Skip to content
Shivacha — Simplifying Tech Solutions
Shivacha AIReference architecture

Permission-aware enterprise knowledge assistant

How we design a RAG assistant that answers from thousands of internal documents while respecting every user's access rights.

This is a reference architecture describing how Shivacha approaches this class of system. It does not describe a specific client engagement and contains no client names or results.

Challenge

Employees spend significant time searching wikis, policy libraries, ticket histories and shared drives. A generic chatbot cannot be trusted with this: answers must be grounded, cited and restricted to content each employee is allowed to see.

Context

Typical of organisations with several knowledge systems, strict document permissions, and security teams that require data to remain inside the organisation's cloud environment.

Approach

How we approach it

  1. 1

    Evaluation set first

    Collect real questions from several departments with expected answers and sources before building.

  2. 2

    Connector-based ingestion

    Incrementally sync documents and their permission metadata from each source system.

  3. 3

    Hybrid retrieval with ACL filtering

    Combine keyword and vector search, filtered by the user's groups at query time.

  4. 4

    Cited, constrained answers

    Answers must cite passages; the assistant declines when sources are insufficient.

Architecture

System design

Technology

Permission-aware enterprise knowledge assistant
5Sources
WikiDocument storageTicketingPolicy library
4Ingestion
ConnectorsParsing & chunkingPermission syncEmbeddings
3Retrieval
Hybrid searchACL filterRe-ranking
2Generation
Model gatewayGrounded promptCitation validation
1Operations
Evaluation runsFeedback captureAudit logs

Implementation

Key implementation elements

Identity integration

SSO groups mapped to document permissions.

Freshness monitoring

Alerts when sources fall behind sync targets.

Model gateway

Provider abstraction with logging and cost attribution.

Embedded UI

Assistant available in the intranet and chat tools.

Outcome

The design goal is an assistant that employees can rely on: every answer traceable to a source they are allowed to read, with quality measured continuously against the evaluation set rather than judged anecdotally.

Lessons

  • Permission metadata is as important as document content — sync it with the same rigour.
  • Evaluation sets built from real questions surface retrieval gaps early.
  • Declining to answer is a feature; users trust assistants that admit uncertainty.

Next step

Discuss a similar project.

Building something like "Permission-aware enterprise knowledge assistant"? Tell us about your goals and constraints and we will reply with an approach and next steps.

  • Senior engineer reads every enquiry
  • Reply within one business day
  • NDA on request

Prefer to talk first?

Book a 30-minute call, or message the nearest team on WhatsApp.

Book a Call

Your details are used only to reply to this enquiry.

Step 1 of 2Your details

Confidential. We reply within one business day. Privacy