Book a Call
Case Study

We built a permission-aware AI knowledge assistant that answers staff questions from company documents, while keeping every answer inside the limits of the user's role and department.

Built for an organisation whose policies, product information and internal knowledge needed to be easy to ask about, but not open to everyone.

Enterprise and business operations. Client and project names are kept confidential.

Industry
Enterprise and business operations
Project type
Internal AI knowledge hub and permission-aware assistant
Services
AI Assistants and Chatbots, Security and Data Protection, AI Solutions and Automation
Used by
Employee, Department user, Management, Admin
Technology
Kept private at the client's request
Overview

An AI knowledge assistant that respects who is asking.

From scattered documents to one secure assistant

Internal policiesProduct informationManagement files
Permission-aware assistant

The organisation had a lot of useful knowledge: internal policies, product information and the kind of company detail people ask colleagues about every day. Finding it meant knowing which folder to open or which person to message.

We built a permission-aware AI knowledge assistant inside the staff dashboard. People ask questions in plain language and get answers grounded in company information, but only from the knowledge their role and department allow them to see.

The problem

Company knowledge was hard to find and hard to share safely.

Staff needed quick answers about policies and products, yet the information sat across documents that few people knew how to search. Questions went to colleagues, who then had to stop their own work.

A general chatbot was not an option. Finance, HR and management information all carry different sensitivity, and an assistant that could see everything would risk showing the wrong answer to the wrong person.

Answers buried across many documents

Colleagues fielding the same questions

Sensitive information needing tight limits

Departments needing different knowledge

Risk of exposing management information

Time lost hunting for the right policy

What needed to change

What needed to change

The assistant had to be useful to everyone while showing each person only what they are allowed to know. Permissions had to shape the answer itself, not sit on top as an afterthought.

Questions we worked through

  • How should a user's role and department decide which knowledge an answer can draw on?
  • Where should the line sit between departmental knowledge and management-only information?
  • Would source references help staff trust an answer and check the original policy?
  • How could admins spot questions the knowledge base cannot yet answer?
  • Would audit logs of questions and access be needed for sensitive areas?
The solution

A secure knowledge layer behind the AI assistant

We brought company documents into one central knowledge base and connected it to an internal AI chatbot on the user's dashboard. Every user has a role and a department, and those decide which knowledge the assistant can use when it answers.

Document ingestion Central knowledge base Role and department permissions Internal AI chatbot Role-appropriate answer
1

Knowledge base

Holds internal policies, product information and other company knowledge in one place.

2

Document ingestion

Brings company documents into the knowledge base so the assistant can answer from them.

3

AI assistant

Takes natural-language questions and answers from company information.

4

Roles and departments

Gives each user a role and a department that define what they can access.

5

Access rules

Applies finance, HR and management-level restrictions to the knowledge an answer can use.

6

Dashboard integration

Places the assistant inside the dashboard staff already use.

How the workflow works

How the AI knowledge assistant works

For the user it feels like asking a well-informed colleague. Behind the scenes, permissions are applied before any knowledge reaches the answer.

  1. 01

    Documents added

    Company documents are ingested into the central knowledge base.

  2. 02

    Access defined

    Each user is given a role and a department with matching permissions.

  3. 03

    Question asked

    An employee opens the assistant from their dashboard and asks in plain language.

  4. 04

    Permissions applied

    The assistant limits itself to knowledge the user's role and department allow.

  5. 05

    Answer returned

    The user receives an answer grounded in company information they are entitled to see.

Who uses it

Who uses it

The same assistant serves everyone, but what it can tell each person depends on where they sit in the organisation.

Employee

Opens the internal assistant, asks a question and receives an answer appropriate to their role.

Department user

Gets answers from their own department's knowledge, such as finance or HR.

Management

Can access sensitive information that has been authorised for management.

Admin

Manages documents, permissions, users, departments and knowledge sources.

Permission-aware answers

What each department can ask about.

The assistant only draws on knowledge the person asking is allowed to see, based on their role and department.

All staffFinanceHRManagement
Company policies and product information
Finance knowledgeIf authorised
HR knowledgeIf authorised
Restricted management information
Key features

Key features

Internal AI chatbot

An assistant built for staff, not the public, available from their dashboard.

Central company knowledge base

Policies, product information and company knowledge held in one place.

Document ingestion

Company documents are brought in so the assistant can answer from them.

Natural-language questions

Staff ask the way they would ask a colleague, with no search syntax to learn.

Grounded answers

Responses are based on company information rather than general knowledge.

Role-based permissions

Each user's role decides which knowledge an answer can draw on.

Department-level access

Finance users reach finance knowledge and HR users reach HR knowledge.

Management-level restrictions

Sensitive management information stays limited to those authorised.

Business value

Business value

The organisation gets the convenience of an AI assistant without loosening control over who can see what.

Before

  • Knowledge spread across documents
  • Questions sent to busy colleagues
  • No safe way to open up sensitive areas
  • The same access for everyone
  • Slow answers on policy and product

After

  • One central knowledge base
  • Answers on demand from the dashboard
  • Access shaped by role and department
  • Management information kept restricted
  • Answers grounded in company information
The outcome

The outcome

Staff can ask the assistant first, and the answers they get reflect both what the company knows and what they are allowed to see.

  • Employees find policy and product answers without chasing colleagues.
  • Finance and HR knowledge reaches the people who need it.
  • Sensitive management information stays behind the right permissions.
  • Admins manage documents, users and departments from one place.
  • The assistant sits inside the dashboard staff already use.