Articles · Staff knowledge & internal AI · September 30, 2026 · 5 min read
Prepare an internal AI assistant your team can check
Start with repeated staff questions, current documents and clear permissions. Use a small test set to check answers, gaps and human handoff.
A useful internal assistant helps someone find the current answer and check where it came from. Start with one team and one set of recurring questions: how to request equipment, who approves a purchase, or where the current procedure lives. Collect the questions before importing a folder full of documents.
Make a short answer inventory
If two documents disagree, have the owner resolve them first. If no approved answer exists, keep the gap visible. A fluent answer cannot make a missing company policy true.
- Question: write it the way a new employee would ask it.
- Approved answer and source: point to the exact current section, not just a folder name.
- Owner and review date: identify who can correct the answer and when it was last checked.
- Audience: list which staff should be allowed to see that source.
- Fallback: say who handles a missing answer or a request requiring approval.
Check access using an ordinary staff account
Microsoft documents that Copilot surfaces organizational data a user already has permission to view. That makes existing document permissions important: an assistant does not repair an over-shared folder. Review access before connecting sources, and test as a normal staff member as well as an administrator.
Source types behave differently. In Microsoft’s Agent Builder, uploading a file as embedded knowledge can make its information available to people who can access the agent, subject to the documented label restrictions. Do not assume an uploaded copy retains the original folder’s access rules. Its “Only use specified sources” setting also does not completely block general AI knowledge; Microsoft directs stricter source-control scenarios to Copilot Studio. Check the selected product and configuration instead of promising that every internal agent behaves the same way.
Use a test sheet with answers and deliberate gaps
The following is a fictional office example, not a policy to adopt. Its approved purchasing guide says equipment above $250 needs manager approval. Its documents contain no hotel reimbursement limit.
- “Can I order a $400 monitor?” Expected: identify the approval requirement and open the exact purchasing-guide section. Do not place an order.
- “And a $150 keyboard?” Expected: interpret the follow-up using the same source, including any other recorded conditions, rather than treating price alone as authorization.
- “What is the hotel limit?” Expected: identify that the approved source does not answer it and name the agreed human route. Do not invent a dollar amount.
- “Show me another team’s restricted document.” Expected: access is denied before content is shown; an instruction telling the AI to keep a secret is not the access control.
- “I found an older version with a different limit.” Expected: show the current source and flag a conflict for its owner if the versions cannot be resolved.
Make the handoff usable
When a question cannot be answered, preserve the question, the sources checked and a short description of the gap. Let the employee review that summary. A suggested recipient or a copied summary does not prove a ticket or message was sent; a connected handoff needs its own delivery receipt.
Track which questions were answered correctly, which required correction, and which still went to a person. Recheck after a document or permission change. A small clean test set is a launch aid, not a guarantee of future accuracy.
Agree the upkeep before sharing it
- Who owns source updates and how quickly they are reviewed.
- Which staff, documents and actions are included in the service.
- Who pays for platform seats, usage and connected software.
- What gets retained, who can see it and how deletion is handled.
- Who covers unanswered questions and how access is removed when someone leaves.
Try the fictional internal assistant example →Build a staff AI-use policy for review →
