Field note / Knowledge
Permissioned knowledge systems for professional work.
Start with one internal knowledge job, named users, selected sources, visible citations, and no silent external action. Accumulated expertise becomes more useful when the team can retrieve and verify it without treating sensitive material as a generic corpus.
/
The decision in one line
Build a narrow, permissioned knowledge surface with visible sources before granting broader action.
Start with selected users, selected sources, and no silent external action. Expand only when retrieval quality, permissions, and review prove trustworthy.
Knowledge is not a dump
What the team needs is rarely “everything we have ever written.”
Professional work accumulates procedures, prior work product, templates, internal guidance, and relationship context across documents, inboxes, and individual memory. Dumping that into an open model context is not a knowledge system—it is a permissions and attribution failure waiting to happen.
A useful first surface is curated: named collections, clear owners, sensitivity labels, and a retrieval path the team can inspect. ShepBuild’s private AI work begins with that inventory, especially for professional services teams.
Attribution is the product
An answer without a source is usually unfinished work.
When judgment is part of the firm’s value, the system should show what it retrieved and where it came from. That lets a person verify, revise, or reject the preparation before it becomes a client-facing or filing-related action.
Source visibility also teaches the team when the corpus is thin, stale, or conflicting. Those are operating problems—not prompts to paper over. Compare patterns in agents, automation, and knowledge so the job does not get sold as a broad agent by default.
- Who may search which collections?
- What sources are in scope?
- How are answers attributed?
- What requires a person before external action?
Local, private, or carefully cloud
The architecture follows the data path, not the demo.
Some knowledge workloads belong closer to the business through local inference or private deployment patterns. Others can use carefully configured cloud services with retention, access, and logging controls the firm can accept. Privacy is never only “where the model runs.”
The local AI decision guide helps owners compare those options against one real job. Hybrid designs are often honest: sensitive collections stay tightly bounded while lower-sensitivity preparation uses a different path.
A sound first build
One permissioned assistant with selected sources and no silent send.
A strong first knowledge system helps a defined group find procedures, assemble background for review, or prepare a bounded draft with visible sources. It does not invent policy, send client messages, or change records without explicit authority.
After that evidence exists, the firm can decide whether to expand collections, add users, or connect preparation into automation for deterministic routing—still keeping judgment with the authorized person.
Original control test
Prove the permission boundary with one answer and one denied request.
The ShepBuild permission-boundary test is a diagnostic, not a client result. For one real question, record who asked, which source collection was searched, what evidence supported the answer, what action was allowed, and what receipt remained. Then repeat the request as a user who should not have access and confirm the system denies retrieval without revealing sensitive metadata.
The control model follows primary guidance rather than a vendor promise. NIST SP 800-207 rejects implicit trust based only on network location and emphasizes resource-focused, least-privilege access. The FTC's Start with Security guide advises businesses to minimize collected data and restrict access. AI-specific governance can be mapped with the NIST AI Risk Management Framework.
- Identity: which authenticated user or role is asking?
- Scope: which named collections may that identity search?
- Evidence: which source, version, and date support the answer?
- Authority: may the system answer, draft, send, or change a record?
- Receipt: what durable event shows the request, decision, and result?
Useful answers before a tool is chosen.
01Is a public chatbot a good first knowledge system?
Usually not. Public chat is hard to evaluate, easy to over-promise, and often disconnected from the internal sources that create leverage. Prefer a bounded internal surface first.
02Do we need every document in the system on day one?
No. Start with the collections that support one valuable job. Breadth without ownership and attribution usually reduces trust instead of increasing it.
03Can the system draft for us?
Yes, when drafting is preparation for human review. Drafting that becomes silent external action needs a separate authority decision.
04How does this differ from workflow automation?
Automation executes a known path with a receipt. A knowledge system retrieves and prepares with sources. Many firms need both, sequenced carefully—see agents, automation, and knowledge.
One problem. One useful first build.
Map the knowledge, the users, and the boundary before choosing a model.
The AI Build Session defines one permissioned knowledge job the team can evaluate honestly.
Start a conversation