Retrieval must respect the source system

An employee should not gain access to a restricted policy, client file or board document merely because it was indexed for AI search. Permission-aware retrieval carries identity and access context into every query and filters results before the model sees them.

Copying everything into one unrestricted index is operationally convenient and often unacceptable. Source owners, access groups and deletion/update behaviour need to be part of the architecture.

An answer needs evidence

Citations let the user inspect where an answer came from, how current it is and whether the source applies to their situation. The system should distinguish quotation, summary, inference and uncertainty rather than presenting every response with equal confidence.

  • Show title, owner and last-updated context
  • Link to the accessible source
  • Prefer no answer over unsupported invention
  • Capture feedback without exposing sensitive prompts

Operate the knowledge, not only the assistant

Unanswered questions reveal missing, conflicting or outdated documentation. Assign those gaps to content owners and measure how quickly they are resolved.

A useful knowledge assistant is therefore partly a governance programme: approved sources, review cycles, permissions, ownership and feedback. The conversational interface is the visible layer, not the whole system.