Can we demonstrate a user only saw what they were entitled to?
This is the question that decides whether an AI deployment survives an access audit. Demonstrating it requires more than asserting that a filter was in place; it requires showing what the requester's surface actually contained at the time.
Audience and role assignments travel with each record in Centralpoint, and because restricted material is excluded during ingestion rather than filtered from results, the surface available to a given identity is derivable from record classification rather than from filter behaviour. The Interaction Log records the requester alongside what was retrieved, so the claim can be evidenced per execution rather than argued in general.