Insight
An AI knowledge base for company documents: permissions, sources and the content nobody owns
Employees waste time searching shared drives, wikis and email for policies, procedures and past answers. AI assistants that answer from company documents can help, but only when they respect permissions, cite sources and draw from content someone actually maintains.
The problem is not search alone
Most organisations already have search in their document systems. Employees still ask colleagues because documents are scattered across tools, named inconsistently, duplicated in several versions and written for people who already know the context. Search returns files; employees need answers.
An internal AI knowledge base uses retrieval to find relevant passages from approved sources and a language model to compose an answer from them. When designed well, it can answer questions such as how to process a supplier refund, which contract template applies or what the travel policy says about hotel limits, and it can link to the documents behind the answer.
When designed badly, it gives confident answers from outdated drafts, exposes documents people should not see or invents details when retrieval fails.
Start with sources, not models
The first project decision is which content the assistant may use. Policies, procedures, product documentation, templates, onboarding material and approved FAQs are good starting points. Personal folders, old project archives, email and unreviewed drafts usually are not.
Every source should have an owner and a review cycle. If nobody is responsible for the travel policy, the assistant will eventually give out-of-date travel advice. Knowledge base projects often reveal that the organisation’s real problem is content governance.
- Good first sources
- Approved policies, procedures, templates, product documentation and onboarding guides.
- Risky sources
- Drafts, personal folders, old archives, email and duplicated files.
- Required metadata
- Owner, status, audience, review date and permissions.
Permissions must be enforced at retrieval
An internal assistant must not become a way around document permissions. If an employee cannot open a board paper, HR file or client contract in the source system, the assistant should not retrieve passages from it for that employee.
Permission-aware retrieval is technically harder than indexing everything into one database, but it is essential. Permissions should be synchronised from source systems and checked for every query, not copied once during setup.
Citations make answers checkable
Answers should show which documents and sections they used. Citations let employees verify important answers, help content owners find outdated material and make it easier to trust the system.
The assistant should also refuse when it cannot find a reliable source. A clear message that no approved document answers the question, with a route to the responsible team, is better than a plausible guess.
Evaluate with real questions
Before rollout, collect real questions from employees and help desks, define expected answers and sources, and test the system against them. Evaluation should check whether the right documents were retrieved, whether the answer was correct, whether citations were accurate and whether restricted documents stayed hidden.
After launch, feedback buttons, unanswered question reports and source usage data show where content is missing or unclear. These insights often improve the documentation itself.
Rollout and data protection
A focused first rollout works best: one department, one set of sources and a clear group of users. Expansion can follow once accuracy, permissions and content ownership are proven.
Internal documents may contain personal data, confidential business information or regulated information. Organisations should assess where data is processed, whether prompts and documents are used to train external models, retention of queries and answers, and how access is logged.
The value of an internal knowledge base is not that it knows everything. It is that it helps people find reliable, approved answers faster, and makes gaps in company knowledge visible.
Questions
What is an internal AI knowledge base?
An assistant that retrieves approved company documents and composes answers from them.
Should it index every company file?
No. Start with approved, maintained sources and avoid drafts, archives and personal folders.
How are document permissions handled?
Permissions should be enforced during retrieval so users only get answers from documents they may access.
Why are citations important?
They let users verify answers and help content owners find outdated material.
What should the assistant do when it cannot find an answer?
Say so clearly and route the user to the responsible team.
How should the system be evaluated?
With real employee questions, expected answers, source checks and permission tests.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Complete Digital Transformation — The whole stack, sequenced — brand, web, marketing, CRM, automation, reporting and infrastructure — with benefits measured afterwards rather than projected and forgotten.
- AI for custom customer care: what it can answer and what it must not
- Customer care for logistics companies: proactive delay communication beats a bigger call centre
- Invoice fraud and business email compromise: the controls that stop payments going to criminals
- Italy’s e-invoicing through the SdI: how Europe’s first B2B clearance model works in practice
- All insight articles
Planning an AI assistant for company documents?
We select and govern sources, build permission-aware retrieval with citations and evaluate the assistant against your employees’ real questions.
Get in touch