Review and access
Human responsibility, scoped source access and sharing considerations for a future MapToc pilot.
A useful program record also needs a clear account of who can contribute, review and read it. Access and review are design requirements to validate before a pilot uses sensitive material.
Start with a defined boundary
The organization should select the program, sources and users included in the pilot. It should decide which information can be processed and which material must be excluded or redacted. Shared organizational documentation is not automatically appropriate for wider circulation.
Separate responsibilities
Contributors supply the source material. Reviewers assess proposed statements. Program owners define the record's intended use and resolve questions about responsibility. Readers receive access appropriate to their role. These are proposed roles; the exact permission model is still to be implemented and tested.
Preserve human judgement
An AI suggestion should never be presented as approved simply because a score is high or a sentence sounds plausible. The review should consider the source, the wording, uncertainty and whether the category fits. A numerical confidence display is not a substitute for that process.
Share evidence deliberately
Cross-program discovery should respect the original access restrictions. Useful lessons may be shared in a form that removes sensitive details, while original sources remain restricted. Public research articles on this website are separate from any future internal program archive.
Security and AI data use
MapToc should be built on enterprise AI infrastructure where customer content sent through professional API endpoints is not used to train public foundation models. This claim depends on the selected provider, contract terms and account configuration, so it should be documented before any government, donor or enterprise pilot.
The target architecture should also include tenant-level data separation, encryption in transit and at rest, role-based access control, audit logs and clear retention settings. Standard AI API services may retain logs temporarily for abuse monitoring unless Zero Data Retention or modified abuse monitoring has been approved. MapToc should describe these controls precisely in each pilot agreement rather than presenting them as already delivered certifications.
Questions to settle before live use
- Which source collections are included, and who authorises access?
- Who can approve, revise, export or remove evidence?
- How are personal and sensitive details handled?
- What happens to source links when permissions change?
- How will an organization retrieve its record when the pilot ends?
- Which AI provider, retention setting and tenant-isolation model will be used?
These are implementation and governance questions, not claims about security certifications or capabilities already delivered.
Transparency with defined access
The shared record is not an unrestricted surveillance feed. Institutions and implementers should agree which summaries, source passages and documents each role can see. Personal information and sensitive community feedback need appropriate restrictions or redaction.
The design should preserve corrections, disputed interpretations, source versions and review history. A program team must be able to explain or challenge a flagged issue. Financial anomalies and missing evidence should prompt investigation, not automatic accusations or payment decisions.
Updated 24 September 2026 · Map the Outcome