If corporate AI does not require a twelve-component stack, what does it require? That question follows directly from why bigger, more elaborate systems keep failing in the first place. The answer is smaller than most companies expect and more specific than most vendors describe. The operating layer has four parts, and each one has a minimum viable version: the least you can build that still produces an answer a business can act on. This isn't a reduced version of the real thing, but a complete system at a smaller scale.
The smallest complete system beats the largest incomplete one
There is a difference between building less and building partially.
A partial system covers three of the four parts and leaves one open. It produces answers that are current and well-sourced but reach the wrong people. Or answers that respect permissions but draw on a document nobody has verified in a year. The missing part is where the failure arrives, and it arrives at the worst moment because everything else worked.
A minimum viable operating layer covers all four parts, narrowly. Narrow it to one decision, one team, and one set of sources. All four parts still must be there. None of them have to be large.
This is the same principle behind starting narrow but building to scale. The scope is small. The structure is complete. That is what makes the second area faster to build than the first.
This is the same insight behind the original minimum viable product concept: a skateboard is not a fraction of a car, it is a complete, usable thing at a smaller scale, and that is what makes it viable rather than merely small.
One authoritative source for each question you plan to answer
The minimum version of trusted sources is not a full data catalogue. It is a short list.
Pick the decision you are starting with. List every question that decision depends on. For each question, name the one source that settles it, and name the person who confirms that source is current.
For a quarterly reporting build, that might be five questions and five sources: the chart of accounts, the current classification memo, the approved policy version, the system of record for actuals, and the sign-off log.
What matters is that each question has exactly one answer to the question "where does this come from". When two sources conflict, the system knows which one wins, because someone decided in advance rather than at the moment of failure.
Everything else in the company can stay uncatalogued. You are not building a map of all corporate knowledge. You are establishing authority over a handful of questions.
Permissions built around one real decision, not the whole org chart
The minimum version of role-aware permissions is not a company-wide access model. Modelling every role, department, and sensitivity level across an organization is a multi-year program, and companies that start there rarely finish.
Instead, start with the people involved in the one decision you chose. Usually that is three or four roles. For a discount approval, it might be the rep, the manager, finance, and legal.
For each role, answer two questions. What can this person see? What can this person be told? These are not the same thing. A junior analyst may be permitted to open a dataset and still not be the right recipient of a synthesized answer that reveals individual compensation patterns.
Four roles, two questions each. That is a permission model you can define in an afternoon and enforce from the first week. It will extend later because the pattern is already established, not because you predicted every future case.
The answer has to survive one real workflow
The minimum version of workflow integration is one place where the answer lands and gets used.
Not a chat window beside the work, but inside it. The variance commentary that goes into the board pack. The approval that moves to the next stage. The response that reaches the customer.
Choosing one workflow forces a question that a standalone assistant never has to answer: what happens after the system produces something, who receives it, what they do next, and what stops a bad answer from continuing downstream.
If the answer has nowhere to go, the system is a demonstration. If it enters a real process, every weakness surfaces immediately, which is the exact point. You want the gaps visible in week two of one workflow rather than in month nine across five.
Every answer shows where it came from
The minimum version of accountability is a source line.
Every answer states which source it drew on, when that source was last verified, and what was excluded. You do not need a full lineage graph. Just three facts attached to the output.
This is the cheapest of the four parts and the one most often skipped, because nothing breaks when it is missing. Then a figure is challenged in a meeting, nobody can reconstruct where it came from, and confidence in the system drops further than the error deserved.
A source line also makes the system honest about uncertainty. When the sources conflict, the answer says so. As we covered in what changes when corporate AI is working, a system that declines to give one number when one number would be misleading is not underperforming. That restraint is the feature.
Add complexity only where the business demands it
Build those four parts around one decision and you have a complete operating layer. It will be narrow, but complete.
What happens next is the useful part. The second decision reuses the permission pattern. The third reuses the source authority discipline. The fourth needs a capability the first three did not, and at that point you add it, because a real requirement asked for it rather than because an architecture diagram suggested it.
This is how the layer grows without becoming the twelve-component stack nobody can maintain. Each addition earns its place by solving a problem the business actually encountered.
Most organizations are closer to this than they think. The conditions for a first build are usually already met somewhere in the business. What is missing is rarely capability. It is the decision to define the four parts for one question and start there.

