AI delivery · Retrieval

An internal assistant that respects access rights and shows its sources

If you need an assistant or search tool over private documents, you can commission me to design and build it as a bounded delivery. I start with a source and permission assessment and a relevance set built with your experts, then deliver retrieval that enforces access rights in the query, cites its sources, keeps the index fresh, and passes agreed evaluation before handover.

This is a good fit if…

  • You are building a new internal knowledge assistant, support-knowledge tool or enterprise search product and want one person accountable for delivering it.
  • Your documents carry real access rules (per team, per client, per tenant) and the assistant must never show a user a passage they could not open themselves.
  • Users need to see where each answer came from, so they can check it and trust it.
  • You have an internal owner for the knowledge system after launch, even if they cannot build it today.

Look elsewhere if…

  • You already have a RAG system and its answers have degraded. Use RAG quality rescue instead; it starts from a failure analysis, not a design.
  • You want an engineer working under your manager on your existing retrieval backlog. Hire a RAG engineer on contract instead.
  • You need to establish whether a retrieval or knowledge-conflict method generalises. That is a research study, run through dipankar.cc.

What you get

Retrieval and knowledge-system implementation

  • A source inventory with owners, access rules and update frequency for every corpus in scope.
  • Retrieval that applies access controls inside the query, tested with a permission test set that must show zero leaks.
  • Answers with citations to the exact passage and document version used.
  • Ingestion with freshness checks, so new and changed documents appear and withdrawn ones disappear.
  • A relevance evaluation set and harness your team can run on every change.
  • A runbook and handover to a named owner.

How it runs

  1. 01

    Brief and fit check

    You describe the users, the document sources and the access model. I reply with questions and a view on fit before anything is signed.

  2. 02

    Source and permission assessment

    I inventory sources, trace how access rights are expressed in each, and build the first relevance and permission test sets with your domain experts.

  3. 03

    Build and evaluate

    Ingestion, chunking, indexing, retrieval, re-ranking and answer assembly are built in your environment, with every design choice measured against the test sets.

  4. 04

    Pilot with real users

    A limited group uses the assistant on real questions. Failures are logged, classified and fixed or recorded as known limits.

  5. 05

    Acceptance and handover

    Agreed evaluation thresholds are checked, the owner signs off, and the harness, runbook and remaining backlog are transferred.

What needs to be in place

  • Named source systems in scope and an owner for each who can confirm access rules.
  • Service access to those systems, including the permission metadata, provisioned through your normal process.
  • Two or three domain experts who can label relevance for a few hours a week during the build.
  • A decision on where the system runs and which model providers are approved for your data.

Not included

  • Cleaning up or restructuring the source content itself, beyond flagging problems to the content owners.
  • A promised accuracy figure before the baseline is measured.
  • Answers that constitute legal, financial or medical advice without human review.
  • Ongoing operation after handover unless agreed separately as maintenance.

Retrieval work: commission, repair, hire or research

What you are buyingStart here whenMain output
RAG and enterprise search (this page) A designed and built outcomeNo system yet, or the current one is being replacedPermission-aware retrieval with citations, freshness checks and evaluation
RAG quality rescue A bounded repair with acceptance criteriaAn existing assistant retrieves the wrong or outdated sourcesFailure analysis, freshness tests, permission checks and evaluated repair
Contract RAG engineer Senior capacity under your managerYour team owns the system and needs hands on its backlogRetrieval backlog, evaluation plan and handover
Research study (dipankar.cc) A validation of a method or claimYou need to know whether a finding generalisesStudy protocol and evidence, not a production system

The situation

You want people to ask questions of your organisation’s documents and get answers they can trust: policies, contracts, product specifications, support articles, project files. The demo is easy. A weekend prototype can embed some PDFs and answer questions about them.

What stops it reaching real users is less visible. Documents live in several systems with different access rules. Some are superseded but never deleted. Some users must never see certain content. And when an answer is wrong, nobody can tell whether the system retrieved the wrong passage, ranked the right one too low or simply invented something.

This page is for commissioning the system properly: designed and built as a bounded delivery, with access rights, citations and freshness as acceptance criteria rather than afterthoughts.

What the work involves

Sources and permissions first. Before any embedding, I inventory every source in scope: where it lives, who owns it, how often it changes, and how access is expressed (groups, folders, client codes, tenant IDs). The hardest design decision in most enterprise retrieval is how to carry those rules into the index so they can be enforced in the query. Post-filtering after retrieval leaks, and it also starves the model of context.

A relevance set before a pipeline. With two or three of your domain experts, I build a set of real questions, the passages that should answer them, and passages that must never appear for given roles. This becomes the measure for every choice that follows.

Retrieval designed for your content. Chunking that respects document structure, hybrid lexical-plus-vector search where exact terms matter (part numbers, clause references, product codes), metadata filters for version and access, and re-ranking where it measurably helps.

Answers that show their sources. Each answer cites the passage and document version used. If nothing relevant is retrieved, the assistant says so rather than improvising.

Freshness as an operational property. Ingestion runs on changes or a schedule, with alerts when a source stops updating and removal of withdrawn documents.

The signature deliverable

You receive the retrieval and knowledge-system implementation: ingestion, index, retrieval service and answer interface in your environment, plus the evaluation harness, permission test set, source inventory and runbook. Illustrative example of an evaluation summary at acceptance:

Question categoryQuestionsCorrect passage in top 5Cited correctlyPermission leaks
HR policy4037360
Product specifications5549480
Client contracts (restricted)3026260

Illustrative example. Figures are placeholders showing the format, not results from a client.

How acceptance is judged

After the source assessment and baseline, we agree thresholds in writing: retrieval recall per question category, citation correctness, zero leaks on the permission set, and a freshness check that passes for each source. The pilot adds real-user failures to the evaluation set. Your named owner signs off against those measures. Where a category falls short, the cause is recorded with options rather than hidden in an average.

Ownership and handover

Everything runs in your accounts and repositories. The owner receives the harness, the test sets, the source inventory, the re-indexing and access-change runbook, and a prioritised backlog of known limits. I pair with at least one of your engineers during the build so the system is not a black box at handover. I do the work personally; any specialist help is disclosed and approved by you first.

When to choose something else

If you already run an assistant and its answers have drifted, RAG quality rescue starts from a failure analysis of your live system. If your team owns retrieval and needs senior capacity under its own manager, hire a RAG engineer on contract. If the blocker is that sources and access rules are unknown or scattered, start with AI data readiness. If you need to know whether a retrieval method holds in general, that is a research question for dipankar.cc.

Questions buyers ask

How do you stop the assistant showing people documents they should not see?

Access rules are carried from each source into the index as metadata and applied inside the retrieval query, not filtered after the model has seen the text. A separate permission test set, built with your owners, checks that users of each role cannot retrieve restricted passages. That set must pass with zero leaks before acceptance.

Which vector database or model will you use?

Whatever fits your environment and your team can operate. Often that is search you already run, such as PostgreSQL with pgvector or Elasticsearch, rather than a new service. Model providers must be ones your organisation has approved for the data. The choice is recorded with its reasons.

How is this different from hiring a RAG engineer?

Here you commission an outcome with acceptance criteria, and I am responsible for delivering it. A contract buys my time under your manager on your backlog, and decisions stay with your team. If you have a retrieval team that needs senior hands, the contract route is usually cheaper and simpler.

What happens when documents change?

Ingestion runs on a schedule or on change events, depending on the source. Each source gets a freshness check that alerts if updates stop arriving, and withdrawn documents are removed from the index. Answers cite the document version, so a stale answer is visible rather than hidden.

What if retrieval quality is not good enough at the end?

Acceptance thresholds are agreed after the baseline, not guessed upfront. If the system falls short, you get a written account of which question types fail and why, and the options. Some content cannot support reliable answers until it is rewritten, and that is a finding rather than a failure to hide.

Describe your retrieval problem

A short, non-confidential description is enough to start. I read every brief personally and reply within two business days, including when the answer is that I am not the right fit.

Step 1 of 2 · The basics