Operating model
The company brain, honestly.
The last post made the case for putting a centralised brain at the middle of your company. Here, "brain" means a governed system that stores sources, retrieves relevant material and helps people reuse past decisions. It is not a mind, and it should not become an invisible authority. This is the harder question: when does shared memory help, and when does it become surveillance with a search box?
The upside, named honestly
What the brain actually buys
The useful part is continuity. A team can keep the policy, decision, evidence and later correction together instead of scattering them across inboxes and memories. That can make a repeated question faster to answer and a disputed decision easier to inspect. It is also a practical way to retain useful organisational context while the models and interfaces around it change.
None of those benefits arrive merely because more material was captured. They depend on curation, source quality and permission design. A larger corpus can improve recall while making the correct record harder to find. The honest promise is narrower: well-governed memory can reduce repeated searching and make some decisions more traceable. It does not remove management, judgement or the people who understand the work.
Every durable memory needs a ledger
A stored answer is not trustworthy until the system records why it exists and who governs it.
- Purpose The decision or workflow this memory is allowed to support.
- Source and date Where the claim came from and when it was observed.
- Owner and authority Who can correct, approve or override it.
- Access and retention Who can see it and when it should expire or be deleted.
- Review trigger The event that forces re-evaluation.
If the ledger cannot be filled in, the memory should not silently guide consequential work.
The bill nobody itemizes
What it quietly costs
Privacy starts before encryption. Ask what the system is allowed to know and why. Purpose limitation means collecting and using information for a defined job, not keeping everything because it might be useful later. A support system may need an order, the customer's messages and the refund policy. It does not automatically need private staff chats, health details or a manager's notes.
Access should follow the same discipline. Give each role only the records needed for its task, log sensitive access and separate customer service from employee performance use. Set retention periods, then delete raw and derived copies when their purpose or legal basis ends. Deletion must reach indexes, summaries and backups according to the organisation's policy, not just the original upload.
Employees and customers may have rights to notice, access, correction, deletion, objection or review of automated decisions, depending on the data, purpose and jurisdiction. Employment consultation and sector rules may add further duties. This is an operating checklist, not legal advice: privacy, employment and security specialists should determine the actual obligations before collection begins.
If you cannot state the purpose, authorised users and deletion rule in plain language, the corpus is not ready to ingest.
The failure that compounds
When the summary becomes the memory
A model-generated summary can omit a condition, combine incompatible sources or state an inference as fact. Reuse then amplifies the error. A neat paragraph copied into onboarding, support and planning can outrank the messier source simply because it is easier to read.
The control is provenance: every important claim links to its source, author, date and applicable scope. Keep the source as the authority, version the synthesis and show when it was last checked. A correction path must let an authorised person challenge a record, attach evidence, amend it and identify downstream summaries or decisions that may now be stale. The same concentration risk appears when we treat an organisation like one context window: whoever selects the visible context can shape the answer.
Where to start (small)
One loop, well-built, that you can audit
Consider one narrow loop: helping a support lead decide whether a customer should receive a refund for a duplicate charge. Its purpose is decision support for that request, not employee scoring or future marketing. The allowed sources are the order record, payment event, customer ticket and current refund policy. Access is limited to the assigned support team and authorised reviewers.
The system retrieves those sources and proposes: "refund the second charge," with links to the two payment IDs and the policy clause. A human support lead checks the evidence, makes the final decision and records the reason. If the customer corrects the order history, the record is amended, the recommendation is rerun and the earlier decision is marked for review. The ticket and derived summary follow a stated retention schedule, and a rights request enters the organisation's normal privacy process.
Test the loop with representative approved cases before relying on it, then sample live decisions for missing sources and unequal treatment. The gate should measure the observable decision support, not how persuasive the prose sounds. This is the same discipline as insisting that "done" needs evidence.
One governed memory loop
The system should make every step from collection to deletion visible and interruptible.
- Collect for a named purpose Do not gather knowledge merely because it may become useful.
- Classify and permission Apply sensitivity, ownership and retention rules.
- Retrieve with provenance Return the source and current status with the memory.
- Use under human authority Consequential action remains reviewable.
- Correct, supersede or delete Feedback changes the record instead of appending another contradiction.
A company brain is healthy when people can challenge the loop at every gate.
The honest call
Start with one bounded, reversible loop
Start with one bounded purpose, one owner and one decision that can still be reversed. Write down who may access the data, when each copy is deleted, how sources are cited, how a person corrects the record and which human has authority to decide. If the loop cannot satisfy those questions, adding more memory will make the weakness larger, not smarter.
My student instinct likes the elegance of shared organisational memory. My professional instinct asks who can see it, who can challenge it and who remains accountable. As a father, I also think privacy includes the right to remain a person rather than become an endlessly reusable record. A good company brain remembers enough to help, forgets what it no longer needs and leaves consequential authority with people.