Insight

An AI knowledge base for company documents: permissions, sources and the content nobody owns

Employees waste time searching shared drives, wikis and email for policies, procedures and past answers. AI assistants that answer from company documents can help, but only when they respect permissions, cite sources and draw from content someone actually maintains.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight AI knowledge bases for company do… Get in touch 01 The problem is not se… 02 Start with sources, n… 03 Permissions must be e…

The problem is not search alone

Most organisations already have search in their document systems. Employees still ask colleagues because documents are scattered across tools, named inconsistently, duplicated in several versions and written for people who already know the context. Search returns files; employees need answers.

An internal AI knowledge base uses retrieval to find relevant passages from approved sources and a language model to compose an answer from them. When designed well, it can answer questions such as how to process a supplier refund, which contract template applies or what the travel policy says about hotel limits, and it can link to the documents behind the answer.

When designed badly, it gives confident answers from outdated drafts, exposes documents people should not see or invents details when retrieval fails.

Start with sources, not models

The first project decision is which content the assistant may use. Policies, procedures, product documentation, templates, onboarding material and approved FAQs are good starting points. Personal folders, old project archives, email and unreviewed drafts usually are not.

Every source should have an owner and a review cycle. If nobody is responsible for the travel policy, the assistant will eventually give out-of-date travel advice. Knowledge base projects often reveal that the organisation’s real problem is content governance.

Good first sources
Approved policies, procedures, templates, product documentation and onboarding guides.
Risky sources
Drafts, personal folders, old archives, email and duplicated files.
Required metadata
Owner, status, audience, review date and permissions.

Permissions must be enforced at retrieval

An internal assistant must not become a way around document permissions. If an employee cannot open a board paper, HR file or client contract in the source system, the assistant should not retrieve passages from it for that employee.

Permission-aware retrieval is technically harder than indexing everything into one database, but it is essential. Permissions should be synchronised from source systems and checked for every query, not copied once during setup.

Citations make answers checkable

Answers should show which documents and sections they used. Citations let employees verify important answers, help content owners find outdated material and make it easier to trust the system.

The assistant should also refuse when it cannot find a reliable source. A clear message that no approved document answers the question, with a route to the responsible team, is better than a plausible guess.

Evaluate with real questions

Before rollout, collect real questions from employees and help desks, define expected answers and sources, and test the system against them. Evaluation should check whether the right documents were retrieved, whether the answer was correct, whether citations were accurate and whether restricted documents stayed hidden.

After launch, feedback buttons, unanswered question reports and source usage data show where content is missing or unclear. These insights often improve the documentation itself.

Rollout and data protection

A focused first rollout works best: one department, one set of sources and a clear group of users. Expansion can follow once accuracy, permissions and content ownership are proven.

Internal documents may contain personal data, confidential business information or regulated information. Organisations should assess where data is processed, whether prompts and documents are used to train external models, retention of queries and answers, and how access is logged.

The value of an internal knowledge base is not that it knows everything. It is that it helps people find reliable, approved answers faster, and makes gaps in company knowledge visible.

Questions

What is an internal AI knowledge base?

An assistant that retrieves approved company documents and composes answers from them.

Should it index every company file?

No. Start with approved, maintained sources and avoid drafts, archives and personal folders.

How are document permissions handled?

Permissions should be enforced during retrieval so users only get answers from documents they may access.

Why are citations important?

They let users verify answers and help content owners find outdated material.

What should the assistant do when it cannot find an answer?

Say so clearly and route the user to the responsible team.

How should the system be evaluated?

With real employee questions, expected answers, source checks and permission tests.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Planning an AI assistant for company documents?

We select and govern sources, build permission-aware retrieval with citations and evaluate the assistant against your employees’ real questions.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp