Triage fixed your corpus-poisoning finding by editing the one bad row. What do you tell the owner?
answer
- concede the instance, argue the class
- one sentence gone is all you can claim
- a sample bounds nothing
- who owns the write path
- accepted risk is written down, not closed
basics
~20 sEditing the row closes one instance, not the class. The only defensible claim is that this sentence is gone; anything broader would require re-verifying every passage that can be retrieved, which nobody has funded or scheduled.
solid answer
~50 sSeparate the instance from the class out loud, because the edit genuinely resolved the instance and pretending otherwise loses the room. Then state what remains true: any account with write access to a field that is rendered into answers can restate a false fact, nothing in the pipeline evaluates a source against the world, and the resulting failure arrives labelled as model quality. Say plainly what a spot-check of the corpus can be claimed to buy - it samples, so it lowers the count of what is there and proves nothing about what is not. Then force the ownership question, which is the real decision: this is either a defect owned by whoever owns the write path into answering context, or an accepted design limit of grounding on an anyone-can-edit store. Both are legitimate answers; only leaving it as a closed model-quality ticket is not.
go deeper
Take away the distinction between fixing one instance and addressing a class - deleting a bad sentence does not tell you anything about the next one.
Be able to explain why nobody can produce a count of similar passages: they have no distinguishing features to search for, so only a domain reader can judge them.
Show you would write the residual down rather than smooth it over, and that you would not overstate what a corpus spot-check establishes.
Own the ownership call and its cost. Route the class to the write path, or get the design limit accepted in writing with a named owner - and say aloud that leaving it as model quality is what makes recurrence invisible.
## Why this is a judgment call and not a technical one Everything technical is already settled by the time this conversation happens. The sentence was authored, it was retrieved, the assistant repeated it faithfully, and somebody deleted it. What is unsettled is who owns the next one, what anybody is entitled to claim, and whether this goes on a risk register or back into a queue. Those are organisational calls, and a lead is expected to make them explicitly rather than let a ticket status make them by default. ## Concede the instance immediately The edit worked. The wrong sentence is gone, the answers change back, and the person who made the edit did something useful and cheap. Opening with anything other than agreement on that point turns a shared problem into a status dispute, and the class argument is the one that matters. ## Then state the class in one sentence The class is not a wrong definition. It is that a field editable by anyone, re-read by nobody, is rendered verbatim into answers that people quote as operational fact - and that the failure surfaces with no anomalous features anywhere, because nothing was commanded and the answer was faithful to what it was given. That is why it was originally filed as model quality, and why the same event would be filed that way again next time. If your write-up cannot survive being reduced to that sentence, it is not ready to be argued. ## Be precise about what can be claimed The assurance question is the one that trips people. Three claims are commonly conflated: | Claim | What supports it | |---|---| | This sentence is gone | The edit, and a re-run showing the answer changed | | Similar sentences are rare | Nothing, until somebody looks | | The corpus is clean | Re-verification of every retrievable passage against the world | The third is the one people ask for and the one nobody funds. It is not a scan; it is a domain expert disagreeing or not disagreeing with each passage, which scales with the corpus and not with the tooling. A sample lowers the count of what is there and says nothing about what is not - that is what sampling means, and it is worth stating in exactly those terms so that the residual risk is written down rather than assumed away. A claim you *can* make is narrower and more useful: the pipeline has no stage that evaluates a source against reality, so any confidence in the corpus is inherited entirely from the write path, and the write path currently has no review. ## Force the ownership question This is the decision the conversation exists to produce, and there are only three honest destinations. **It belongs to the write path.** If content that lands in answering context is going to be treated as a source, then whoever owns that store owns the fact that its contents become assertions. This is usually the right answer, and it is also usually the expensive one - which is precisely why the finding keeps being routed elsewhere. **It is an accepted design limit.** Grounding an assistant on a store that anybody can edit is a deliberate product choice with a known consequence, and an organisation is entitled to accept it. But accepting a risk means writing it down with a named owner and a review date, not closing a ticket. Say so, and let the acceptance be visible. **It stays a model-quality issue.** This is the only unacceptable outcome, because it is the one that guarantees a recurrence and hides it. The misdiagnosis is not incidental to this attack class - it is the mechanism by which the plant survives, and a lead should name that dynamic aloud. ## What to ask for, and what not to Resist the urge to arrive with a control design; you will lose the argument on cost and the room will hear a proposal instead of a risk. Bring the decision instead: which of the three destinations is this, who is the named owner, and by when is the acceptance reviewed. Bring the residual too - the honest statement that nobody can currently say what else is in the corpus, and that the number of such sentences is unknown rather than small. ## The uncomfortable part There is no way to promise that this does not recur, and a lead who promises it has traded credibility for a comfortable meeting. The defensible position is narrow and durable: one instance closed, one class open, an unknown residual, and a named owner who decided knowingly. That is a better outcome than a clean-sounding claim nobody can support the second time this happens.
- The owner asks for a number: how many more of these are in the corpus?The honest answer is that it is unknown, and that the only way to produce a number is a domain expert reading every retrievable passage. A sample gives you the count in the sample and no bound on the rest, because these passages have no distinguishing features to search for - they are fluent, on-topic and grammatically ordinary. Give the unknown as the finding rather than manufacturing a reassuring estimate.
- Is this a bug or a design limit?It depends on a decision nobody has made yet. If the store is intended to be an authoritative source, an unreviewed write into it is a bug in the ownership model. If the store is understood to be freely editable and the assistant grounds on it anyway, it is a design limit - legitimate, but one that belongs on a risk register with a named owner, not in a queue where it will be closed as a wrong answer.
- Why not just accept the model-quality classification and move on?Because that classification is what makes the construction durable. It closes the ticket, leaves the sentence in place, and teaches the organisation that this failure shape means the model needs work. The next instance will be triaged the same way and disappear the same way, so the classification is not a paperwork detail - it is the part of the system the attacker is relying on.
saying these in an interview costs you the question
- Claims the corpus is clean after a sample
- Argues the instance was not really fixed
- Promises the class cannot recur
- Leaves the finding filed as model quality
- Treats accepting the risk as the same as closing the ticket
- Assigns the defect to the model owner by default