Find the answer, see the source, never see what you should not.
Policies, procedures, tickets and product documentation are spread across SharePoint, Confluence, file shares and business systems. We build retrieval that respects each source’s permissions and answers with citations, or says plainly that it cannot.
For organisations whose knowledge is spread across systems, countries and languages, and whose permissions must hold.
Approved sources are connected together with their permissions and indexed with metadata. A person asks a question; retrieval is trimmed to what that person may see. When the evidence is missing or conflicting, the question goes to a content owner; otherwise the answer cites its sources. Feedback improves the sources and the evaluation set.
Before and after
What changes in the working day
Today
With the system
Today
Today: Search that returns everything
Keyword search lists hundreds of files, including drafts, duplicates and versions that were withdrawn years ago.
With the system
With the system: Short answers with sources
Each answer quotes the passages it relies on, links to them and shows when each source was last reviewed.
Today
Today: Knowledge sits with a few people
The fastest route to an answer is asking the colleague who has been there longest, which does not scale and leaves when they do.
With the system
With the system: Permissions travel with the content
Results are filtered by the asker’s own access rights at query time, so a shared index never becomes a shared secret.
Today
Today: Answers without evidence
People repeat what they remember. Nobody can tell which version of a policy an answer was based on.
With the system
With the system: Abstention when evidence is thin
When the sources do not support an answer, the assistant says so and routes the question to the person who owns that topic.
Today
Today: Language barriers
The procedure exists, but in French, while the question was asked in Dutch.
With the system
With the system: Cross-lingual retrieval
A question in one language finds sources in Dutch, French, German or English and answers in the language it was asked.
Workflow
How the workflow runs
Retrieval quality depends on the sources more than on the model. That is why the workflow starts with owners deciding what is indexed and ends with feedback going back to them.
Illustrative workflow
7 steps · 2 human checkpoints
Legend
System
Person
Human checkpoint
Exception path
Enterprise knowledge: illustrative workflow with abstention path
Read the diagram as text
The main path runs from connecting approved sources and indexing them with metadata, through a person asking a question, permission-trimmed retrieval and an answer with citations, to feedback and evaluation.
Content owners approve every source before it is indexed: that is the first human checkpoint.
When retrieval finds too little evidence or conflicting sources, the assistant does not answer. The question leaves the main path and is referred to a content owner, who answers it and decides whether a source must change. The referral then rejoins the main path at feedback and evaluation.
01
Step 1: Connect approved sourcesSystem
Connectors read SharePoint sites, Confluence spaces, file shares, ticketing systems and ERP document stores, and synchronise each item’s access-control list together with its content.
Human checkpoint
Content owners approve each source and its scope before anything is indexed; withdrawn sources are removed from the index.
02
Step 2: Index with metadataSystem
Documents are split along their structure and enriched with owner, language, status (draft, approved, superseded) and review date. A hybrid index combines keyword and vector search.
03
Step 3: Ask in contextPerson
People ask in the tools they already use: the intranet, Microsoft Teams, the service console or a business application. Their identity travels with the question.
04
Step 4: Permission-trimmed retrievalSystem
The query is expanded across languages, results are filtered by the asker’s entitlements and re-ranked. Superseded documents are excluded; conflicting sources are detected.
05
Step 5: Refer to a content ownerPerson
Questions without enough supporting evidence, or with sources that contradict each other, go to the owner of that topic with the retrieved passages attached.
Exception path: Evidence missing or conflicting· Returns to step 7
Human checkpoint
The assistant abstains rather than guesses. A person answers, and decides whether a source must be written, updated or withdrawn.
06
Step 6: Answer with citationsSystem
A short answer is generated only from the retrieved passages. Every statement links to its source, with the source’s owner and review date shown.
07
Step 7: Feedback and evaluationSystem
Ratings, corrections and referred questions become test cases. Groundedness and citation correctness are re-measured before any change to retrieval or prompts.
Components
What we would build
01
Source connectors with permission sync
Incremental connectors that carry access-control lists, deletions and version status from each source system into the index.
Identity provider and group directory (Microsoft Entra ID or similar)
Salesforce Service Cloud knowledge and consolePlatformSalesforce
SAP document stores and business objectsPlatformSAP
Microsoft Teams and the intranet
Service-management platform
Controls
Controls designed in
Access boundaries
Permissions are never flattened into one shared index. Each item keeps its own access-control list and every query is filtered by the asker’s identity and group membership at the moment of asking.
Sensitive spaces such as HR, legal and security can be excluded entirely, or indexed only for their own audience.
Human review
Content owners decide what is indexed and are notified about unanswered questions and sources that conflict. Answers in high-impact domains can be limited to verbatim quotes.
Auditability
Each answer is logged with the question, the retrieved passages, the sources cited, the model and prompt version and the user’s feedback, under a retention period you set.
Data protection
Personal data in source documents stays under the source’s own access rules. Logs are pseudonymised where possible, and no content is used to train external models.
AI transparency
The interface states that answers are generated by an AI system, shows the sources for every answer and makes it easy to report a wrong one.
Measures
What we would measure
We agree these measures with you during discovery, using real questions collected from the teams who will use the assistant.
What we would measure
Metric
Why it matters
How we would measure it
01Groundedness
Why it mattersAn answer that is not supported by its sources is worse than no answer.
How we would measure itShare of answer statements supported by the cited passages, scored on a test set and by sampled human review.
02Citation correctness
Why it mattersPeople must be able to verify an answer in one click.
How we would measure itShare of citations that point to the passage that actually supports the statement.
03Search success
Why it mattersShows whether people find what they need, not just whether they receive text.
How we would measure itRated answers, follow-up questions and referrals per domain, from usage logs and feedback.
04Time to answer for defined tasks
Why it mattersConnects the assistant to real work, such as answering a policy question at the service desk.
How we would measure itTimed task comparisons before and after, on a fixed set of representative questions.
No targets are set before a baseline exists.
Rollout
How we would roll it out
Phase 01
Discovery and source review
One domain with clear owners, such as HR policy or product support. We collect real questions and assess the state of the sources.
Exit criteria
Sources and owners agreed
Question set collected
Permission model verified with IT security
Phase 02
Pilot with a defined group
The assistant runs for one team, inside one front end, on approved sources only.
Exit criteria
Groundedness and citation criteria met
No permission leaks in access tests
Owner feedback loop in use
Phase 03
Extend domains
More sources and audiences, each added through the same review of owners, permissions and test questions.
Exit criteria
Evaluation set per domain
Content lifecycle agreed with owners
Phase 04
Operate
Monitoring, evaluation runs and content reporting handed to your team, with a clear owner for the service.
Product terms, compliance policies and procedures for advisers and operations staff.
Illustrative example
Group policies for staff in four countries
Situation
A group with offices in four EU countries publishes HR and compliance policies centrally, with local addenda in each language. Staff ask the same questions to local HR teams again and again.
System
An assistant in the intranet answers from group policies and the asker’s own country addenda only, in the asker’s language, citing the clause it relies on.
Human control
Local HR owns its addenda and approves them for indexing. Questions the sources do not cover are referred to local HR, not answered by the assistant.
What we would measure
Groundedness and citation correctness on a question set per country, and the volume of questions referred to HR.
International
Knowledge across borders and languages
International organisations keep policies and procedures in several languages, under different national rules, in systems that each manage their own permissions. We design retrieval that keeps those permissions intact and answers across languages, so a team in one country can rely on guidance written in another.
Hosting region, logging and retention are agreed up front with your data protection officer under GDPR. Where an assistant informs people at work, we design with the EU AI Act transparency duties in mind and document how answers are produced and evaluated.
01How do you make sure people only see what they are allowed to see?
Access-control lists are synchronised from each source and applied at query time, using the asker’s identity. We test it explicitly: before a pilot starts, we run access tests with accounts from different groups and check that nothing leaks across.
02What happens when the assistant is wrong?
It will sometimes be wrong, so every answer shows its sources and users can report a problem in one click. Reports go to the content owner and become test cases. Where the evidence is thin, the assistant is designed to abstain rather than guess.
03We already have a workplace assistant. Why build something?
Often you should not. If your content lives in one suite and its built-in assistant meets your quality criteria, we help you configure and govern it. A custom service makes sense when sources span several systems, when you need control over retrieval and evaluation, or when data residency rules out the default.
04Our documents are messy. Do we need to clean everything first?
No, but content governance is usually the real bottleneck. We start with one domain, mark superseded and draft documents, and give owners reports on duplicates and stale sources so quality improves where it matters first.
05Can it answer across Dutch, French and German sources?
Yes. Multilingual embeddings and query expansion find sources in other languages, and the answer is given in the language of the question, with citations to the original passages.
06How long does a pilot take?
That depends mainly on access to sources and owners. We agree the pilot scope and exit criteria during discovery. Read more about how we work and our AI engineering practice.
Discuss your knowledge sources
Tell us where your knowledge lives and who needs it. We will look at sources, permissions and languages together and propose a first domain.