Ember

Request a diagnosis

We’ll reply within one working day.

Or write to hello@emberhub.dev. We only use this to reply to you.

Blog

Your AI can retrieve the right document and still act on the wrong fact

Why enterprise agents need a resolution layer, not just a better search index.

A correct citation can support an incorrect decision

Imagine a renewal assistant with access to a CRM, an ERP and an account manager's inbox. The CRM contains last year's price. The ERP contains the amount on the current invoice. An email discusses a new price, conditional on a longer contract. All three records are real. All three are relevant. Which amount should the assistant put in a renewal offer? This is an illustrative example, not a customer case.

A retrieval system can do its job perfectly and return all three. The model can summarize each accurately. The action can still be wrong, because the missing piece is a business decision: which agreement governs this renewal, under which conditions, and who can confirm it?

That is the data problem beneath the agent problem. Better access to evidence does not automatically turn evidence into an authoritative fact.

Relevance, authority and permission are different questions

A search score asks which records are useful for a query. An access check asks whether the caller may read them. Neither question, by itself, determines which record governs an action.

Authority has a scope. Finance might own the invoiced amount, while an account manager owns whether a proposed commercial exception was accepted. Time has a scope too: when a record was edited is different from when a term takes effect. A newer email can contain a suggestion rather than an agreement. A recently synchronized CRM record can still hold an old value.

The engineering task is therefore more demanding than selecting the freshest chunk. It requires matching entities, distinguishing proposals from commitments, comparing like terms, and retaining the evidence behind the decision. A price without currency, contract period and effective date is not yet a safe input to a quote.

Do not compress disagreement into confidence

When two sources conflict, asking a model to produce one clean answer can hide the very signal a workflow needs. The system should preserve candidate values and their provenance until a documented rule or a qualified person resolves the conflict.

A useful state model distinguishes supported, conflicted, missing and expired facts. Those states should affect execution. A harmless summary might show both candidates. A customer-facing quote might stop. The threshold depends on the consequence of being wrong, not on how confident the generated sentence sounds.

OWASP's misinformation guidance recommends cross-verification, human oversight and automatic validation alongside retrieval-augmented generation. That combination matters: adding sources helps, but checking whether their claims support the intended action is a separate responsibility. [1]

Ask for the missing fact, not another blanket approval

A reviewer shown only a polished quote has the same blind spot as the agent. An approval button does not reveal the disagreement that disappeared upstream. A better question makes the competing evidence explicit: 'The CRM shows the old annual rate. The email proposes a new rate for a two-year term. Was that term accepted for this renewal?'

The answer should become a reusable, scoped record, with the respondent, evidence and time attached. Otherwise the next agent repeats the same research and the next reviewer carries the same burden. Reuse still requires access checks and invalidation when the underlying agreement changes.

The hard part is closing this loop without turning everyone into a full-time data steward. Questions need an owner, a reason they matter, and a limit on interruption. No owner or no answer should remain an explicit gap, rather than an invitation to guess.

The layer Ember is aiming at

Ember's public description centers on this loop: read connected systems, find conflicting or missing facts, ask the person who knows, and keep the answer with who gave it and when. It describes read-only access and human approval before source systems change. [2]

The point is not to replace search. Search discovers evidence. A resolution layer determines whether that evidence is sufficient for a particular decision, and obtains the missing answer when it is not.

If an agent is going to act for a business, the business needs a way to say both 'this is the fact you may use' and 'we do not know yet.' The second answer is often what prevents the first expensive mistake.

Sources

[1] OWASP: LLM09:2025 Misinformation

[2] Ember: public product description