Minimize and filter retrieved context before generation: What additional control is most important?
Authorization is necessary but insufficient; minimize authorized context before generation to reduce unnecessary disclosure.
The question
An insurance assistant retrieves claim files, policy manuals, and investigation notes. Document-level permissions are checked at retrieval, but the assistant places the entire authorized context into its prompt before answering. What additional control is most important?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Minimize and filter retrieved context before generation. ✓Even authorized material should be limited to what the task requires; context minimization reduces unnecessary disclosure through prompts, outputs, and citations.
- Require confirmation before opening cited documents.Confirmation before opening a citation does not prevent sensitive material from being included in the prompt or answer.
- Add more policy manuals for broader coverage.More manuals may improve coverage, but they do not reduce unnecessary exposure of claim or investigation material already retrieved.
- Encrypt the prompt and response in transit.Encryption protects transmission, but it does not limit the sensitive content assembled into the prompt or generated response.
The trap
Check both who may access a document and whether the task actually requires placing its contents in model context. How to remember it
Authorization is necessary but insufficient; minimize authorized context before generation to reduce unnecessary disclosure.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Fine-tuning does not ensure current facts: What specific risk remains? →
- Enforce approval before the tool can submit: The team proposes relying on a system instruction saying, “Do not →
- The model may confidently propose unsupported routes: Which residual risk still most specifically requires →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.