Skip to content
Bahman Shadmehr Independent AI Systems & Automation Engineer
On this pattern

System Pattern 09 / Documents, Knowledge & Context

No evidence. No conclusion.

Evidence-Bounded Inference

A generated conclusion is allowed to exist only when its material claims remain connected to current, permitted and sufficient evidence.

Maturity
Reference design / Specified
Critical uncertainty
The model may explain evidence. It may not manufacture missing evidence or convert uncertainty into a conclusion.
Human boundary
Interpret authorized ambiguity and make decisions within delegated scope
Applications
Support answers · Contract analysis · Incident hypotheses · Call compliance
Support, legal, incident, and compliance questions enter nine evidence-control layers and end as supported, contradicted, or insufficient evidence.

Problem shape

The problem beneath them

Bind every material claim to current, permitted, versioned evidence; search for contradiction; and abstain when the evidence cannot carry the conclusion.

Generation is cheap; warranted conclusion is not. Retrieval can return semantically similar but obsolete, unauthorized, incomplete, or contradictory material. A citation can exist without supporting the sentence beside it. Long context can contain the answer while a model attends to the wrong passage. Fluent wording then makes weak evidence appear settled.

The pattern treats a response as a set of claims, not one indivisible paragraph. Each material claim has an evidence contract: source types permitted, temporal scope, required specificity, minimum support, contradiction handling, and authority. Evidence retains stable identity, version, location, and access basis. The system validates whether cited spans entail the claim rather than merely share vocabulary.

Abstention is therefore an engineered outcome. “Insufficient evidence” should identify what is missing and who can obtain or judge it. Human review is not a ceremony that converts missing support into truth; a reviewer may approve a bounded interpretation, request evidence, record a policy judgment, or reject the claim.

The model may explain evidence. It may not manufacture missing evidence or convert uncertainty into a conclusion.

Evidence-bounded inference improves traceability and epistemic control. It does not guarantee that an authoritative source is factually correct, resolve conflicting authorities automatically, or confer legal, clinical, or operational authority on a generated explanation.

Different problems, same shape

The surface changes. The decision structure persists.

01 / Support

Which policy supports this answer?

A fluent response cites no current governing source.

02 / Legal

Which clause governs this conclusion?

Several versions or clauses may apply to the same question.

03 / Incident response

What evidence supports this hypothesis?

Symptoms suggest a cause but competing explanations remain.

04 / Compliance

Where in the call did this happen?

A consequential finding must resolve to timestamped source material.

All four questions converge into Evidence-Bounded Inference.

Exploded pattern

Open the mechanism at every decision boundary.

  1. 01

    Define the claim contract

    Question
    What claims may be produced, and what evidence would make each permissible?
    Responsibility
    Specify materiality, source eligibility, temporal scope, required granularity, contradiction policy, and authority boundary.
    Input
    User task, domain policy, consequence, and requested output form.
    Output
    Machine-checkable claim and evidence requirements.
    Stops when
    The task is bounded or rejected as unsupported by an available evidence contract.
  2. 02

    Retrieve current permitted sources

    Question
    Which sources may answer this question for this user and time?
    Responsibility
    Enforce authorization, jurisdiction, effective dates, tenancy, and source status during retrieval.
    Input
    Claim contract, query, identity, policy context, and source catalog.
    Output
    Eligible candidate sources plus retrieval trace.
    Stops when
    The bounded retrieval plan completes or source access is denied explicitly.
  3. 03

    Preserve source identity and version

    Question
    Can every cited passage be recovered exactly as evaluated?
    Responsibility
    Retain stable source ID, version, checksum, effective period, location, and access basis.
    Input
    Retrieved documents, transcript segments, records, and metadata.
    Output
    Versioned evidence objects with resolvable locators.
    Stops when
    Later reconstruction does not depend on mutable “latest” content.
  4. 04

    Locate supporting evidence

    Question
    Which exact spans support each proposed material claim?
    Responsibility
    Select minimal sufficient passages and map them to atomic claims.
    Input
    Eligible evidence objects and candidate claims.
    Output
    Claim-to-span support links with context.
    Stops when
    Each claim has candidate support or is marked unsupported.
  5. 05

    Search for counterevidence

    Question
    What permitted evidence conflicts with, narrows, or supersedes the claim?
    Responsibility
    Run contradiction-oriented retrieval across relevant sources and versions.
    Input
    Candidate claim, supporting spans, source hierarchy, and known alternatives.
    Output
    Counterevidence links, unresolved conflicts, and supersession signals.
    Stops when
    Required opposing searches complete within the defined evidence scope.
  6. 06

    Validate claim-to-source alignment

    Question
    Does the cited evidence actually entail the wording and scope of the claim?
    Responsibility
    Check entities, qualifiers, negation, dates, jurisdiction, numerical values, and citation coverage.
    Input
    Atomic claim, support, counterevidence, and claim contract.
    Output
    Supported, contradicted, or misaligned assessment per claim.
    Stops when
    Material wording is either grounded or removed from the proposed conclusion.
  7. 07

    Measure evidence sufficiency

    Question
    Is the evidence adequate for the consequence, not merely relevant?
    Responsibility
    Evaluate authority, independence, completeness, recency, contradiction, and missing required evidence.
    Input
    Alignment results, source hierarchy, consequence, and sufficiency rules.
    Output
    Supported, contradicted, or insufficient-evidence route.
    Stops when
    The disposition is justified without using model confidence as a substitute for evidence.
  8. 08

    Abstain or escalate

    Question
    What should happen when the contract cannot be satisfied?
    Responsibility
    Suppress unsupported conclusions and return precise evidence gaps or an authorized review packet.
    Input
    Failed sufficiency checks, consequence, deadline, and escalation policy.
    Output
    Bounded abstention, request for evidence, or human-review task.
    Stops when
    No unsupported claim leaks into an authoritative output.
  9. 09

    Record the human disposition

    Question
    How did an authorized person resolve interpretation, conflict, or missing evidence?
    Responsibility
    Capture decision, authority, rationale, evidence reviewed, qualifications, and expiration.
    Input
    Review packet and reviewer judgment.
    Output
    Attributable disposition that does not rewrite source evidence.
    Stops when
    The decision and its scope are reconstructable and reviewable.

Decision forks

Every branch states why it exists and when it escalates.

Signals, decisions, reasons, and escalation conditions
Signal Decision Reason Escalates when
Current authoritative source directly supports claim Mark supported within stated scope Evidence satisfies authority, time, and alignment Consequence requires mandatory human approval
Authoritative source contradicts claim Mark contradicted; do not soften conflict Counterevidence governs the disposition Authorities conflict or applicability is disputed
Citation is topically related but not entailing Remove or rewrite claim Relevance is not support The requested conclusion cannot be narrowed safely
Required source is inaccessible Return insufficient evidence Permission failure must not be bypassed An authorized person can lawfully obtain it
Sources apply to different versions or jurisdictions Separate scopes or escalate Combining them creates a false universal claim Applicability needs domain authority
Support exists but a required qualifier is absent Narrow wording Claim must not exceed evidence Qualification changes a consequential action
Model confidence is high but support is missing Abstain Confidence describes output behavior, not truth Evidence can be gathered or specialist review is required

Operating paths

Clear, ambiguous, and failed work all reach explicit states.

Clear path

Define claim contract, retrieve eligible sources, map exact support, check contradiction and alignment, then publish bounded claims.

Final state
Supported or Contradicted.
Owner
Evidence service until disposition; consuming authority remains responsible for consequential action.
Evidence
Claim text, source IDs and versions, exact spans, retrieval trace, checks, and policy version.
Recovery
Re-evaluate when sources, effective dates, access, or claim wording change.
Ambiguous path

Expose conflicts or gaps, suppress a definitive conclusion, and send an evidence packet to an authorized reviewer.

Final state
Insufficient evidence.
Owner
Domain reviewer or source owner.
Evidence
Candidate support, counterevidence, missing requirements, applicability conflict, and model/system trace.
Recovery
Obtain evidence, narrow the claim, record a scoped human disposition, or retain abstention.
Failure path

Halt publication when provenance, permissions, indexing, or validation integrity fails.

Final state
Insufficient evidence.
Owner
Knowledge platform owner until trustworthy processing resumes.
Evidence
Failed component, affected corpus/version, queries, partial results, and containment event.
Recovery
Repair and re-index from authoritative sources, validate locators, and replay affected claims.

Authority map

Capability does not grant authority.

RULE

May decide
Enforce source eligibility, dates, required checks, and mandatory abstention
May not decide
Resolve substantive ambiguity not encoded in policy
Required evidence
Rule/version, context, evaluated conditions, and result

MODEL

May decide
Propose claims, find passages, compare wording, and explain conflict
May not decide
Invent evidence, override access, or authorize consequential action
Required evidence
Model/version, prompt/task, cited spans, and uncertainty

SYSTEM

May decide
Retrieve, preserve provenance, validate contracts, and suppress unsupported output
May not decide
Treat a retrieval score as factual sufficiency
Required evidence
Retrieval trace, source versions, mappings, checks, and state

HUMAN

May decide
Interpret authorized ambiguity and make decisions within delegated scope
May not decide
Backdate evidence, erase contradiction, or claim authority not held
Required evidence
Identity, remit, evidence reviewed, rationale, scope, and expiry

EXCEPTION

May decide
Hold missing, conflicting, stale, or inaccessible evidence cases
May not decide
Emit a definitive conclusion by default
Required evidence
Trigger, evidence gaps, owner, deadline, and recovery options

Failure modes and recovery

A failed path remains owned, evidenced, and recoverable.

Failures, detection, containment, recovery, and owners
Failure Detection Containment Recovery Owner
Stale policy remains searchable Effective-date or checksum audit disagrees Exclude stale version from current-answer route Re-index authoritative version and replay affected claims Content owner
Citation does not support adjacent claim Alignment check or review finds scope mismatch Suppress claim and preserve trace Rewrite narrowly or locate sufficient evidence Evidence service
Chunking removes decisive qualifier Source-span comparison reveals omitted context Expand context; reject fragment-only support Reprocess source with versioned segmentation Knowledge platform
Cross-tenant retrieval exposes evidence Authorization audit or tenant mismatch Block response, isolate index, start incident process Repair partitioning and assess exposure Security owner
Counterevidence search is skipped Missing required stage in trace Prevent final disposition Run required search and revalidate all claims Evidence service
Human approval lacks rationale Required disposition fields absent Keep item non-final Return to authorized reviewer for complete record Domain owner

Invariants and guarantees

Properties the structure is designed to preserve.

  • Every material published claim maps to recoverable, permitted, versioned evidence.
  • Source locators resolve to the content actually evaluated, not an untracked latest version.
  • Contradictory evidence remains visible and affects disposition.
  • Missing access, missing evidence, and low support never become affirmative conclusions.
  • Model confidence never substitutes for source sufficiency.
  • Human dispositions retain scope, authority, rationale, and expiration where relevant.
  • Consequential action remains outside the model’s authority unless separately delegated to an accountable role.

What changes between implementations

The constraints determine the final mechanism.

The claim contract changes with domain and consequence. Support may require one governing policy, several independent observations, a complete contract hierarchy, or exact transcript timestamps. Retrieval architecture follows corpus size, update frequency, source permissions, language, and latency. Alignment may combine deterministic checks, specialist models, and human review.

Sufficiency thresholds depend on false-conclusion cost, review capacity, and reversibility. Some outputs can safely quote evidence without concluding; others must withhold the entire response. Retention and trace detail follow privacy and legal requirements. The invariant is that implementation convenience cannot widen the claim beyond current permitted evidence.

Evidence chain

Follow the pattern into systems and software.

Architecture and controls specified; no production results published.

version-aware-support-rag relates to current-policy answers; incident-triage to evidence-backed hypotheses; contract-compliance to clause-level conclusions; and on-prem-sales-call-compliance to timestamped findings. These are reference-design relationships and do not establish that this exact pattern was implemented, tested, or measured in those cases.

Entity resolution can preserve which real-world subject the evidence concerns. Risk-aware cascades can allocate model depth after evidence and authority floors are enforced. Private inference constrains where the entire evidence path may execute.

This is a REFERENCE DESIGN with specified controls; no production results are published. No open-source implementation is linked. No evaluation fixture, test, or benchmark is linked. Case-study references identify conceptual composition points only and carry no standalone implementation claim.

Known boundaries

Limitations and non-fit

Grounding cannot make a false source true or settle conflicts between authorities. Retrieval may miss decisive evidence, especially in incomplete, scanned, multilingual, or rapidly changing corpora. Claim decomposition and alignment checks reduce risk but are themselves fallible and need domain-appropriate evaluation before automation.

The pattern is not a substitute for professional judgment, discovery obligations, incident investigation, or policy ownership. It is excessive for unconsequential creative generation where factual grounding is not requested. It is non-fit when source rights prohibit the required processing, provenance cannot be retained, or the consuming process demands certainty that available evidence cannot provide.

Related patterns

Continue through the adjacent decision structures.

Evidence-bounded inference changes the unit of trust from a fluent response to a reconstructable claim. The useful output may be support, contradiction, or a precise refusal to conclude. All three are operational results when the system preserves what is known, what is missing, and who has authority to decide next.

Adapt the pattern

Bring the problem, the boundary, and the consequence of being wrong.

Let's build something real