Skip to content
DBAI

The AI Buyer’s Guide · 08

Give your team answers they can trace and trust.

An internal AI knowledge base should answer a defined set of employee questions from approved company sources, within each person’s access rights, and show the evidence behind the answer. Start with one team and one useful question set. Agree who owns the sources, how changes reach the system, and when it should decline to answer before connecting more content.

Published
Cluster
Buying AI

Start with questions your team already asks

Choose a job such as finding the current production procedure, locating an approved product specification, or understanding a documented project decision. Collect real questions from the people doing that job. Pair each question with the source an experienced colleague would use today. If nobody can identify an authoritative answer, adding a chat interface will not resolve the disagreement.

A hypothetical operations pilot might answer “Which artwork format do we accept?” from an approved production guide. It should not infer a customer-specific deadline from that guide. A standard procedure, a live order record, and an informal discussion describe different kinds of facts. Decide which questions belong in the pilot and which need another system or a person.

Understand what retrieval adds

A common design searches approved material and gives the relevant excerpts to a model to help construct an answer. This is often called retrieval-augmented generation, or RAG. It is different from assuming the model already knows your business. Ask your provider to show the retrieved passages as well as the final response: a fluent answer can still use the wrong version or draw a conclusion the source does not support.

Do not begin by importing every available folder. Start with a coherent collection whose owner can confirm its status and intended audience. Identify approved documents, working drafts, duplicates, and superseded versions before deciding which should be searchable. More material only helps when the system can distinguish what applies.

Decisions to settle for the first source collection. These are planning requirements, not claims that a connector provides them automatically.
DecisionWhat to recordWhat to demonstrate
AuthoritySource owner, approved version, effective date, and what takes precedence when documents disagree.A question with conflicting versions returns the approved basis or a clear unresolved conflict.
AccessWhich users or groups may retrieve each source, including extracts and attached files.An unauthorized user cannot receive restricted excerpts, summaries, or revealing citations.
TraceabilityA stable source link, passage or section, and the version used for the answer.A reviewer can open the permitted source and verify the specific claim.
Change handlingHow edits, deletions, and permission changes reach the index and relevant caches.Changed or removed material stops being used within the agreed window.
OwnershipWho resolves content disputes, failed imports, and unanswered questions.A failed answer reaches an accountable owner with enough context to act.

Test permissions before testing clever answers

Signing in to an assistant is only the first boundary. The system also needs to determine which material that person may retrieve. Specify that unauthorized source text must be excluded before it reaches the answer-generation step. A prompt telling the model to keep secrets is not the access-control design.

Microsoft’s Azure AI Search documentation gives a concrete implementation example: document permissions can be represented alongside indexed content and used to filter query results. It also explains that source permission changes depend on synchronization to the index. Several native integrations are marked preview. The buyer’s question is therefore specific: which mechanism enforces access in this proposed system, and how quickly does a revoked permission take effect?

Use authorized test accounts with different roles. Include a document that one account can access and another cannot, then remove access and repeat the check. Inspect retrieved excerpts, citations, and cached responses. Separately agree how saved conversation history is handled after access changes; rebuilding an index is not the same as removing previously stored answers.

Require useful citations and useful uncertainty

A source link is not proof by itself. Check whether the cited passage supports the claim, whether it is current for the question, and whether the employee can open it. If an answer combines two documents, make the contribution of each source clear. Keep a factual quotation distinct from the assistant’s interpretation.

For an unanswered question, define a useful response: explain that the approved sources do not establish the answer, identify the appropriate owner without exposing restricted material, and offer the permitted next step. Avoid a generic refusal that leaves the employee stranded. Do not reward the system for answering every question when some answers are absent from the collection.

Keep the business evidence specific

DBAI’s Knowledge Systems service covers retrieval pipelines, source traceability, ingestion permissions, and internal assistants. Its linked Exora INK case study describes a staff assistant connected to the same product data layer as the storefront. That illustrates a focused knowledge source tied to a real staff task.

An assistant over product records is not evidence that every document repository or permission model is already supported. Treat each additional source as an integration with its own access, freshness, and validation work. Ask for that work in the scope rather than assuming “connect your documents” includes it.

Copy this brief before requesting a proposal

Internal knowledge base project briefUse this with the team that owns the questions and sources. Describe access requirements without copying confidential documents into the brief. · markdown
# Internal AI knowledge base — first release
Team and business task:
Questions the pilot must answer:
Questions explicitly out of scope:

## Sources
Approved collection and source owner:
Authority / version precedence:
Document IDs, links, and effective dates:
Allowed users and groups:
Permission enforcement before retrieval reaches the model:
Update, deletion, and revocation windows:
Handling of saved answers and caches:

## Answer contract
Required citation detail:
When the system must say the answer is unavailable:
Conflict handling:
Handoff owner and next step:

## Evaluation
Known-answer questions and supporting passages:
Questions with no supported answer:
Conflicting or superseded documents:
Unauthorized-user and revoked-access cases:
Failed-import and deleted-document cases:
Reviewer and acceptance decision:
Ongoing source maintenance owner:

Judge the pilot on the work it supports

Evaluate retrieval and the answer separately. Did the system find the right permitted passage? Did the answer faithfully use it? Then ask whether the employee could complete the intended task and how much verification was needed. Record the sample and its limits instead of presenting a small demonstration as proof across every department.

Agree release blockers, an escalation path, and who will maintain the collection after launch. A focused knowledge base with dependable sources and a clear owner gives you a basis for expansion. Add the next team or source when you can explain how its questions, permissions, and update rules fit.

FAQ

  1. Do we need to train a model on all our documents?

    Not necessarily. A retrieval-based system can search approved sources and provide relevant material when answering. Ask the provider which approach the proposed workflow needs and how sources, permissions, and updates are handled.

  2. Will an AI knowledge base inherit our existing permissions automatically?

    Do not assume it will. Verify the exact connector, identity mapping, retrieval filters, synchronization behavior, and limitations. Test allowed, denied, and revoked access with representative accounts before rollout.

  3. What should happen when company documents disagree?

    Define a source owner and precedence rule. If the system cannot resolve the conflict using an approved rule, it should state the uncertainty and route the question to the owner instead of silently choosing a convenient answer.

Bring the questions your team keeps asking.

DBAI can help map the approved sources, access requirements, and evaluation plan for an internal knowledge assistant.

Plan your knowledge system