A poisoning write's weakest link is a partner-run intake queue you don't control - whose finding is it?
answer
- root cause is outside your org
- index lockdown buys nothing here
- partner owns the review
- you own the decision to keep ingesting
- drop, demand assurance, or accept - name which
basics
~20 sIt is a shared finding whose root cause sits outside the team that runs the assistant. The assistant owner cannot fix the partner's review, and their instinct to lock down the index buys nothing against a write that never targeted the index. The real decision is whether to keep ingesting a source whose review they neither see nor set.
solid answer
~60 sPicture a compliance assistant that ingests a partner-run intake queue among its sources, and the poisoning write's weakest link is that queue's review - which the partner owns and the assistant team can neither see nor set. When you file this, the owner's first reflex is usually to tighten who can add documents to the index. That is the wrong door twice over: the write never targeted the index, and the failed review belongs to another organisation. So the finding does not have a single owner. The partner owns the review that let the write through. The assistant team owns a different decision they cannot delegate: whether to keep ingesting a source whose review strength is invisible to them and outside their control. What the index lockdown buys against this class is nothing. The honest options are to drop or quarantine that source from ingestion, to require review evidence or provenance from the partner, or to accept the residual risk explicitly and knowingly. A lead has to name which of those they are choosing and why - the one thing they cannot do is claim the index control closed it.
go deeper
Not expected at this level; recognising that the weak review sits at a source outside the team is already strong.
Be able to say why an index control does not address a write that entered at an external source, without owning the organisational decision.
Explain the ownership split and that the team's real lever is the ingestion decision, not the partner's review - and diagnose why the reflex fix misses.
Own the call: split ownership across the boundary, name the defensible option among drop, demand assurance, or accept residual, and refuse to report the index lockdown as a fix.
## Why this is a judgment, not a fix Most findings have an owner and a patch. This one crosses an organisational boundary, so it has neither cleanly, and that is what makes it a principal-level call rather than a harder technical one. The setting: a compliance-answering assistant builds its corpus by ingesting several outside sources, one of which is a partner-run intake queue. Analysis shows the cheapest, most durable poisoning write goes through that queue, because its pre-publication review is the weakest of the sources - and that review is owned, staffed and set by the partner, not by the team running the assistant. From inside the assistant team, the strength of that review is invisible and unchangeable. ## The reflex that buys nothing The assistant owner's instinct is almost always to tighten control of the index: restrict who can add documents, lock the store. Naming why that fails is the core of the answer. The write never targeted the index - it entered at the queue and was carried in by a trusted build. And the review that failed is the partner's, which no index control touches. So the index lockdown, whatever else it is worth, buys nothing against this class of write. A lead who reports "we fixed it by locking the index" has mis-described the finding. ## Splitting the ownership The finding is genuinely shared, and the split is worth stating precisely: - **The partner owns the review.** The write got past the queue's editorial step; making that step stronger is the partner's action, on the partner's staff and budget, and the assistant team cannot perform it. - **The assistant team owns the ingestion decision.** They chose to union this source into a corpus that answers real questions. That decision - to keep trusting a source whose review they cannot see or set - is theirs, and it cannot be delegated to the partner. It is the part they can actually act on. ## The honest options Under this split, a lead is choosing among a small set, none of which is "lock the index": - **Drop or quarantine the source** from ingestion, accepting the loss of whatever value it added. - **Demand assurance from the partner** - evidence of review, provenance on submissions, an SLA on turnaround and reversion - and continue ingesting only if it arrives. - **Accept the residual risk** explicitly, documenting that a source with unseen review feeds the corpus and that this is a known, owned exposure. The judgment is which of these to choose, given what the source is worth, what the partner will agree to, and how much the compliance domain can tolerate a wrong answer sourced from a poisoned entry. There is no single right choice; there is a defensible one and an indefensible silence. ## What a lead must not do The one move that is simply wrong is to claim the index control resolved it. That misstates where the write enters and where the review lives, and it leaves the actual exposure - an ingested source with unseen, unowned review - in place while reporting it closed. The whole value of the principal answer is refusing that misdescription. ## The organisational shape Stepping back: teams draw their security boundary around what they build and operate - the index, the prompt, the model calls. But ingestion pulls content across that boundary from sources whose controls they do not own. The poisoning target is chosen precisely at the source with the weakest of those unseen controls. So the finding forces an uncomfortable admission: part of the corpus's trustworthiness is delegated, by the act of ingestion, to organisations whose review the team cannot inspect. Owning that - deciding consciously what to ingest and on what assurance - is the actual work, and it is not something an index ACL can stand in for. ## Why interviewers ask it It tests whether a candidate can hold a finding whose fix is not theirs to make, resist the reflex control that misses, split ownership honestly across an org boundary, and name a defensible decision under constraint. That is the lead's job on exactly this class of finding, and the tell of a weak answer is reaching for the index lockdown and calling it done.
- The assistant owner wants to close this by tightening who can add documents to the index. What do you tell them?That it does not touch this finding. The write never targeted the index; it entered at a partner-run source and was carried in by a trusted build, and the review that failed is the partner's, which no index control reaches. Tightening the index may be worth doing for other reasons, but reporting it as the fix here misstates where the write enters and leaves the real exposure open.
- If the partner won't strengthen their queue's review, what is left to decide?The decision the assistant team actually owns: whether to keep ingesting that source. The honest options are to drop or quarantine it, to require provenance or review evidence on each submission before trusting it, or to accept the residual risk explicitly and document it. What is not acceptable is continuing to ingest silently while claiming the exposure is closed. The lead names which trade they are making and why.
saying these in an interview costs you the question
- Closes the finding by locking down the index
- Assigns the whole finding to the assistant team alone
- Assumes the team can fix a partner's review
- Continues ingesting silently and reports it resolved