Permission-aware enterprise knowledge assistant
How we design a RAG assistant that answers from thousands of internal documents while respecting every user's access rights.
This is a reference architecture describing how Shivacha approaches this class of system. It does not describe a specific client engagement and contains no client names or results.
Challenge
Employees spend significant time searching wikis, policy libraries, ticket histories and shared drives. A generic chatbot cannot be trusted with this: answers must be grounded, cited and restricted to content each employee is allowed to see.
Context
Typical of organisations with several knowledge systems, strict document permissions, and security teams that require data to remain inside the organisation's cloud environment.
Approach
How we approach it
- 1
Evaluation set first
Collect real questions from several departments with expected answers and sources before building.
- 2
Connector-based ingestion
Incrementally sync documents and their permission metadata from each source system.
- 3
Hybrid retrieval with ACL filtering
Combine keyword and vector search, filtered by the user's groups at query time.
- 4
Cited, constrained answers
Answers must cite passages; the assistant declines when sources are insufficient.
Architecture
System design
Technology
Implementation
Key implementation elements
Identity integration
SSO groups mapped to document permissions.
Freshness monitoring
Alerts when sources fall behind sync targets.
Model gateway
Provider abstraction with logging and cost attribution.
Embedded UI
Assistant available in the intranet and chat tools.
Outcome
The design goal is an assistant that employees can rely on: every answer traceable to a source they are allowed to read, with quality measured continuously against the evaluation set rather than judged anecdotally.
Lessons
- Permission metadata is as important as document content — sync it with the same rigour.
- Evaluation sets built from real questions surface retrieval gaps early.
- Declining to answer is a feature; users trust assistants that admit uncertainty.
Services
Services involved
RAG Development
Retrieval-augmented generation systems that ground LLM answers in your documents with permissions, citations and measurable accuracy.
Learn moreEnterprise AI Solutions
Enterprise AI programmes: shared AI platforms, governance, security and a portfolio of production use cases across the organisation.
Learn moreAI Integration Services
Integrate AI capabilities into existing products, ERP, CRM and internal systems through APIs, events and embedded UI.
Learn moreMore work
Other reference architectures
Agentic claims intake with human approval
A reference design for an AI workflow that reads claim submissions, extracts and validates data, and prepares cases for adjusters.
Learn moreMulti-tenant SaaS foundation built for enterprise readiness
The foundations we put in place when building a SaaS product that will need to sell to enterprises.
Learn moreIncremental replacement of a legacy monolith
Our strangler-pattern approach for replacing a critical legacy system domain by domain without downtime.
Learn moreNext step
Discuss a similar project.
Building something like "Permission-aware enterprise knowledge assistant"? Tell us about your goals and constraints and we will reply with an approach and next steps.
- Senior engineer reads every enquiry
- Reply within one business day
- NDA on request
Your details are used only to reply to this enquiry.
