Skip to content

Tenant Data Boundaries & Authority Hierarchy

OrviQ enforces a strict logical boundary between Product Knowledge and Tenant Knowledge, governed by an immutable authority hierarchy.


Knowledge Layer Separation

  • Product Knowledge (Global / Shared): Official customer documentation published from docs.orviq.io. Contains no tenant data, customer records, or credentials. Accessible equally to all tenants.
  • Tenant Knowledge (Isolated / Authoritative): Private organizational records (requirements, internal controls, risks, policies, evidence). Scoped strictly to the authenticated tenant.

Authority Hierarchy

When synthesizing responses, OrviQ Assistant adheres to the following source precedence:

1. Authenticated Application / Page Context (Active Screen)

2. Authoritative Tenant Structured State (Database Records)

3. Tenant-Authorized Document Context (Uploaded Evidence / Policies)

4. Official OrviQ Product Documentation (docs.orviq.io)

5. General Model Knowledge (Language formatting only)

::: important Authority Principle Documentation explains product concepts and procedures, but never overrides tenant state. For example, documentation may define what Effective means, but the Assistant will never report that CTL-2026-0004 is Effective unless actual tenant records say so. :::

OrviQ Enterprise Governance, Risk & Compliance Platform