Max Tymoshyn, founder of Norml Studio
Max TymoshynFounder, Norml Studio

Internal AI knowledge-base assistant

Your policies and operating instructions live in documents, but employees still need help finding the relevant section. We build an internal assistant that retrieves approved material and answers with source references. The first scope uses a defined Google Drive collection and Claude, with access checks before any document text reaches the model.

Answers grounded in permitted documents

Choose a specific document collection and employee audience first. The implementation must account for the source files, their permissions and the way changes reach the retrieval index.

Solution
Integrations
Connected systems
Claude + Google Drive
Data flow
An authenticated employee asks a question. The retrieval service selects only permitted Google Drive material and sends relevant passages to Claude. The answer returns with source references; Drive remains the document owner, and the assistant does not edit files or perform business actions.

Prepare a controlled collection

Identify current documents, duplicate policies and material that must stay outside the assistant. Preserve source identifiers and version information so an answer can be traced to the document used.

Enforce document access

Design identity and permission checks for the chosen collection. An index does not inherit Google Drive permissions automatically. The system must exclude denied content before generation, including when a user loses access after a document was indexed.

Show sources and uncertainty

Connect retrieved passages to answer citations and provide a clear response when evidence is missing or conflicting. Source links support review; staff still need to check the underlying document before relying on a consequential interpretation.

Maintain the document lifecycle

Define refresh, removal and permission-change handling. Content owners need a way to retire a source and investigate unanswered questions without treating every employee conversation as a new approved policy.

What we need before building

Source and access owners

Provide the Drive collection, supported file types and the people responsible for document accuracy. Identify groups that share the same access and any exceptions that require separate handling.

Identity and account policy

Confirm how employees sign in and which model account may process the material. Check data retention, logging access and available API features before indexing confidential documents.

A representative question set

Supply questions with known answers, conflicting versions and examples that should return no answer. Include users with different access so the evaluation covers permission boundaries as well as helpfulness.

How we build and test it

  1. Map documents and permissions

    Inspect representative files and their access paths. Agree on a supported audience and source set before implementing retrieval.

  2. Test retrieval and answers

    Compare cited answers against the source text. Test a denied document, revoked access, deleted source and a question whose answer is absent.

  3. Hand over source maintenance

    Document how new files enter the collection, how removed files leave it and who reviews content issues. Provide a way to disable a source while a problem is investigated.

Questions about this implementation

Does connecting Google Drive preserve every permission automatically?
No. The integration needs an explicit access model. We verify the selected route against Drive identities, groups and file access, then test retrieval under different users. Unsupported sharing cases must be excluded or handled before release.
Can staff ask about all company documents?
Only the approved collection within their verified access. A smaller collection with a clear owner is the starting point; additional sources need their own format, permission and refresh checks.
Do citations guarantee the answer is correct?
No. A citation identifies supporting source material, but interpretation can still be wrong or incomplete. We evaluate answers against known examples and define when the assistant should report uncertainty or direct the employee to a document owner.
Can this assistant update CRM records or approve requests?
The starting scope is document retrieval and answers. Record updates and approvals are separate action integrations with their own permissions, confirmation and audit requirements.
Share the collection your team relies on and several questions employees ask about it. We will scope the source set, audience and access checks.

Make one document collection easier to use.

Discuss your AI integration