The CCFE Group AI Constitution
Control Before Capability.
AI should increase intelligence without surrendering control.
Across the CCFE Group ecosystem, artificial intelligence is governed by a common operating philosophy: AI may assist human judgment. It does not replace human accountability.
Our approach extends beyond cybersecurity.
It governs:
Where data is processed and stored
Which systems may access that data
Which AI models may be used
What information may be submitted to AI
What AI may and may not do
How AI-generated findings are validated
How different divisions may share information
How models and integrations are approved
How decisions are documented
How incidents are contained
How human authority is preserved
The objective is not unrestricted automation.
The objective is controlled intelligence.
Every division, platform, employee, contractor, model, agent, integration and automated workflow operating within our ecosystem is expected to operate under the same governing principles.
Technology may change.
These principles do not.
Human Accountability Is Non-Delegable.
AI may analyze.
AI may compare.
AI may identify contradictions.
AI may summarize.
AI may calculate.
AI may identify patterns.
AI may surface risk.
AI may prepare recommendations.
AI may assist in producing reports.
But AI does not become the responsible party.
Final commercial, contractual, estimating, operational and professional decisions remain subject to human authority.
There must always be an identifiable person or business function accountable for consequential decisions.
AI can inform authority. It cannot become authority.
Client Data Remains Client Data.
Access to information does not create ownership of that information.
Client information is to be used only for authorized operational purposes.
The governing standard prohibits unauthorized:
Sale of client information
Repurposing of client information
Distribution of client information
Cross-client exposure
Public disclosure
Contribution of client information to public AI training systems
Use outside the authorized business purpose
Possession of data is not permission to use it without boundaries.
Data Placement Is a Security Decision.
Where information resides matters.
Our infrastructure strategy is based on controlled data placement, jurisdictional awareness, system segmentation and defined access boundaries.
We do not believe sensitive project intelligence should move indiscriminately between systems simply because technology makes that possible.
Data placement is evaluated according to factors including:
Sensitivity
Business purpose
Client requirements
Jurisdiction
System classification
Operational need
Access requirements
Retention requirements
Integration risk
Detailed physical data center locations and infrastructure information are not publicly disclosed when doing so could unnecessarily increase security exposure.
Where appropriate, infrastructure region and data-handling information can be addressed directly with customers.
Transparency does not require publishing a roadmap to the infrastructure.
Data Classification Before AI Access.
Not every piece of information should be treated the same.
Our governance model recognizes different levels of data sensitivity.
Information approved for unrestricted public distribution.
- Published marketing information
- Public webpages
- Publicly released documents
- General industry information
Business information intended for authorized internal operations.
Client, project, commercial or operational information requiring controlled access.
Information requiring the highest level of handling, access and authorization.
A system being technically capable of processing information does not automatically mean it is authorized to receive it.
Classification comes before convenience.
Data Center & Infrastructure Governance.
Our architecture is designed around a simple principle: information should exist only where it has a reason to exist.
Infrastructure controls are expected to address:
Segmentation
Sensitive systems and data environments should be separated according to operational function and risk.
Least-Privilege Access
Users, systems and AI services should receive only the level of access required to perform an authorized function.
Identity Control
Access should be attributable to identifiable users, services or approved system processes.
Encryption
Sensitive information should be protected during transmission and storage using appropriate encryption controls.
Logging
Material system activity should be capable of being recorded and investigated.
Backup & Recovery
Critical information should be protected against accidental deletion, corruption and operational disruption.
Controlled Integration
An available API, connector or integration does not automatically become an approved connection.
Environment Separation
Development, testing and production activities should be separated where appropriate.
Retention Control
Information should not remain indefinitely simply because storage is inexpensive.
Secure Disposal
Data that no longer has an authorized business or legal purpose should be subject to controlled deletion or disposition.
SQUARES AI™: A Closed Construction Intelligence Environment.
SQUARES AI™ is positioned as the Construction Intelligence Engine operating behind our ecosystem.
It was not developed around the idea of giving every employee unrestricted access to an AI chatbot.
It was developed around the opposite idea: control the intelligence layer.
SQUARES AI™ is intended to bring information together from approved sources, analyze that information within defined workflows and produce intelligence that remains subject to human governance.
The system may support analysis involving:
Construction drawings
Specifications
Addenda
RFIs
Finish schedules
Scope information
Estimating information
Project correspondence
Historical project intelligence
Commercial documents
Approved enterprise information sources
Connectivity does not eliminate governance.
Every additional data source expands intelligence — and expands responsibility.
Approved AI Only.
Employees and contractors should not be free to move company or client information into whichever AI application happens to be convenient.
Enterprise AI governance requires a distinction between:
Systems evaluated and authorized for defined business purposes.
Public, personal, experimental or otherwise unauthorized systems where company or client information should not be submitted.
This includes apparently harmless activities such as:
Summarizing an email
Reviewing a contract
Uploading drawings
Checking pricing
Rewriting an RFI
Analyzing specifications
Summarizing meeting notes
Uploading customer spreadsheets
A five-minute productivity gain is not sufficient justification for uncontrolled data exposure.
The Minimum Necessary Data Principle.
AI should receive the information necessary to perform its authorized function.
Not everything available to the enterprise needs to be exposed to every model, workflow or employee.
Before information is made available to AI, the governing questions are:
Does the system need this information?
Is the system authorized to receive it?
Is the user authorized to expose it?
Is there a less sensitive way to accomplish the same objective?
More data does not automatically mean better governance.
Evidence Before Assertion.
One of the greatest risks in artificial intelligence is not simply a wrong answer.
It is a wrong answer presented with confidence.
Our Construction Intelligence philosophy therefore places a premium on evidence.
Where practical, material findings should be traceable to their underlying source.
Examples include:
Drawing sheet
Detail
Specification section
Addendum
RFI
Finish schedule
Contract provision
Email
Approved project record
Other identifiable source material
When evidence is unavailable, uncertainty should not be disguised as certainty.
Inference must remain distinguishable from fact.
AI Output Is Not Automatically True.
AI-generated information may contain:
Errors
Missing context
Misinterpretations
Conflicting conclusions
Outdated information
Unsupported assumptions
False confidence
Fabricated information
For that reason, AI-generated output should be evaluated according to the consequence of being wrong.
The greater the commercial, contractual, financial, legal, safety or operational consequence, the greater the expected level of human review.
Prohibited Uses.
Across the enterprise, AI should not be used to independently:
Execute contracts
Accept contractual obligations
Approve material commercial commitments
Submit bids without authorized human review
Create unauthorized scope commitments
Represent unverified information as established fact
Circumvent company security controls
Circumvent access restrictions
Upload confidential information into unapproved AI systems
Conceal the origin of fabricated information
Impersonate individuals without authorization
Make discriminatory employment or personnel decisions
Provide final legal determinations
Override required human approvals
Disable required audit or logging controls
Bypass established document-control processes
Artificial intelligence is not a justification for eliminating established controls.
No Autonomous Commercial Authority.
AI systems operating within our ecosystem are not granted independent authority to bind the company or its clients.
Unless explicitly authorized through a separately controlled process, AI may not independently:
Commit pricing
Approve change orders
Accept substitutions
Approve contracts
Accept scope
Release contractual notices
Authorize payments
Execute purchases
Sign documents
Waive rights
Modify contractual obligations
Commercial authority remains human authority.
Divisional Governance.
The same AI Constitution applies across the organization, but implementation depends upon the function of each division.
CCFE Group
Provides the enterprise governance framework connecting the businesses operating within the ecosystem.
CDPC Partners, LLC
Provides ownership and operating oversight across the portfolio and establishes enterprise-level accountability.
Compass Global
Uses Construction Intelligence in support of pre-construction analysis, estimating intelligence and project reporting. AI findings support professional review. They do not eliminate estimator responsibility.
Division 09 Estimators
Uses controlled technology to support commercial flooring takeoffs and estimating. Quantities, assumptions, scope interpretations and project conditions remain subject to estimator review.
Rogue IQ
Develops and advances Construction Intelligence technologies and the systems that support the broader ecosystem.
SQUARES AI™
Operates as the Construction Intelligence Engine connecting approved project information, enterprise data and governed analytical workflows.
HOLMES
Applies intelligence to contracts, specifications, submittals, product data, obligations and commercial documentation. HOLMES provides Construction Intelligence and commercial document review. It is not a substitute for legal counsel and does not provide legal advice.
Rhogan Research Institute
Supports the methodology, standards, benchmarking, testing and research necessary to advance Construction Intelligence as a disciplined field rather than an uncontrolled technology experiment.
Cross-Division Data Boundaries.
Being part of the same corporate ecosystem does not mean every division automatically receives unrestricted access to every piece of information.
Access should remain purpose-driven.
Cross-division information sharing should consider:
Client authorization
Business necessity
Data classification
Contractual limitations
System permissions
Conflict concerns
Confidentiality obligations
Scope of engagement
Enterprise integration does not mean enterprise-wide exposure.
Model Governance.
AI models change. Providers change. Capabilities change. Risk changes.
A model that was appropriate for one workflow may be inappropriate for another.
AI governance therefore includes the model itself.
Models and major AI components should be evaluated for factors such as:
Intended purpose
Data handling
Reliability
Security
Model behavior
Known limitations
Integration requirements
Vendor dependency
Output quality
Change risk
Material model or architecture changes should be treated as governed system changes rather than invisible software updates.
Version Control & Change Management.
A powerful AI system should not quietly become a different AI system overnight without anyone understanding what changed.
Material modifications to:
Models
Prompts
Agents
Data sources
Permissions
Integrations
Automated actions
Decision logic
Retrieval systems
should be subject to appropriate testing and change control.
The question is not only: Does the new version work?
It is also: What new risk did the new capability create?
Agentic AI Requires Higher Control.
Traditional AI produces information. Agentic AI may be capable of taking actions. That changes the risk profile considerably.
As systems gain the ability to:
Send communications
Modify records
Create documents
Trigger workflows
Access multiple systems
Execute transactions
Make decisions
the control requirements must increase accordingly.
More autonomy should never mean less governance.
Prompt Injection & Untrusted Content.
Documents, websites, emails and other data sources may contain content designed to manipulate AI behavior.
Therefore, information entering an AI system should not automatically be treated as trusted instructions.
Content is data.
System authority is separate.
An external document should not be able to rewrite the rules governing the system analyzing it.
Security Before Automation.
We reject a common technology assumption: If something can be automated, it should be automated.
No.
Automation should exist only where the benefit justifies the risk and appropriate controls exist.
Some functions should remain intentionally human.
The Human Override.
Every consequential AI-supported process should preserve the ability for an authorized human to:
Challenge the result
Reject the result
Correct the result
Escalate the result
Disable the workflow
Require additional evidence
AI systems should support judgment — not trap users inside automated conclusions.
Incident Response.
AI incidents are not limited to traditional cybersecurity breaches.
An AI incident may include:
Unauthorized data disclosure
Improper access
Incorrect automated action
Model malfunction
Significant hallucination
Cross-client information exposure
Compromised integration
Prompt injection
Credential compromise
Unapproved system use
Unexpected model behavior
Where necessary, the organization must be capable of isolating:
A user
A model
An integration
A data source
An automated workflow
An entire AI function
Every intelligent system needs an off switch.
Auditability.
Trust should not require blind faith.
Material AI operations should be designed so that authorized personnel can investigate what occurred.
Depending upon the system and risk level, this may include:
User activity
Source data
Model or workflow version
Generated output
Human changes
Approvals
Overrides
System actions
Timestamped events
The more consequential the action, the more important the audit trail.
Continuous Testing.
AI governance is not a policy written once and placed in a binder.
Systems should continue to be challenged.
Testing may include:
Accuracy evaluation
Hallucination testing
Permission testing
Data-boundary testing
Security testing
Adversarial testing
Prompt-injection testing
Cross-client leakage testing
Workflow testing
Human-review testing
Failure-mode testing
We are interested in what the system does when everything works.
We are equally interested in what happens when something goes wrong.
Third-Party & Vendor Risk.
AI governance cannot stop at systems we build ourselves.
Every external:
Model
Platform
API
Connector
Cloud service
Software provider
Data processor
may introduce additional risk.
Convenience does not eliminate the need for vendor evaluation.
AI Literacy Is a Security Control.
Technology alone cannot govern artificial intelligence.
People must understand its limitations.
Employees operating AI-supported systems should understand concepts including:
Hallucination
Data sensitivity
Confidentiality
Prompt injection
Verification
Human accountability
Approved versus unapproved systems
Escalation
Appropriate reliance
A user who blindly trusts AI can defeat even a sophisticated technical control environment.
What We Will Not Claim.
We will not tell customers that any connected technology environment is:
"Unhackable."
"Risk free."
"100% secure."
Those are marketing statements, not serious security principles.
Security is the continuous reduction, management, detection and containment of risk.
The correct question is not: Can risk be completely eliminated? It cannot.
The correct question is: How intelligently is risk controlled?
Responsible AI Is Not Slower AI.
It is sustainable AI.
The construction industry does not need another uncontrolled layer of technology producing more information.
It needs intelligence that can be:
Traced
Challenged
Verified
Governed
Contained
Owned by accountable humans
That is the standard we are building toward across the CCFE Group ecosystem.
Control the data.
Control the model.
Control the access.
Control the authority.
Then use the intelligence.
CCFE Group
Commercial Intelligence. Construction Intelligence. Human Accountability.