Navigation

Get in touch
Logo
News

AI assistants & RAG

AI answers need reliable sources.

Employees look for answers in manuals, tickets and internal documents. We build assistants that find matching content, show sources and respect the access rights of your systems. Actions in business systems are planned and approved separately from pure knowledge search.

a black keyboard with a blue button on it — illustrative image
Assistant with source references · Planning and implementation by OTOKO®

Your brief for OTOKO®

What we take care of for you.

With retrieval-augmented generation, or RAG for short, document sections that match the question are retrieved and provided to the language model as context. We take care of extraction, meaningful sections, metadata and updates. Outdated or deleted content must be removed from the search index. The selection is tested using real questions: does the search find the right passage, and can the answer be supported by it? A source reference alone does not prove that an answer is correct; that requires an assessment of the content.

The possible scope of services

  • Model selection by protection needs: hyperscaler service, EU provider or open-source model in your own data center
  • Connection of SharePoint, Confluence, ticket systems, file shares and business applications
  • Permissions of the source systems are enforced inside the assistant
  • Document processing: classification, extraction, summarization with review steps
  • Evaluation procedure for answer quality, hallucinations and data leakage

We define the specific scope, your involvement and the acceptance criteria before the start.

Technology explained clearly

How we carry out the task.

01

Permissions also apply to search and tools

The assistant should only find content that the requesting user is allowed to read. This check is enforced technically, outside the free-text model response, and takes changed group permissions into account. Documents that are found are treated as data, not as instructions. If the assistant is to create tickets or change records, we limit the permitted tools, target systems and parameters. Steps with significant consequences require human approval. Logging is designed according to protection needs; confidential questions and answers do not always have to be stored in full.

02

Testing answer quality with a fixed question catalog

The test catalog contains answerable questions, missing information, conflicting sources and prohibited access attempts. We measure groundedness, helpful refusal, response time and cost per case. Model or index changes go through the same comparison. An initial pilot works with a limited knowledge base and named users. Further sources and, where applicable, write functions are added only after that.

Meeting room at the OTOKO® Cologne office

A verifiable result

What you keep working with.

  1. Assistant with source references
  2. Permission and data protection concept
  3. Evaluation procedure with test question catalog

The handover brings together implementation and documentation. Together, we review the agreed cases and record any remaining tasks.

Your project in detail

An assistant must know which sources it is allowed to use.

We develop AI assistants for specific knowledge and work processes. This includes document preparation, search, permissions, answer validation and integration into your existing user interfaces.

Make knowledge findable without dissolving access boundaries

RAG connects search across approved content with the formulation of an answer. We plan how documents are ingested, meaningfully split into sections and tagged with source, date and permissions. Removed or changed documents must also be updated in the search index; a one-time import is not enough for living corporate knowledge.

We check search quality with realistic questions and the sources we expect to be found. Technical terms, abbreviations and poorly structured documents can prevent the right passage from being found. We therefore distinguish a search error from an incorrectly formulated answer and improve the affected stage specifically.

Separate answers, actions and human approvals

A knowledge assistant can explain sources without making changes in business systems itself. If the assistant is also meant to perform actions, every connection is given limited rights and clearly defined parameters. Critical operations such as orders or master data changes may need separate confirmation; imported documents must not override these rules.

Before release, we test unauthorized questions, conflicting sources and attempts to redirect the assistant through document content. Logging is aligned with troubleshooting and protection needs. Reports on answer quality, latency and usage cost help steer operations without unnecessarily storing confidential requests long term.

Illustrative project scenario

How the service helps in everyday use.

Example: Employees search for internal work instructions. The assistant finds approved versions, links the sections used and points out where supporting sources are missing. Personnel records of other teams remain excluded. Only after a separate project can the assistant additionally trigger approved tasks in a business system.

This example explains a possible process and is not a customer reference.

Before the first step

Your questions about AI assistants & RAG.

Does RAG fully prevent incorrect answers?

No. Search and generation can make mistakes. Displaying sources, suitable tests and a clear approach to missing evidence reduce the risk; important decisions require expert review.

Do our documents have to reach an external model provider?

Not necessarily. We compare hosted services and operation in your own environment in terms of data flows, performance, cost and responsibilities. The specific architecture is agreed before implementation.

Your project

Which task would you like to solve?

Describe your situation and the desired result. The selected service will be included in the contact request.

Request this service

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.