Initial IAAsk a question ↗
← All resources

Method · 9 min

A reliable document assistant:
the checks that make the difference.

A practical protocol for building, testing and operating an assistant that cites sources and respects permissions.

IN 60 SECONDS

Key takeaways.

  1. 01

    A good model cannot compensate for outdated, poorly segmented sources or access granted to the wrong people.

  2. 02

    Answers must show their sources, know when to abstain and retain a usable audit trail.

  3. 03

    Quality is measured with known-answer questions, unanswerable questions and permission tests.

01 · Follow the answer

A reliable answer is a chain of checks.

In a document assistant, the model should not improvise solely from its own memory. The question is associated with the user, permissions are checked, relevant passages are retrieved and the answer is then written from that context.

Each step can fail independently. Quality therefore needs to be diagnosed across the whole chain, not just in the final text.

02 · Secure

Seven checks to make visible.

These checks turn a convincing demonstration into an operational professional tool.

  • Authorised sources: clear inventory, identified owner and update date.
  • Permissions before search: a prohibited passage must never enter the model's context.
  • Controlled index: managed segmentation, metadata and versions.
  • Citations: a document, passage or link for every important claim.
  • Abstention: an explicit answer when sources are insufficient.
  • Evaluation: a versioned question set rerun after every change.
  • Operations: logs, alerts, user feedback and an owner responsible for fixes.
03 · Test

A minimum protocol before opening access.

Build a test set with business teams. Keep it small enough to rerun often, but varied enough to expose failures.

  1. 01

    20 questions with known exact answers and sources.

    ✓
  2. 02

    10 questions the documents cannot answer.

    ✓
  3. 03

    5 attempts to access content restricted to another role.

    ✓
  4. 04

    5 cases involving old, ambiguous or contradictory documents.

    ✓
  5. 05

    A defined acceptance threshold for citations, abstention and permission leaks.

    ✓
  6. 06

    Human review of errors, with their causes and corrective actions.

    ✓
04 · Monitor

Measure what the user can verify.

Track the proportion of answers supported by a valid source, abstention quality, permission incidents, response times and requested corrections. A single overall score often hides the actual problem.

Helpful / not helpful feedback is useful, but does not replace factual checking. Fluent text can still be wrong; a brief answer with a good source can be much more useful.

DECISION POINT

Objective: an answer that can be traced and challenged. The assistant supports decisions; it does not remove human responsibility.

SOURCES & METHOD

Check and explore further.

We prioritise official texts and reference frameworks. This guide's recommendations are our practical interpretation of those sources, to adapt to your context.

  1. 01
    NIST — AI Risk Management Framework ↗

    Structured approach to governance, measurement and risk management.

  2. 02
    ANSSI — Security of generative AI systems ↗

    Recommendations for architecture, data and operations.

  3. 03
    CNIL — Personal data security ↗

    Organisational and technical measures to protect data.

Private document assistant

Want to test the assistant on your own documents?

We build the test set, permissions and citations with the people who actually know the sources.

View the related service ↗