Grounded answer citations

Handle a citation that staff can no longer open

A failed source link may indicate a moved document, changed access or missing historical evidence. Establish which one happened before changing the answer.

In this article

Preserve the answer's evidence record

When someone reports a broken citation, capture the answer identifier, reference identifier and failure time. Find the source key and version recorded when the answer was generated. Avoid beginning with a broad search for a similarly named document. That can lead to repairing the link against the wrong evidence.

Check whether the failure affects one user, one document or a whole source system. A user-specific failure suggests an access difference. A widespread failure after a connector change suggests routing, credentials or source availability. This first distinction narrows the investigation without exposing document text in a support ticket.

Do not ask the reporter to paste confidential evidence into a general chat channel. Use the established support path for the information involved.

Distinguish access denial from absence

A document may still exist while the reader no longer has permission to open it. Confirm access through the source system or the application's authoritative permission check. Do not restore access merely to make an old answer look complete.

If the source was moved, determine whether its stable identifier still resolves. A path change may be repairable without changing the evidence relationship. If the document was replaced, the new version is not automatically equivalent. Compare the recorded passage or version metadata before redirecting the reference.

Where historical versions are unavailable, say that the original evidence can no longer be inspected. Pointing silently to the current version hides an important limitation and can make an old answer appear to reflect a later policy.

Contain misleading answers

If the incident affects a widely used answer, consider marking it as needing revalidation or preventing further reuse. The response should reflect the consequence of the answer, not just the number of broken links. An inaccessible reference beside a casual overview differs from one beside an instruction staff rely on to approve work.

Re-generation is not a universal repair. It may produce a different answer from current material, while users still need to understand the basis of the earlier one. Keep the distinction between restoring an old evidence trail and producing a new answer clear in the interface and record.

If cached excerpts are involved, check their retention and access rules. Revoking the destination link does not remove evidence already stored with the answer.

Close with a verifiable repair

Test the repaired path with an account representing the affected reader. Confirm the document identity, version and relevant passage, not just an HTTP success response. For access incidents, also test a reader who should remain denied.

Record the root cause and the chosen treatment of affected answers. Add a regression check at the failed boundary, such as stable identifier resolution or version-aware links. Operational monitoring can detect rising reference failures, but periodic review of historical answers is still useful where source systems routinely replace documents without preserving old versions.

Primary sources

OWASP: authorisation guidanceOWASP: logging guidance

References checked 11 September 2026.