Skip to content
Founderz: Responsible Use of AI home

in collaboration with Microsoft

The ten principles

Principle 02 · Before you start · Reliable company knowledge

A single source of truth for AI

AI works from approved, current sources, and every important fact has one owned and dated home.

Key question

Where does this fact live, and who keeps it current?

Benefit

Answers that can be reused with confidence, because they come from sources the whole team trusts.

Context

Workplace assistants increasingly answer from your organization’s own files, emails and chats. Microsoft Copilot, for example, can draw on any content the user already has permission to open. If the shared drive holds five versions of the price list, an assistant will quote one of them, confidently.

That makes looking after sources part of using AI well. Well-kept sources help your colleagues find the right answer faster, and the AI too.

Five rules for a single source of truth

RuleIn practice
1. Every important fact has one homeLink to it from slides, emails and chats, so they always point to the current version.
2. Every home has an owner and a dateThe owner keeps it current. The date tells people, and AI, how fresh it is.
3. Point AI at the homeUse approved sources and ask the assistant which document it used.
4. Drafts stay draftsAI output becomes a source only after a person reviews and publishes it.
5. Fix it at the sourceWhen you find an error, correct the home and tell the owner, so the next person and the next AI get it right.

An approved source can still be wrong, so a good single source of truth also has a simple way to report mistakes, and someone who acts on them.

Source maintenance and access

Old and duplicate files waste people’s time, and an assistant can turn them into answers. Microsoft’s own guidance for organizations deploying Copilot recommends finding overshared, ownerless and inactive sites, reviewing who has access, and archiving inactive sites and deleting obsolete files so that answers stay current.

That guidance is written for IT administrators. Your part is the corner you own: your folders, your team’s pages and the documents with your name on them.

Example: the Founderz source of truth

Founderz keeps its company knowledge in one place. Every document has an owner, a version, a last-checked date and a classification: public, internal or confidential. Each figure is written once, in the document that owns it, and everything else links there. Changes go through review. AI assistants read this knowledge through a connector, and drafts they propose wait for a person before they’re published. Read the case study.

Practices

  1. 01Know where the official version of your key facts lives: prices, policies, product details, client terms.
  2. 02Name and date your documents, and archive the versions you replace.
  3. 03Ask the assistant which document it used, and open it.
  4. 04Keep AI drafts out of shared folders until someone has reviewed them.
  5. 05When you find an error, fix the source and tell its owner.

Prompt examples

A prompt before and after improvement, and the part a person does outside the prompt.

Contracts and policies

Answering from the official policy

Before

“What’s our refund policy for enterprise clients?”

After

“Using only “Refund policy v3.2” in the Legal folder, answer this client’s question. Quote the clause you rely on. If the policy doesn’t cover the case, say so.”

Your part

Open the clause it quoted. If you find an older copy of the policy somewhere else, ask the owner to archive it.

Why it works: Naming the official source and asking for the clause makes the answer checkable in seconds.

Sales and pricing

Checking a discount

Before

“What discount can I offer this client?”

After

“Using only the current price list (“Pricing 2026” in the sales wiki) and the discount policy, tell me the maximum discount for a three-year contract. Quote the lines you used, and tell me if the two documents disagree.”

Your part

Open both documents. If they disagree, ask the owner which one is right, and get the other one fixed.

Why it works: Asking where sources disagree surfaces the stale file before a client sees it.

Research

Updating the team wiki

Before

“Summarize our onboarding process and save it to the wiki.”

After

“Summarize our onboarding process from the three attached documents, as a draft for review. List anything that looks out of date or contradictory.”

Your part

Review and fix the draft, then publish it with an owner and today’s date. Archive the pages it replaces.

Why it works: The AI drafts and a person publishes, so nothing reaches the wiki until someone has checked it.

Evidence

  • Microsoft Copilot only surfaces organizational content that the user already has permission to view. [Microsoft Learn]
  • Microsoft’s deployment guidance for Copilot recommends access reviews, and archiving inactive sites and deleting obsolete files, so answers stay current. [Microsoft Learn]
  • The OECD AI Principles ask those responsible for AI to keep datasets, processes and decisions traceable. [OECD]
  • NIST’s profile for generative AI lists confabulation, false content stated with confidence, among its twelve risks. [NIST AI 600-1]

Case studies and scenarios

Team practice

Agree where your team’s key facts live, who owns each one and when they’re reviewed. The starter kit takes a week of ten-minute steps.

Team toolSingle source of truth starter kit

Sources

What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.

  1. Data, privacy, and security for Microsoft Copilot Microsoft · Updated August 18, 2026 · Product documentation States that Copilot only surfaces organizational data the user has at least view permission for; that prompts, responses and data accessed through Microsoft Graph aren’t used to train foundation models; and that generated responses aren’t guaranteed to be 100% factual, so users should use their judgment before sending output to others. Limits: Applies to that product and its commercial terms only.
  2. Secure and governed data foundation for Microsoft Copilot: foundational deployment guidance Microsoft · May 6, 2026; updated August 18, 2026 · Product documentation Because Copilot can use anything the user can open, recommends finding overshared, ownerless and inactive sites, running access reviews, restricting broad sharing links, and archiving inactive sites and deleting obsolete files so answers stay current. Limits: Vendor guidance for administrators. Features depend on the license.
  3. Recommendation of the Council on Artificial Intelligence (OECD AI Principles) OECD · Adopted May 22, 2019; revised May 3, 2024 · Intergovernmental principles Calls for safeguards such as capacity for human agency and oversight (principle 1.2), accountability with traceability of datasets, processes and decisions (1.5), and systems that can be overridden, repaired or shut down safely (1.4). Limits: Not legally binding.
  4. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) US National Institute of Standards and Technology · July 26, 2024 · Voluntary framework Lists twelve risks of generative AI, including confabulation (confidently stated false content, sometimes with invented citations) and human-AI configuration, which covers automation bias and over-reliance. Limits: Voluntary. It was issued under an executive order that has since been revoked, and the wider framework is under revision.

Cite this page

Founderz (2026). Principle 2: A single source of truth for AI. The RUAI Standard, 2026 edition. Developed by Founderz in collaboration with Microsoft. https://responsibleai.founderz.com/toolkit/principles/single-source-of-truth

Licensed under CC BY 4.0: share and adapt with attribution.