What is a retrieval surface and why should we care?
The term matters because it separates two things organizations usually conflate: everything they hold, and everything the AI can reach. In most deployments the second is defined by a filter's behaviour rather than by the index's contents, which means the honest answer to 'what could this user have retrieved' is 'whatever the filter would have allowed' — a statement about code, not about content.
In Centralpoint the surface is constrained during ingestion, so it is describable directly: these records, with these classifications, visible to these audiences. Audience and role assignments travel with each record, so two people asking the same question draw from genuinely different surfaces. Asked what a given user could have reached on a given date, the answer is reconstructable from record classification rather than reasoned from filter logic.