Article summary
- A private AI assistant should only access approved sources needed for a defined business task.
- The assistant must preserve the access rights of the original systems instead of creating a new route around them.
- Privacy controls include data minimisation, retention rules, logging, deletion procedures and supplier review.
- Human escalation and named ownership are necessary when answers are uncertain or sensitive.
Key takeaways
- Start with one low-risk source collection and one measurable workflow.
- Separate retrieval, drafting and action-taking permissions.
- Test the system with different roles and deliberately restricted documents.
- Document who maintains sources, reviews incidents and approves changes.
Define the purpose before connecting data
Write down the exact task, users, approved sources and expected output before selecting technology. A narrow assistant that finds an approved procedure is easier to govern than a general assistant connected to every drive, mailbox and business system. Do not collect data merely because it may become useful later.
Minimise the information the assistant can access
Use the smallest source set that can solve the task. Exclude personal, contractual, financial or confidential material unless it is genuinely required and protected by an appropriate process. Prefer approved folders, curated knowledge bases and explicit source owners over unrestricted access to shared storage.
Preserve permissions from the source systems
A user should never receive information through the assistant that they could not open in the original system. Identity checks, role-based access, document-level filtering and permission-aware retrieval should happen before content reaches the model. Drafting permission should also remain separate from permission to send messages, change records or publish content.
Decide what is stored, logged and deleted
Decide whether prompts, retrieved passages, answers and feedback are stored. Define retention periods, incident logs, deletion procedures and who can inspect usage records. Avoid keeping full sensitive conversations by default. When an employee leaves or a document becomes obsolete, access and indexed copies need a clear removal path.
Review suppliers, hosting and integrations
Document where data is processed, which subprocessors or external services are involved, what integrations can read or write, and how credentials are protected. Review contractual and technical controls with qualified privacy or legal advisers where necessary; this article is an operational checklist, not legal advice.
Test sensitive cases and human escalation
Test with real questions, misleading wording, missing context and documents that different users should not see. The assistant should say when evidence is insufficient, show sources for important answers and transfer sensitive or uncertain cases to a person. Record failures and update either the source material, retrieval rules or workflow.
Use a practical launch checklist
Before launch, confirm: one defined use case; approved source owners; role-based access; no unrestricted action permissions; retention and deletion rules; logs for failures and access events; a named incident owner; human escalation; documented supplier responsibilities; and a recurring review date. Expand only after the first scope is reliable.
Internal AI assistants · AI integrations · Business automation · Services and pricing · Contact
Want a website that is fast, measurable and yours?
Book a practical website consultation and we will look at ownership, SEO, analytics and conversion tracking together.