# Source-of-Truth Map

Reusable LPM Knowledge Object v1.0

## Purpose

The Source-of-Truth Map identifies which system, artifact, owner, or governed record is authoritative for critical enterprise objects. It prevents teams, dashboards, AI tools, spreadsheets, meetings, and chat threads from creating competing truths.

## Metadata
| Field | Value |
| --- | --- |
| Object type | LPM Knowledge Object |
| Primary LPM layers | Information Ecology, Platform Structure, Governance Architecture, AI Amplification |
| Connected layers | Ownership Map, Decision Architecture, Communication Architecture, Identity & Incentives |
| Primary use | Identify the authoritative source for critical enterprise objects, evidence, decisions, metrics, policies, commitments, and AI outputs. |
| Website use | Downloadable template, workshop guide, AI readiness resource, JSON object for Lapemo ingestion, and future guided skill. |
| Version | 1.0 |
| Owner | LPM / Lapemo |
| Last reviewed | 2026-06-24 |

## Core principles
| Principle | What it means |
| --- | --- |
| One thing cannot have five truths | A business object may appear in many channels, but only one source should be authoritative for the current approved state. |
| Separate discussion from record | Chat, meetings, email, and AI summaries may discuss work, but the durable record must live in an approved system of truth. |
| Every source needs an owner | A source without an accountable owner becomes stale, duplicated, misused, or overtrusted by people and AI. |
| Evidence needs lineage | A claim is not reliable unless the source, owner, refresh date, confidence, and downstream use are visible. |
| AI cannot invent truth | AI may retrieve, summarize, route, classify, or recommend, but it must reference governed sources and expose confidence and human review rules. |
| Systems need boundary clarity | System of record, system of engagement, system of analysis, and system of action are different jobs and should not be confused. |
| Staleness is risk | A source-of-truth map must define review windows, freshness rules, exception handling, and supersession logic. |

## Required fields
| Field | Definition | Required |
| --- | --- | --- |
| Truth object ID | Unique identifier for the source-of-truth object, domain, data product, document, decision record, metric, policy, or AI output | Yes |
| Business object | What the source governs: customer, product, employee, policy, metric, decision, initiative, control, risk, asset, or agent | Yes |
| Truth statement | Plain-language statement of what the organization treats as authoritative | Yes |
| System of record | The approved system where the official state is stored | Yes |
| System of engagement | Where people interact, discuss, request, or collaborate around the object | Required when different |
| System of analysis | Where reporting, dashboards, metrics, or insights are generated | Required when metrics exist |
| System of action | Where work is executed, automated, or triggered from the source | Required when workflow exists |
| Accountable owner | Business role accountable for accuracy, use, change control, and dispute resolution | Yes |
| Technical owner | Technology, platform, data, or integration owner responsible for system reliability and access | Required when system-backed |
| Data steward / content steward | Role responsible for definitions, quality, metadata, retention, and review hygiene | Required when material |
| Primary consumers | Teams, roles, workflows, dashboards, agents, vendors, or controls that depend on the source | Yes |
| Approved uses | What the source can safely support | Yes |
| Disallowed uses | What the source must not be used to decide, automate, publish, or report | Yes |
| Freshness window | How current the source must be to be decision-grade | Yes |
| Evidence standard | Proof required before the source can support a decision, governance action, AI recommendation, or external commitment | Yes |
| Confidence rating | High, medium, low, provisional, stale, disputed, or retired | Yes |
| Lineage / dependencies | Upstream sources, transformations, approvals, integrations, and downstream records that depend on this truth object | Yes |
| Sensitivity level | Public, internal, confidential, restricted, regulated, customer-sensitive, employee-sensitive, legal-sensitive | Yes |
| Access rule | Who can view, edit, approve, export, automate, or supersede the source | Yes |
| AI use rule | Whether AI can retrieve, summarize, classify, recommend, update, or act on the source | Yes |
| Human review rule | When a human owner must validate the source before it is used by people or AI | Required when material |
| Exception path | Where conflicts, stale records, duplicate truths, missing owners, or disputed sources are escalated | Yes |
| Supersession rule | How a source replaces another source, retires duplicates, or marks prior records as obsolete | Yes |
| Review date | Date the source must be reviewed again | Yes |
| Version | Artifact version, owner, last reviewed date, and change history | Yes |

## Truth object types
| Object type | Common source systems | What it governs | Primary consumers | Failure risk |
| --- | --- | --- | --- | --- |
| Customer / account truth | CRM, customer master, support system, data platform | Customer identity, commitments, tier, renewals, support status | Sales, success, support, finance, AI agents | Duplicate customer records, unsupported AI outreach, stale commitments |
| Employee / org truth | HRIS, identity platform, org chart, access system | Role, manager, team, cost center, access, employment status | People leaders, finance, IT, compliance, workforce AI | Wrong routing, access errors, shadow org structures |
| Work / delivery truth | Jira, Azure DevOps, ServiceNow, portfolio tool | Initiatives, backlog, dependencies, owners, status, blockers | Product, engineering, transformation, executives, agents | Hidden work, conflicting status, AI prioritizing stale work |
| Decision truth | Decision Log, governance workflow, board / executive records | Decision, owner, rationale, evidence, effective date, supersession | Leadership, delivery teams, governance, AI assistants | Decisions lost in meetings, conflicting interpretations |
| Metric truth | Metric registry, BI semantic layer, finance system, data catalog | Definition, formula, source, owner, refresh cadence, threshold | Executives, operators, analysts, AI insight tools | Competing dashboards and false confidence |
| Policy / control truth | GRC, policy repository, legal system, security platform | Policy, control, exception, approval, control owner, audit evidence | Risk, compliance, security, audit, AI governance | Unreviewed exceptions, outdated controls, unsupported AI decisions |
| Knowledge truth | Confluence, SharePoint, knowledge base, LMS | Playbooks, SOPs, architecture, onboarding, operating standards | Employees, vendors, AI search, onboarding, support | Stale guidance becoming AI training context |
| AI initiative truth | AI Initiative Owner Register, model registry, vendor system | Use case, owner, value, risk tier, model, data, controls, human review | AI governance, product teams, executives, legal, audit | Pilot sprawl, no accountable business owner |
| AI output truth | Source system plus AI output log or review queue | Generated summary, recommendation, classification, action, confidence, reviewer | Operators, customers, governance, agents, analytics | AI output treated as fact without source and review |
| Vendor / integration truth | Vendor inventory, CMDB, API gateway, procurement system | Vendor, system, integration, contract, data flow, owner, SLA | Procurement, IT, security, data, risk, product | Unknown dependency, unmanaged data sharing, broken integrations |

## Source roles
| Role | Purpose | Boundary | Examples |
| --- | --- | --- | --- |
| System of record | Stores the official approved state | Owns the current truth of the object | HRIS for employee status, CRM for customer record, GRC for control exception |
| System of engagement | Supports human collaboration and interaction | Can discuss or request changes, but does not replace the record | Teams, Slack, email, meeting notes, forms |
| System of analysis | Transforms records into metrics, trends, and insights | Can analyze truth, but must link back to governed definitions and source data | BI dashboard, data warehouse, semantic layer, metric registry |
| System of action | Executes workflow, automation, notifications, tasks, or agentic action | Can act only inside approved boundaries and with valid source references | Workflow tool, agent platform, service desk automation, orchestration layer |
| System of evidence | Stores proof that a claim, decision, control, or output is valid | Can support decisions, audits, AI recommendations, and reviews | Evidence pack, source logs, audit trail, data catalog, lineage graph |
| System of memory | Preserves durable organizational knowledge over time | Can teach future teams and AI what was decided, why, and under what context | Decision log, knowledge base, policy repository, architecture record |

## 500+ employee company version
| Category | Guidance |
| --- | --- |
| Design intent | Create basic source discipline before the company outgrows founder memory, local spreadsheets, and tribal knowledge. |
| Core sources | CRM, HRIS, work system, finance system, knowledge base, decision log, and AI initiative register. |
| Biggest risk | People treat Slack, email, meetings, and spreadsheets as truth because the real record is unclear or missing. |
| Minimum rule | Every critical business object gets one source of record, one accountable owner, and one review cadence. |
| Operating pattern | Quarterly source review, simple duplicate-source cleanup, clear channel guide, and owner validation for AI summaries. |
| AI focus | AI may retrieve and summarize only from approved sources. Unowned or stale content should be flagged, not amplified. |

## 5,000+ employee company version
| Category | Guidance |
| --- | --- |
| Design intent | Standardize truth across functions so every department does not create its own private version of customers, work, metrics, policy, and decisions. |
| Core sources | Enterprise CRM, HRIS, finance, portfolio, service desk, GRC, data platform, knowledge base, metric registry, decision log, AI registry. |
| Biggest risk | Competing dashboards, duplicated systems, and function-specific truth create cross-functional coordination drag. |
| Minimum rule | Material dashboards, decisions, controls, and AI workflows must link to approved sources with owner, freshness, and confidence visible. |
| Operating pattern | Domain-level source owners, monthly exception review, quarterly source rationalization, and formal source-change governance. |
| AI focus | AI should classify source confidence, detect stale or duplicate sources, and route exceptions to accountable owners. |

## 10,000+ employee company version
| Category | Guidance |
| --- | --- |
| Design intent | Operate source-of-truth governance as enterprise infrastructure across regions, business units, regulations, platforms, and AI control planes. |
| Core sources | Master data, data catalog, metric registry, model registry, GRC, CMDB, API gateway, identity, finance, HRIS, CRM, portfolio, knowledge, decision and evidence systems. |
| Biggest risk | The enterprise runs on federated truths without visible lineage, creating audit exposure, AI hallucination risk, and slow executive decisions. |
| Minimum rule | Every enterprise-critical source needs lineage, sensitivity, control owner, review SLA, AI access rule, and supersession governance. |
| Operating pattern | Federated source owners, enterprise metadata standards, automated drift/staleness detection, and executive review of critical truth conflicts. |
| AI focus | AI agents must be source-bound, confidence-aware, permission-aware, and blocked from using stale, disputed, or unowned truth objects. |

## Confidence states
| State | Definition | Use rule |
| --- | --- | --- |
| High confidence | Named owner, approved system, recent refresh, documented lineage, governed access, clear AI rule | Decision-grade and automation-eligible inside approved boundaries |
| Medium confidence | Owner exists and source is mostly current, but lineage, definition, or downstream dependency is incomplete | Can support team-level decisions with owner review |
| Low confidence | Source exists but owner, freshness, quality, access, or definition is weak | Do not use for material decisions without validation |
| Stale | Freshness window missed or review date expired | Flag, route to owner, and block from AI-generated material conclusions |
| Disputed | Multiple sources disagree or teams challenge the authoritative record | Escalate through source owner, data steward, or governance forum |
| Retired | Source has been superseded or should no longer be used | Archive, redirect, and prevent future AI retrieval or workflow use |

## Workshop flow
| Step | Instruction |
| --- | --- |
| 1. Inventory critical truth objects | List the business objects that people, systems, dashboards, decisions, controls, and AI workflows depend on. |
| 2. Separate channel from record | Identify where the object is discussed versus where the official state is stored. |
| 3. Assign owners | Name the accountable business owner, technical owner, and steward where required. |
| 4. Define evidence standard | Clarify what makes the source decision-grade, audit-grade, customer-grade, or AI-safe. |
| 5. Map lineage and consumers | Connect upstream sources, downstream systems, dashboards, workflows, agents, and decisions. |
| 6. Set AI use rules | Define whether AI can retrieve, summarize, classify, recommend, update, or act on the source. |
| 7. Score confidence | Rate the source as high, medium, low, stale, disputed, or retired. |
| 8. Resolve conflicts | Route duplicate, stale, disputed, or unowned sources through the exception path. |
| 9. Publish the map | Store the map in the website resource, knowledge base, and Lapemo ingestion object. |
| 10. Review and supersede | Update owner, status, source, lineage, and AI rules whenever systems or workflows change. |

## Validation rules
| Condition | Rule |
| --- | --- |
| No owner | Flag as not decision-grade and assign an owner before use by AI or governance. |
| No system of record | Classify as unmanaged truth. Route to source rationalization. |
| Duplicate source | Mark as disputed until one record is approved or roles are clarified. |
| Stale review date | Downgrade confidence and notify accountable owner. |
| AI use with no source link | Block from material communication, decision, or automation. |
| Sensitive source with broad access | Escalate to access owner, security, legal, or compliance depending on data type. |
| Dashboard without metric definition | Mark as analysis-only, not decision-grade. |
| Workflow action without authority boundary | Block autonomous action until decision rights and controls are defined. |
| Retired source still referenced | Redirect consumers and update AI retrieval rules. |

## Scoring model
| Dimension | Score | Question |
| --- | --- | --- |
| Owner clarity | 0-5 | Is there a named accountable owner and backup owner? |
| System clarity | 0-5 | Is the record, engagement, analysis, action, and evidence role clear? |
| Evidence quality | 0-5 | Is the source current, defined, linkable, and supported by evidence? |
| Lineage visibility | 0-5 | Are upstream and downstream dependencies known? |
| Access and sensitivity control | 0-5 | Are permissions, retention, and sensitivity rules appropriate? |
| AI readiness | 0-5 | Can AI safely retrieve, summarize, recommend, or act with source links and human review? |

## AI prompts
| Prompt | Instruction |
| --- | --- |
| Classify truth object | Given this source description, classify the business object, source role, owner type, sensitivity, and AI use boundary. |
| Detect duplicate truth | Compare these sources and identify whether they represent duplicate, conflicting, complementary, or superseded records. |
| Score source confidence | Score owner clarity, system clarity, evidence quality, lineage, access control, and AI readiness from 0 to 5. Explain each gap. |
| Generate exception | Draft an exception record for a stale, disputed, unowned, or unsafe source with recommended owner and escalation path. |
| Create website version | Render this source-of-truth map as a website artifact with executive summary, worksheet table, and workshop instructions. |
| Create Lapemo ingestion object | Convert the completed map into JSON with IDs, owners, systems, source roles, confidence, evidence links, and AI rules. |

## Example register rows
| ID | Business object | Source | Role | Owner | Truth governed | Freshness | AI rule | Confidence |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| SOT-001 | Customer account | Salesforce | CRM | VP Sales Ops | Customer master, account owner, tier, renewal status | Weekly | AI can summarize account context. Human approves customer-facing commitments. | High |
| SOT-002 | Enterprise decision | Decision Log | Governance / decision memory | COO or delegated decision owner | Decision, rationale, evidence, effective date, supersession | At decision time and quarterly review | AI can retrieve and summarize with source link. Cannot supersede decision. | High |
| SOT-003 | AI use case | AI Initiative Owner Register | AI control record | Business initiative owner | Use case, value, risk tier, data, controls, human review | Monthly | AI can classify status. Owner approves risk or value changes. | Medium |
| SOT-004 | Metric definition | Metric Registry | Semantic / analytic truth | Data product owner | Metric formula, source data, threshold, dashboard use | Monthly or when formula changes | AI insights require metric owner, freshness, and confidence display. | Medium |
| SOT-005 | Policy exception | GRC Platform | Control and audit truth | Risk control owner | Exception, approval, control impact, expiration, evidence | At approval and expiration | AI can summarize status. Human control owner approves disposition. | High |

## Website positioning

Use this artifact as a downloadable resource and as a guided LPM skill. A company can complete the worksheet manually, upload it during Lapemo onboarding, or convert it into a governed source object that can be scored, reviewed, superseded, and mapped to systems and AI workflows.
