Give the system boundaries it can read.
If an important rule lives only in someone's head, the system cannot follow it, and neither can the next person who joins. So we write the rules down where the machine and the humans both encounter them: which sources are authoritative, what may be changed, what is forbidden, what requires approval, when to stop instead of guessing. The rules live beside the code, not in a policy document nobody opens.