Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

AI knowledge assistant: answers from company knowledge, with sources and access control

An AI knowledge assistant is an internal tool that answers employees' questions from your company's own documents and systems, cites the source behind every answer and shows each person only what they are allowed to see. Netbase offers it as a growth capability, designed with retrieval, evaluation and human review from the first pilot, and has delivered one for a client that is not named.

Review this solution for your workflow View relevant work

Reviewed by David (CEO) · Updated 17 Sep 2026

star

What a knowledge assistant is, and where it stops

An AI knowledge assistant is an enterprise knowledge solution that helps employees, team leads and support staff find the right policy, procedure or project fact in seconds instead of asking a colleague. It uses retrieval-augmented generation: the assistant first searches your approved sources for the passages that answer the question, then writes a short answer from those passages only and links to each one.

It stops at advice. The assistant reads; it does not approve requests, change records or send messages on anyone's behalf. It is for internal users; customer-facing chat with order data is a separate solution. Nor does it replace document owners: when sources conflict or are missing, it says so and names the person responsible.

This page describes a growth capability. Netbase has delivered a RAG knowledge assistant for a client that is not named, recorded as an anonymised portfolio record; the design below is how we build and govern one, not a record of that client's results. It belongs to the digital products family.

Why company knowledge is hard to use

  • Current state
    Answers live in shared drives, wikis, tickets and people's heads
    Target state
    One assistant searches approved sources on the user's behalf
  • Current state
    New staff ask the same questions every week
    Target state
    Routine questions answered with a link to the source
  • Current state
    Search returns files, not answers
    Target state
    A short answer with the passages that support it
  • Current state
    Anyone who finds a file can read it
    Target state
    Answers built only from documents the user may already open
  • Current state
    Outdated procedures keep circulating
    Target state
    Owners see which sources are used, stale or contradicted
  • Current state
    No one knows whether AI answers are right
    Target state
    A test set and reviewer feedback measure answer quality over time

How the assistant answers a question

The workflow, step by step:

  1. Connect

    Approved sources such as document stores, wikis, ticket history and policy libraries are connected, each with an owner.

  2. Index

    Documents are split into passages and indexed together with their access rights and last-updated dates.

  3. Ask

    An employee asks a question in the chat surface or inside a tool they already use.

  4. Retrieve

    The assistant searches only the passages this user is allowed to read.

  5. Answer

    It drafts a short answer from those passages and cites each one.

  6. Check

    If the passages do not support an answer, it says it does not know and suggests the document owner or an expert.

  7. Review

    Users rate answers; flagged answers go to a reviewer queue.

  8. Improve

    Reviewers fix sources or rules, and the test set is re-run before each change goes live.

Capability modules

Document stores, wikis, tickets → Syncs approved content with owners → Current source library

Documents and access rights → Splits, cleans and indexes passages → Permission-aware index

Question and user identity → Finds allowed passages → Ranked evidence

Evidence passages → Writes a grounded answer → Answer with citations

Questions and answers → Blocks out-of-scope or unsafe requests → Safe, on-topic responses

Low-rated or flagged answers → Routes to named reviewers → Corrected sources and rules

Test questions and expected sources → Scores accuracy and citation quality → Release decision per change

Requests per user and team → Applies quotas and limits → Predictable running cost

Every question, answer and source → Records who asked what, and when → Traceable history

Illustration of a glowing central node linked to a network

The chat surface can start from the AI chatbot and WorkChat integrator in the Netbase productized module library, and the retrieval engineering behind it is our enterprise knowledge and RAG service.

AI in this solution

Where AI already runs in delivered work, and where it is offered as a growth capability.

Governance, integrations, data and deployment

  • Human-in-the-loop points

    Document owners approve which sources are connected; reviewers handle flagged answers; answers on regulated topics such as HR, legal or finance can be set to "draft for review" instead of direct reply.

  • Evaluation

    Before launch and before every change, a test set of real questions with expected sources is scored for correctness, citation quality and refusals. The NIST AI Risk Management Framework and its Generative AI Profile shape how risks are mapped, measured and managed.

  • Access control

    Retrieval runs as the user, so the assistant never quotes a document that person could not open. Admin roles are separate from reviewer roles.

  • Audit log

    Every question, retrieved passage, answer and rating is logged with user and time, and retention follows your policy.

  • Data boundary

    Content stays in your systems and your index. The model provider, hosting region and whether prompts may be retained are decided in architecture and written into the contract. The OWASP Top 10 for LLM Applications lists sensitive information disclosure, vector and embedding weaknesses and misinformation among the key risks; the design addresses each one.

  • Cost limits

    Quotas per user and team, caching of repeated answers and a monthly budget alert keep running cost predictable.

  • Security and compliance

    Netbase security practices apply by design: secure code review, TLS in transit and AES at rest, role-based access with MFA, vulnerability scanning, penetration testing and disaster recovery. Netbase follows GDPR alignment for data privacy in Europe, HIPAA-aligned methods for healthcare data and CCPA compliance for clients with U.S. customers. Data and model choices are covered in our data and AI stack.

Implementation phases, roles and support

  1. Use-case and knowledge audit

    Pick one team and its most repeated questions, and list the sources and owners.

  2. Data and permission review

    Check access rights, remove stale content and agree the data boundary.

  3. Pilot with evaluation

    Build the assistant for that team, with a test set and success thresholds agreed in advance.

  4. Governed rollout

    Extend to more teams and sources only when the test scores hold.

  5. Operate and improve

    Review flagged answers, refresh sources and re-run the tests.

A typical team combines a business analyst, a solution architect, AI and backend engineers, QA and a project manager. The pilot runs in short Agile sprints with a weekly demo on your own questions, the team works remote-first from Hanoi in English, and the assistant is served through an API so the intranet, chat tools and mobile apps share one governed service. Timeline drivers are the quality of sources, the permission model and your review capacity. For feature work beyond the assistant, see generative AI development. Most Netbase projects are delivered on fixed-price contracts, with scope and price agreed after the audit; milestone-based, monthly team retainer and KPI-linked terms are also offered.

Configuration, customization, IP and lock-in

  • Configured

    Connected sources, roles, topics that need review, quotas and answer style.

  • Customized

    Connectors for internal systems, retrieval tuning, evaluation sets and the chat surface.

  • Ownership

    You own the IP Netbase creates for your custom development and your index; Netbase productized modules are licensed, not transferred. The model layer sits behind an interface, so the provider can change without rebuilding the assistant.

Industry variants and use cases

Professional services

Consultants find past proposals, methods and project lessons; see professional services.

Professional services

HR and policy

Staff get cited answers on leave, benefits and internal rules, with sensitive topics routed for review.

IT and internal support

First-line questions answered from runbooks and past tickets.

Sales and proposals

Teams pull approved product facts and references into proposals.

Operations manuals

Field and back-office teams query procedures instead of searching folders.

Proof: an anonymised assistant and Cloodo

Delivered: RAG knowledge assistant (anonymised client). Netbase delivered a retrieval-augmented knowledge assistant as AI consultant, engineer and integrator. The record publishes the kind of system and Netbase's role only: no client name, sources, model or results.

Cloodo, one of the Netbase Business Divisions, is an AI-powered digital workplace for company profiles, services, projects and team collaboration that connects internal staff and outsourced specialists in one hybrid workspace, with CRM, HRM, Cloud ERP and AI modules. Netbase builds and runs it.

Cloodo is platform proof, not a knowledge-assistant case: it shows Netbase designing and operating an AI-enabled workplace product. No usage figures are published. Read the Cloodo Workspace record and see more in our work.

Cloodo Workspace: the work-management SaaS Netbase built and operates
Cloodo Workspace: the work-management SaaS Netbase built and operates

It puts company profiles, service listings, projects, tasks and team collaboration in one cloud workspace, beside CRM, HRM, Cloud ERP and AI modules, for internal staff and outside specialists alike.

Keep Reading
Retrieval-augmented knowledge assistant for an anonymous client
Retrieval-augmented knowledge assistant for an anonymous client

This anonymous portfolio record describes only the kind of AI system and what Netbase did; it publishes no client name, logo, location, dates, model choice, figures or results.

Keep Reading

Frequently asked questions

It is designed to answer only from retrieved passages and to say "I don't know" otherwise. Evaluation measures how often it gets this right before each release.

No. Retrieval runs with the user's own permissions.

The model is chosen in architecture against your data boundary, cost and quality needs, and it can be changed later. We work with models from OpenAI, Anthropic (Claude), Google (Gemini) and Meta (Llama), among other commercial and open-weight models.

With one team, one set of sources and a pilot measured against a test set.

Enterprise AI knowledge assistants: RAG engineering with access control Enterprise AI knowledge assistants: RAG engineering with access control

Netbase engineers retrieval-augmented generation (RAG) over company knowledge: the ingestion, search, permission checks, cited answers and evaluation that let a language model answer from your own documents and systems. It is a growth capability with access control and evaluation designed in from the first prototype, and Netbase has delivered a RAG knowledge assistant for a client that is not named.

Learn More
line

Related solutions and next step

Explore the other Netbase solutions or view relevant work. Send us the questions your team answers most often and where the answers live, and we will review this solution for your workflow.

Contact Netbase

Discuss a project

Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.
Project enquiries

[email protected]

WhatsApp

+84 937 869 689

Office address

91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam

Get in touch

Tell us what you want to build, modernize, or operate.

Tell us what you want to build, modernize, or operate.

Contact Netbase