Facility teams are beginning to use artificial intelligence (AI) to search manuals, summarize work histories, and assemble operating context. Retrieval can make those systems more useful, but it can also make a wrong answer look unusually credible. An authentic policy, equipment export, public page, and manager note can all be relevant without having equal authority, the same effective period, or permission for the same audience.

That distinction matters whenever an AI answer could influence access, maintenance, vendor dispatch, customer communication, or another real facility decision. Finding a passage is not the same as establishing that the passage governs the question. Facility leaders need an operational memory contract: a small set of rules that determines what retrieved content may support, for whom, as of when, and with what consequence.
Relevance Is Only the First Gate
A retrieval system typically ranks passages that appear similar to a question. Facility operations need five additional tests.
First, identity: Does the passage describe the correct building, asset, zone, tenant, policy, work item, or event?
Second, authority: Is the source allowed to govern the fact being asked about? A public page may govern posted hours, a controller export may show programmed state, and a technician note may document an observation.
Third, effective time: Was the assertion in force at the time the user means? Upload, observation, and effective time answer different questions.
Fourth, entitlement and purpose: May this user see the content, and may it be used for this task? Permission to use an AI interface should not imply permission to retrieve every indexed record.
Fifth, consequence: Is the evidence informational, suitable for a draft, eligible for a recommendation, or sufficient only to trigger human review? A retrieved sentence should never grant itself authority to act.
These tests turn a document collection into governed operational memory. Each admitted assertion needs an immutable identity; subject and claim type; source owner and authority; effective period; audience and purpose; provenance; supersession or challenge state; stable citation address; and maximum consequence. The schema can vary. The distinctions should not.
A Fictional Access-Hours Conflict
Consider a fictional self-storage facility called Harbor Annex. Its retrieval corpus contains four authentic items:
- A public facility page captured August 1 says gate access is 6:00 a.m. to 10:00 p.m.
- A controller configuration export captured August 18 shows a 6:00 a.m. to 9:00 p.m. schedule.
- A manager memo effective August 20 authorizes temporary 24-hour access for one approved contractor through August 23.
- A year-old brochure says “access anytime.”
A tenant asks, “Can I enter at 11 tonight?”
All four items concern access, but a model should not merge them by majority vote. The brochure is superseded and does not govern current access. The contractor exception does not apply to the tenant. The controller export describes programmed state, while the public page describes the current public statement. Those last two sources conflict.
The useful answer is therefore bounded: the posted public hours end at 10:00 p.m.; the observed controller schedule ends at 9:00 p.m.; the 24-hour exception does not apply; and the unresolved difference requires facility confirmation before anyone promises entry.
For an operator investigating a denial at 9:35 p.m., the same evidence can explain the mismatch and open a reconciliation item. It still should not modify the controller or contact tenants without authorization.
This example is fictional, but the design lesson is practical. A trustworthy response should return an evidence packet, not just prose: the question, subject, as-of time, answer or abstention, supporting assertions, source versions, effective periods, conflicts, excluded items, missing facts, consequence class, and next action.
A 30-Minute Implementation Ladder
A facility team can begin with one 30-minute exercise around a narrow question such as public hours, a recurring alarm, or an active water-leak procedure.
During the first 10 minutes, collect three to five sources. Name the facility and fact each may support. Record the owner and effective period. If no one can say which source governs, mark the gap.
During the next 10 minutes, assign each source an audience, purpose, supersession state, and maximum consequence. Quarantine unknown, conflicting, or unapproved content.
During the final 10 minutes, write five tests:
- The correct answer using the current governing source.
- A historical question that must use the earlier version.
- A user who is not entitled to one relevant source.
- A conflict that must be surfaced rather than averaged away.
- A request whose consequence requires review or abstention.
Record expected citations and stop behavior. Rerun the tests when a source, identity, permission, retrieval method, model, or policy changes.
Current guidance supports pieces of this model without making it a universal standard. NIST’s voluntary AI Risk Management Framework addresses governing, mapping, measuring, and managing risk. Its 2024 Generative AI Profile includes suggested actions for provenance, retrieval grounding, source review, and retesting after retrieval changes. Joint 2025 guidance from NSA, CISA, FBI, and international partners addresses AI data provenance, integrity, access, malicious modification, and drift. W3C PROV-O supplies general provenance vocabulary. Facility leaders still must translate those references into an operating contract.
The most important rule is simple: Retrieval can propose evidence, but it does not establish authority. When a facility system keeps identity, authority, effective time, entitlement, conflict, and consequence visible, AI can accelerate operational understanding without quietly becoming the decision-maker.
Jared Mastroianni is chief operating officer of modSTORAGE and CEO and co-founder of Facily.ai. His work focuses on multi-location operations, data governance, human review, and bounded uses of AI in self storage.
