not applicable.

    Prompt: Retrieval Chunking and Metadata Experiment Design

    Input for this step

    Provide representative documents, source-authority decisions, current and candidate configuration, query logs or benchmarks, answer standards, source-version fields, and constraints.

    Carry forward

    Carry the experiment or verified-configuration boundary, query slices, measures, guardrails, acceptance criteria, and untested assumptions into entitlement review.

    Review note

    The retrieval, data, and domain owners approve the evidence standard and any configuration selected for testing or release.

    Open prompt
  5. Step 5 Reconcile effective knowledge entitlements

    Compare authoritative access policy with effective permissions across source, ingestion, index, cache, retrieval, citation, and response layers; identify stale grants, missing restrictions, and recertification gaps.

    Prompt: Knowledge Entitlement Drift Review

    Input for this step

    Provide identity and tenant models, source ACLs, group and role data, ingestion and index mappings, cache behavior, retrieval traces, exception registers, recertification history, and prior findings.

    Carry forward

    Carry the entitlement matrix, drift findings, exposed scope, containment needs, owner actions, and regression requirements into context-lineage review.

    Review note

    The data owner, security reviewer, and identity or service owner authorize access removal, exception continuation, and recertification decisions.

    Open prompt
  6. Step 6 Trace sensitive context beyond retrieval

    Trace sensitive context from source and retrieval through agent handoffs, prompts, memory, tools, logs, shared workspaces, and downstream outputs. Reconcile propagation with freshness, authority, retrieval, and entitlement evidence.

    Prompt: Sensitive Context Propagation and Cross-Agent Contamination Audit

    Input for this step

    Provide data classifications, RAG and agent flows, representative payloads, memory and tool configuration, logs, retention rules, tenant and purpose boundaries, and prior-step findings.

    Carry forward

    Produce the final Ready, Restricted, Revalidate, or Hold record with control work, restrictions, regression criteria, owners, evidence gaps, and re-review triggers.

    Review note

    Knowledge, data, product, and release owners make the readiness decision with security and privacy review for material exposure.

    Open prompt

Completion criteria

The workflow is complete when:

  • Decision-critical knowledge has an evidence-based freshness state, SLO or trigger, owner, breach response, and revalidation priority.
  • Conflicting or superseded sources have an authority disposition and downstream exposure decision.
  • Retrieval configuration is supported by measured evidence or an explicit controlled experiment.
  • Effective entitlements are reconciled across source, ingestion, index, cache, retrieval, citation, and response layers.
  • Sensitive-context propagation is bounded and the final state is Ready, Restricted, Revalidate, or Hold with observable conditions.
  • Uninspected systems, unrun tests, and unavailable evidence remain explicit.

Was this useful?

Browse Workflows
AMO-W-000012 5 steps

Investigate an AI Agent Security Incident

Reconstruct an AI agent incident, trace delegated authority and sensitive context, conditionally investigate memory or RAG authorization, and prepare evidence-based containment and recovery gates.