Figure 3

Audit any deployment

Eight questions to take into a vendor conversation — including ours. Answers should be specific enough to write down. The blanks that stay blank are the map of the remaining risk.

01

Data location

Where do originals, indexes, queries and answers reside — and can that differ by project?

02

Media processing

Where are previews, thumbnails and transcripts created? Is full media transferred to make them?

03

Model access

What exact content reaches each model? Can external processing be disabled per source?

04

Storage and retention

How long are prompts, answers and derived assets kept, and by whom?

05

Permissions

Does the assistant inherit existing user and project access, or expose a broader view?

06

Provenance

Can every answer lead back to inspectable evidence? How are conflicting sources shown?

07

Operations

Who maintains, updates and monitors it? What capacity does indexing need?

08

Exit and deletion

Can indexes and derived assets be exported or removed? How is deletion verified?

These questions are useful whatever the final topology. Their purpose is not to steer every studio towards the same answer, but to replace assurance with an operating model.