An assistant can quote a document accurately and still return the wrong business instruction. If the underlying document was changed without authorization, faithful retrieval reproduces the unauthorized change. The security question sits in the knowledge pipeline as well as in the generated answer.
This matters for assistants that explain internal procedures, product policies, or customer obligations. An answer can look well supported because it includes a citation, while the cited source itself needs verification.
Distinguish integrity from retrieval accuracy
OWASP's data and model poisoning category includes manipulation of data used in training, fine-tuning, or embedding pipelines. Its guidance discusses the consequences of accepting manipulated inputs. In a business knowledge system, an analogous review follows who can introduce or replace documents that the assistant treats as authoritative.
An illustrative internal travel assistant reads the company's reimbursement policy. A test contributor uploads a second document with a similar title and an altered approval threshold. The assistant may retrieve the new document because it matches the question closely. The problem is not necessarily inaccurate quotation; it is the selection and status of the source.
Establish which sources carry authority
A knowledge inventory can distinguish approved policies, working drafts, discussion threads, and external reference material. Those categories can inform retrieval rules and answer presentation. A draft uploaded yesterday does not automatically supersede an approved policy with an older timestamp.
Record document ownership, approval status, version history, and the source location carried through ingestion. If the pipeline strips these attributes, the answering system may have no basis for explaining why one of several conflicting documents was used.
Exercise conflict and replacement cases
Create a synthetic policy set with one approved document, one draft, and one superseded version. Ask questions whose answers differ between the documents. Inspect both the selected chunks and the citation shown to the user. Then change the draft's title and upload date to test whether superficial relevance displaces the approved source.
Repeat the exercise after withdrawing a document. Verify how the index and cached answers respond. A documented delay may be an operational constraint, but it still needs to be visible to whoever owns the policy and the assistant's release decision.
Keep the incident response path specific
If an unauthorized document enters the corpus, responders need to identify when it was indexed, which revisions were affected, and which answers referenced it. That requires source identifiers and version information rather than only a copy of the final generated text.
The remediation can involve restoring the source, rebuilding affected index entries, invalidating relevant caches, and checking that the approved material is selected again. The acceptance record should describe those observed outcomes. It should not infer that correcting one answer establishes integrity across the entire knowledge base.
Sources
OWASP: RAG Security. The travel-policy example is a controlled integrity test, not an account of an actual policy change.