The CCFE Group AI Constitution

Control Before Capability.

AI should increase intelligence without surrendering control.

Across the CCFE Group ecosystem, artificial intelligence is governed by a common operating philosophy: AI may assist human judgment.  It does not replace human accountability.

Our approach extends beyond cybersecurity.

It governs:

  • Where data is processed and stored

  • Which systems may access that data

  • Which AI models may be used

  • What information may be submitted to AI

  • What AI may and may not do

  • How AI-generated findings are validated

  • How different divisions may share information

  • How models and integrations are approved

  • How decisions are documented

  • How incidents are contained

  • How human authority is preserved

The objective is not unrestricted automation.

The objective is controlled intelligence.

Preamble

Every division, platform, employee, contractor, model, agent, integration and automated workflow operating within our ecosystem is expected to operate under the same governing principles.

Technology may change.

These principles do not.

Article I

Human Accountability Is Non-Delegable.

§ 1
  • AI may analyze.

  • AI may compare.

  • AI may identify contradictions.

  • AI may summarize.

  • AI may calculate.

  • AI may identify patterns.

  • AI may surface risk.

  • AI may prepare recommendations.

  • AI may assist in producing reports.

§ 2

But AI does not become the responsible party.

Final commercial, contractual, estimating, operational and professional decisions remain subject to human authority.

There must always be an identifiable person or business function accountable for consequential decisions.

§ 3

AI can inform authority.  It cannot become authority.

Article II

Client Data Remains Client Data.

§ 1

Access to information does not create ownership of that information.

Client information is to be used only for authorized operational purposes.

§ 2

The governing standard prohibits unauthorized:

  • Sale of client information

  • Repurposing of client information

  • Distribution of client information

  • Cross-client exposure

  • Public disclosure

  • Contribution of client information to public AI training systems

  • Use outside the authorized business purpose

§ 3

Possession of data is not permission to use it without boundaries.

Article III

Data Placement Is a Security Decision.

§ 1

Where information resides matters.

Our infrastructure strategy is based on controlled data placement, jurisdictional awareness, system segmentation and defined access boundaries.

We do not believe sensitive project intelligence should move indiscriminately between systems simply because technology makes that possible.

§ 2

Data placement is evaluated according to factors including:

  • Sensitivity

  • Business purpose

  • Client requirements

  • Jurisdiction

  • System classification

  • Operational need

  • Access requirements

  • Retention requirements

  • Integration risk

§ 3

Detailed physical data center locations and infrastructure information are not publicly disclosed when doing so could unnecessarily increase security exposure.

Where appropriate, infrastructure region and data-handling information can be addressed directly with customers.

Transparency does not require publishing a roadmap to the infrastructure.

Article IV

Data Classification Before AI Access.

§ 1

Not every piece of information should be treated the same.

Our governance model recognizes different levels of data sensitivity.

§ 2
Public

Information approved for unrestricted public distribution.

  • Published marketing information
  • Public webpages
  • Publicly released documents
  • General industry information
Internal

Business information intended for authorized internal operations.

Confidential

Client, project, commercial or operational information requiring controlled access.

Restricted

Information requiring the highest level of handling, access and authorization.

§ 3

A system being technically capable of processing information does not automatically mean it is authorized to receive it.

Classification comes before convenience.

Article V

Data Center & Infrastructure Governance.

§ 1

Our architecture is designed around a simple principle: information should exist only where it has a reason to exist.

§ 2

Infrastructure controls are expected to address:

Segmentation

Sensitive systems and data environments should be separated according to operational function and risk.

Least-Privilege Access

Users, systems and AI services should receive only the level of access required to perform an authorized function.

Identity Control

Access should be attributable to identifiable users, services or approved system processes.

Encryption

Sensitive information should be protected during transmission and storage using appropriate encryption controls.

Logging

Material system activity should be capable of being recorded and investigated.

Backup & Recovery

Critical information should be protected against accidental deletion, corruption and operational disruption.

Controlled Integration

An available API, connector or integration does not automatically become an approved connection.

Environment Separation

Development, testing and production activities should be separated where appropriate.

Retention Control

Information should not remain indefinitely simply because storage is inexpensive.

Secure Disposal

Data that no longer has an authorized business or legal purpose should be subject to controlled deletion or disposition.

Article VI

SQUARES AI™: A Closed Construction Intelligence Environment.

§ 1

SQUARES AI™ is positioned as the Construction Intelligence Engine operating behind our ecosystem.

It was not developed around the idea of giving every employee unrestricted access to an AI chatbot.

It was developed around the opposite idea: control the intelligence layer.

SQUARES AI™ is intended to bring information together from approved sources, analyze that information within defined workflows and produce intelligence that remains subject to human governance.

§ 2

The system may support analysis involving:

  • Construction drawings

  • Specifications

  • Addenda

  • RFIs

  • Finish schedules

  • Scope information

  • Estimating information

  • Project correspondence

  • Historical project intelligence

  • Commercial documents

  • Approved enterprise information sources

§ 3

Connectivity does not eliminate governance.

Every additional data source expands intelligence — and expands responsibility.

Article VII

Approved AI Only.

§ 1

Employees and contractors should not be free to move company or client information into whichever AI application happens to be convenient.

Enterprise AI governance requires a distinction between:

Approved AI Environments

Systems evaluated and authorized for defined business purposes.

Unapproved AI Environments

Public, personal, experimental or otherwise unauthorized systems where company or client information should not be submitted.

§ 2

This includes apparently harmless activities such as:

  • Summarizing an email

  • Reviewing a contract

  • Uploading drawings

  • Checking pricing

  • Rewriting an RFI

  • Analyzing specifications

  • Summarizing meeting notes

  • Uploading customer spreadsheets

§ 3

A five-minute productivity gain is not sufficient justification for uncontrolled data exposure.

Article VIII

The Minimum Necessary Data Principle.

§ 1

AI should receive the information necessary to perform its authorized function.

Not everything available to the enterprise needs to be exposed to every model, workflow or employee.

§ 2

Before information is made available to AI, the governing questions are:

  • Does the system need this information?

  • Is the system authorized to receive it?

  • Is the user authorized to expose it?

  • Is there a less sensitive way to accomplish the same objective?

§ 3

More data does not automatically mean better governance.

Article IX

Evidence Before Assertion.

§ 1

One of the greatest risks in artificial intelligence is not simply a wrong answer.

It is a wrong answer presented with confidence.

Our Construction Intelligence philosophy therefore places a premium on evidence.

Where practical, material findings should be traceable to their underlying source.

§ 2

Examples include:

  • Drawing sheet

  • Detail

  • Specification section

  • Addendum

  • RFI

  • Finish schedule

  • Contract provision

  • Email

  • Approved project record

  • Other identifiable source material

§ 3

When evidence is unavailable, uncertainty should not be disguised as certainty.

Inference must remain distinguishable from fact.

Article X

AI Output Is Not Automatically True.

§ 1

AI-generated information may contain:

  • Errors

  • Missing context

  • Misinterpretations

  • Conflicting conclusions

  • Outdated information

  • Unsupported assumptions

  • False confidence

  • Fabricated information

§ 2

For that reason, AI-generated output should be evaluated according to the consequence of being wrong.

The greater the commercial, contractual, financial, legal, safety or operational consequence, the greater the expected level of human review.

Article XI

Prohibited Uses.

§ 1

Across the enterprise, AI should not be used to independently:

  • Execute contracts

  • Accept contractual obligations

  • Approve material commercial commitments

  • Submit bids without authorized human review

  • Create unauthorized scope commitments

  • Represent unverified information as established fact

  • Circumvent company security controls

  • Circumvent access restrictions

  • Upload confidential information into unapproved AI systems

  • Conceal the origin of fabricated information

  • Impersonate individuals without authorization

  • Make discriminatory employment or personnel decisions

  • Provide final legal determinations

  • Override required human approvals

  • Disable required audit or logging controls

  • Bypass established document-control processes

§ 2

Artificial intelligence is not a justification for eliminating established controls.

Article XII

No Autonomous Commercial Authority.

§ 1

AI systems operating within our ecosystem are not granted independent authority to bind the company or its clients.

Unless explicitly authorized through a separately controlled process, AI may not independently:

  • Commit pricing

  • Approve change orders

  • Accept substitutions

  • Approve contracts

  • Accept scope

  • Release contractual notices

  • Authorize payments

  • Execute purchases

  • Sign documents

  • Waive rights

  • Modify contractual obligations

§ 2

Commercial authority remains human authority.

Article XIII

Divisional Governance.

§ 1

The same AI Constitution applies across the organization, but implementation depends upon the function of each division.

CCFE Group

Provides the enterprise governance framework connecting the businesses operating within the ecosystem.

CDPC Partners, LLC

Provides ownership and operating oversight across the portfolio and establishes enterprise-level accountability.

Compass Global

Uses Construction Intelligence in support of pre-construction analysis, estimating intelligence and project reporting.  AI findings support professional review.  They do not eliminate estimator responsibility.

Division 09 Estimators

Uses controlled technology to support commercial flooring takeoffs and estimating.  Quantities, assumptions, scope interpretations and project conditions remain subject to estimator review.

Rogue IQ

Develops and advances Construction Intelligence technologies and the systems that support the broader ecosystem.

SQUARES AI™

Operates as the Construction Intelligence Engine connecting approved project information, enterprise data and governed analytical workflows.

HOLMES

Applies intelligence to contracts, specifications, submittals, product data, obligations and commercial documentation.  HOLMES provides Construction Intelligence and commercial document review.  It is not a substitute for legal counsel and does not provide legal advice.

Rhogan Research Institute

Supports the methodology, standards, benchmarking, testing and research necessary to advance Construction Intelligence as a disciplined field rather than an uncontrolled technology experiment.

Article XIV

Cross-Division Data Boundaries.

§ 1

Being part of the same corporate ecosystem does not mean every division automatically receives unrestricted access to every piece of information.

Access should remain purpose-driven.

Cross-division information sharing should consider:

  • Client authorization

  • Business necessity

  • Data classification

  • Contractual limitations

  • System permissions

  • Conflict concerns

  • Confidentiality obligations

  • Scope of engagement

§ 2

Enterprise integration does not mean enterprise-wide exposure.

Article XV

Model Governance.

§ 1

AI models change.  Providers change.  Capabilities change.  Risk changes.

A model that was appropriate for one workflow may be inappropriate for another.

AI governance therefore includes the model itself.

§ 2

Models and major AI components should be evaluated for factors such as:

  • Intended purpose

  • Data handling

  • Reliability

  • Security

  • Model behavior

  • Known limitations

  • Integration requirements

  • Vendor dependency

  • Output quality

  • Change risk

§ 3

Material model or architecture changes should be treated as governed system changes rather than invisible software updates.

Article XVI

Version Control & Change Management.

§ 1

A powerful AI system should not quietly become a different AI system overnight without anyone understanding what changed.

Material modifications to:

  • Models

  • Prompts

  • Agents

  • Data sources

  • Permissions

  • Integrations

  • Automated actions

  • Decision logic

  • Retrieval systems

should be subject to appropriate testing and change control.

§ 2

The question is not only: Does the new version work?

It is also: What new risk did the new capability create?

Article XVII

Agentic AI Requires Higher Control.

§ 1

Traditional AI produces information.  Agentic AI may be capable of taking actions.  That changes the risk profile considerably.

As systems gain the ability to:

  • Send communications

  • Modify records

  • Create documents

  • Trigger workflows

  • Access multiple systems

  • Execute transactions

  • Make decisions

the control requirements must increase accordingly.

§ 2

More autonomy should never mean less governance.

Article XVIII

Prompt Injection & Untrusted Content.

§ 1

Documents, websites, emails and other data sources may contain content designed to manipulate AI behavior.

Therefore, information entering an AI system should not automatically be treated as trusted instructions.

§ 2

Content is data.

System authority is separate.

An external document should not be able to rewrite the rules governing the system analyzing it.

Article XIX

Security Before Automation.

§ 1

We reject a common technology assumption: If something can be automated, it should be automated.

No.

Automation should exist only where the benefit justifies the risk and appropriate controls exist.

Some functions should remain intentionally human.

Article XX

The Human Override.

§ 1

Every consequential AI-supported process should preserve the ability for an authorized human to:

  • Challenge the result

  • Reject the result

  • Correct the result

  • Escalate the result

  • Disable the workflow

  • Require additional evidence

§ 2

AI systems should support judgment — not trap users inside automated conclusions.

Article XXI

Incident Response.

§ 1

AI incidents are not limited to traditional cybersecurity breaches.

An AI incident may include:

  • Unauthorized data disclosure

  • Improper access

  • Incorrect automated action

  • Model malfunction

  • Significant hallucination

  • Cross-client information exposure

  • Compromised integration

  • Prompt injection

  • Credential compromise

  • Unapproved system use

  • Unexpected model behavior

§ 2

Where necessary, the organization must be capable of isolating:

  • A user

  • A model

  • An integration

  • A data source

  • An automated workflow

  • An entire AI function

§ 3

Every intelligent system needs an off switch.

Article XXII

Auditability.

§ 1

Trust should not require blind faith.

Material AI operations should be designed so that authorized personnel can investigate what occurred.

Depending upon the system and risk level, this may include:

  • User activity

  • Source data

  • Model or workflow version

  • Generated output

  • Human changes

  • Approvals

  • Overrides

  • System actions

  • Timestamped events

§ 2

The more consequential the action, the more important the audit trail.

Article XXIII

Continuous Testing.

§ 1

AI governance is not a policy written once and placed in a binder.

Systems should continue to be challenged.

Testing may include:

  • Accuracy evaluation

  • Hallucination testing

  • Permission testing

  • Data-boundary testing

  • Security testing

  • Adversarial testing

  • Prompt-injection testing

  • Cross-client leakage testing

  • Workflow testing

  • Human-review testing

  • Failure-mode testing

§ 2

We are interested in what the system does when everything works.

We are equally interested in what happens when something goes wrong.

Article XXIV

Third-Party & Vendor Risk.

§ 1

AI governance cannot stop at systems we build ourselves.

Every external:

  • Model

  • Platform

  • API

  • Connector

  • Cloud service

  • Software provider

  • Data processor

may introduce additional risk.

§ 2

Convenience does not eliminate the need for vendor evaluation.

Article XXV

AI Literacy Is a Security Control.

§ 1

Technology alone cannot govern artificial intelligence.

People must understand its limitations.

Employees operating AI-supported systems should understand concepts including:

  • Hallucination

  • Data sensitivity

  • Confidentiality

  • Prompt injection

  • Verification

  • Human accountability

  • Approved versus unapproved systems

  • Escalation

  • Appropriate reliance

§ 2

A user who blindly trusts AI can defeat even a sophisticated technical control environment.

Article XXVI

What We Will Not Claim.

§ 1

We will not tell customers that any connected technology environment is:

  • "Unhackable."

  • "Risk free."

  • "100% secure."

§ 2

Those are marketing statements, not serious security principles.

Security is the continuous reduction, management, detection and containment of risk.

§ 3

The correct question is not: Can risk be completely eliminated?  It cannot.

The correct question is: How intelligently is risk controlled?

Article XXVII

Responsible AI Is Not Slower AI.

§ 1

It is sustainable AI.

The construction industry does not need another uncontrolled layer of technology producing more information.

It needs intelligence that can be:

  • Traced

  • Challenged

  • Verified

  • Governed

  • Contained

  • Owned by accountable humans

§ 2

That is the standard we are building toward across the CCFE Group ecosystem.

Control the data.

Control the model.

Control the access.

Control the authority.

Then use the intelligence.

CCFE Group

Commercial Intelligence.  Construction Intelligence.  Human Accountability.