Knowledge Assistant
A RAG assistant that answers from company docs, with citations.
You can claim one night of standard accommodation, economy travel and a daily meal allowance. Pre-approval is needed for stays longer than two nights1.
- Client
- Consulting group (NDA)
- Role
- AI engineer
- Year
- 2026
- Industry
- Professional services
Problem
The answer existed, somewhere
Policies, SOPs and project knowledge were spread across SharePoint, Google Drive and Confluence. People asked colleagues instead of searching, and the same questions came up again and again.
- Does anyone know where the latest travel policy is?Operations channel, via chat
- Re: Which onboarding checklist do we use now?Consultant, via email
- Expenses policy (old) - copy.docxGoogle Drive, via doc
- Who approves client-billed travel?Operations channel, via chat
Research
Finding where answers actually live
Before choosing a retrieval approach, we mapped where knowledge lives, who is allowed to see it, and which questions people ask most. Permissions turned out to be the hard part, not the model.
What we learned
- Most questions already had an answer; people couldn't find it, or didn't trust it was current.
- An answer without a source wasn't trusted, however fluent it sounded.
- Permissions differ per source, so they must be synced with the content, never assumed.
- Unanswered questions are valuable in themselves: they show where documentation is missing.
User journey
From 'who knows this?' to a cited answer
A composite persona from the consulting team, following one policy question.
BeforeWith the product
- 1
Ask a question
Before: Guessed keywords across several search boxes.
Now: Asks in plain language, in one place.
- 2
Find the right document
Before: Opened promising files that turned out to be out of date.
Now: Retrieval ranks passages from current documents he is allowed to see.
- 3
Trust the answer
Before: Messaged a senior colleague to double-check.
Now: Every sentence cites the passage it came from, one click away.
- 4
Go deeper
Before: Started a new search for each related policy.
Now: Follow-up questions keep the context of the conversation.
- 5
Close the gap
Before: Unanswered questions disappeared into chat history.
Now: A thumbs-down or 'no answer' shows knowledge managers what to document next.
Solution
Answers with receipts
A retrieval-augmented assistant that searches only what the signed-in person is allowed to see, answers in plain language, and cites the exact passages it used. A LangGraph flow decides when to search, when to ask a clarifying question and when to say it doesn't know.
How the work flows
Switch between the old process and the one the product runs.
- 1
Ask in plain language
One place, natural questions.
Person, in productOwner: Consultant - 2
Retrieve from permitted sources
Search is filtered by the person's access groups.
AutomatedOwner: Answer graph - 3
Answer with citations
Every claim links to its passage.
AutomatedOwner: Answer graph - 4
Verify in one click
Open the cited passage in its source.
Person, in productOwner: Consultant - 5
Feedback flags gaps
Unanswered questions reach knowledge managers.
AutomatedOwner: Admin view
Architecture
Permissions travel with the content
Connectors sync documents and their access groups together. Chunks are embedded and stored in pgvector alongside those groups, so the answer graph can filter by the signed-in person's access inside the query. Restricted text never reaches the model.
- Interface
- Service
- AI
- Data and queues
- External system
Sources
Ingestion
Knowledge
Answering
Answer graph
Rewrites the question, retrieves with a permission filter, re-ranks, then answers or abstains.
Why it's built this way
An explicit graph with typed state, so each step can be tested and traced on its own.
Connections
UI
Designed for verifying, not just reading
The interface assumes people will check the answer, and makes that effortless. Citations are inline, sources preview on hover, and the assistant is honest when it can't find something.
Development
Evaluation before features
RAG systems fail quietly, so the build started with a way to measure answers. Every change to chunking, retrieval or prompts runs against the same graded questions before it ships.
Stack
- Frontend
- Next.jsTypeScript
- AI
- LangGraphLLM
- Data
- pgvectorRedis
- Sources
- SharePointGoogle DriveConfluence
AI
Retrieval that respects permissions
Documents are chunked by structure, embedded, and stored in pgvector with their access groups. At question time the graph rewrites the question, retrieves with the person's groups as a hard filter, re-ranks, and generates an answer that must cite what it used.
A cited answer
- 1
Understand the question
Follow-ups are rewritten into standalone queries, and the graph decides whether retrieval is needed.
- 2
Retrieve with a permission filter
Vector and keyword search run with the person's access groups inside the query, not after it.
- 3
Re-rank and assemble
The most relevant passages are ordered and trimmed to fit, keeping their source links.
- 4
Answer or abstain
The model answers only from those passages, cites them, and says so when they don't cover the question.
Guardrails
- Access filtering happens inside the database query, so restricted text never reaches the model.
- Answers without supporting passages are replaced by an honest 'I couldn't find this'.
- Every answer stores its retrieved passages, so a bad answer can be traced and fixed.
Integration
Three sources, one permission model
Each source expresses access differently. Connectors translate SharePoint permissions, Drive sharing and Confluence restrictions into one model of access groups that retrieval can filter on.
SharePoint
Microsoft Graph API
Sites and libraries with item-level permissions; delta queries fetch only changes.
InboundGoogle Drive
Drive API
Shared drives with file permissions; the changes feed keeps the index current.
InboundConfluence
REST API
Spaces and pages with space and page restrictions resolved to groups.
Inbound
Performance
Quick answers without cutting corners
Speed matters in a chat interface, but not at the cost of permissions or grounding. The approach keeps every safety step and makes each one cheap.
Outcome
What's in place so far
In build: outcomes below describe what works today
The assistant is in build. Retrieval, citations and the feedback loop work end to end against the connected sources, and the unanswered-questions view is ready for knowledge managers. Launch follows once permission sync has been verified source by source.
What's next
After launch, answer feedback and unanswered questions become the main signals for what to improve, both in the assistant and in the documentation.
In place so far
- Answers link back to the source document so staff can verify them
Outcomes are described qualitatively. Client figures stay with the client.
Have a similar project?
Whether it's an AI feature that needs to be trustworthy or a system you need to integrate with, tell me what you're building. I reply within one business day with questions and a suggested first step.