Knowledge Assistant Solution
RAG assistant that answers over your documents securely
The challenge
Knowledge is spread across SharePoint, file shares, wikis and closed tickets, so people ask a colleague instead of searching. The answer depends on who you ask, new joiners take months to become useful, and any search tool that ignores source permissions is a data leak waiting to happen.
The outcome
Azure AI Document Intelligence parses the content, Azure AI Search indexes it with the source permissions attached, and Azure OpenAI answers with a citation. Retrieval is security-trimmed before generation, so people only ever see what they were already entitled to read, and unanswerable questions are logged as gaps.
01 — Architecture
End-to-end architecture
Content is crawled from SharePoint, file shares and wikis, parsed by Document Intelligence, chunked and embedded into a hybrid AI Search index that carries the source permissions. At query time the retrieval is security-trimmed before generation, so the assistant can only ground an answer in material the user was already allowed to read.
- User: Employee / Customer
- Front end: Azure Static Web Apps, Microsoft Teams
- Application: Azure API Management, Azure Container Apps
- AI & retrieval: Azure AI Search, Microsoft Foundry Agent, Azure OpenAI models, Azure AI Content Safety
- Content & data: SharePoint / OneDrive, AI Document Intelligence, Azure Blob Storage
- Governance & insight: Permission trimming, Azure Key Vault, Power BI / Fabric
02 — Workflow
Process & decision workflow
How content becomes a trustworthy answer — connect, parse, chunk, index, retrieve and answer, then branch. A grounded answer is returned with its citations; when no trusted source exists the assistant says so, logs the gap and offers a human route rather than guessing.
- Connect: SharePoint, file shares, wikis and ticket systems
- Parse: PDFs, decks and tables turned into clean text
- Chunk: Split, embed and tag with source and permissions
- Index: Hybrid keyword and vector index in Azure AI Search
- Retrieve: Security-trimmed passages fetched for the question
- Answer: Grounded response with citations and confidence
- Path 1 · grounded answer — Answer with citations: Response returned with links to the source
- Path 2 · no trusted source — Say so and route on: The assistant declines, logs the gap and offers a human
03 — Components
Key Microsoft components
Enterprise retrieval-augmented generation is a permissions problem as much as a search problem — both are handled inside the Microsoft ecosystem.
Azure AI SearchHybrid keyword and vector index with security trimming.
Azure OpenAI modelsEmbeddings, query rewriting and grounded answer generation.
Microsoft Foundry Agent ServiceRetrieval tools, citation rules and refusal behaviour.
Azure AI Content SafetyGuardrails against ungrounded, unsafe or off-topic answers.
Azure AI Document IntelligenceParses PDFs, decks, scans and tables into clean text.
Microsoft Entra permissionsSecurity trimming so users only retrieve what they may read.
Azure FunctionsChunking, embedding and incremental index refresh.
Azure Logic AppsConnectors and scheduled crawls across content sources.
Azure Blob StorageSource documents, chunks and extracted artefacts.
Azure Cosmos DBConversation history, feedback and citation records.
Azure Container AppsRetrieval orchestration API that scales with usage.
Azure API ManagementSecure gateway, throttling and per-application access.
Azure Key VaultConnector secrets, keys and certificate management.
Power BI / Microsoft FabricUsage, answer quality and knowledge-gap dashboards.
04 — AI
What the agent consumes
The capabilities behind every answer, and the line the assistant does not cross.
AI capabilities embedded in the agent
- Document parsing
- Semantic chunking
- Vector embeddings
- Hybrid retrieval
- Query rewriting
- Retrieval-augmented generation
- Answer citation
- Groundedness scoring
- Security trimming
- Refusal on low confidence
- Knowledge-gap detection
- Workflow orchestration
AI responsibility boundaries
The assistant answers only from indexed content the user is already permitted to see, and every answer carries its citation. Where no trusted source exists it says so rather than guessing, logs the gap for the content owner and offers a human route. Permissions are enforced at retrieval time, not filtered after generation.
05 — Personalization
Personalization & evolving process
The same methodology applies to every agent in the catalog. Tune the content sources, the retrieval template, the guardrails and the value model — the page structure stays identical.
Content & audience profile
Define the repositories in scope, languages, sensitivity labels, refresh cadence and who may see what. The personas are the employee, the content owner, the compliance officer and the external customer.
Retrieval template
One consistent flow for every knowledge agent: connect, parse, chunk, embed, index, security-trim, retrieve, answer with a citation and capture feedback on the answer.
Rules & guardrails
Declare the authoritative sources, freshness rules, refusal thresholds, tone, restricted topics and escalation routes. An answer that cannot be grounded is refused, not improvised.
Value model
Capture baseline metrics first, then map the expected benefits: time spent searching, repeat questions to experts, onboarding time, ticket deflection and content freshness.
06 — Impact
Key outcomes & business impact
Starting targets for the value case — validate each one against the customer baseline during discovery.
- Search time−60%Answers arrive with citations instead of a list of links.
- Expert interruptions−40%Repeat questions are answered from the indexed source of truth.
- OnboardingDaysNew joiners self-serve against the same trusted knowledge base.
- Answer traceability100%Every response links to the passage and document behind it.
Illustrative improvement index
Manual baseline = 100. Illustrative targets, not a commitment — confirm against the customer baseline.
- Time to find an answer: manual baseline 100, AI-assisted target 40
- Expert interruptions: manual baseline 100, AI-assisted target 60
- Onboarding ramp time: manual baseline 100, AI-assisted target 45
Related & recommended
Derived automatically from our solution knowledge graph.
Related professional services
How we design, build and secure it.
AI Governance
AI Governance delivered by Cloud Mechanics certified experts.
AI Integration
AI Integration delivered by Cloud Mechanics certified experts.
Data Engineering
Data Engineering delivered by Cloud Mechanics certified experts.
AI Agent Development
AI Agent Development delivered by Cloud Mechanics certified experts.
Related quick wins
Ready-made Azure AI to start fast.
Technologies
What powers this solution.
Related managed services
Keep it running and optimised.
AI Managed Services
AI Managed Services from our UAE-based 24/7 Cloud Operations Center.
Cloud Managed Services
Cloud Managed Services from our UAE-based 24/7 Cloud Operations Center.
DevOps Managed Services
DevOps Managed Services from our UAE-based 24/7 Cloud Operations Center.
FinOps / Cloud Cost Management (OpsNow)
FinOps / Cloud Cost Management (OpsNow) from our UAE-based 24/7 Cloud Operations Center.
Ready to move from challenge to solution?
Talk to a Cloud Mechanics expert or build your solution in minutes.