Back to the episode map

Article

How to Use AI With Company Documents Safely

Choose an authoritative source set, control access, require citations, verify passages, and keep accountable decisions outside the assistant.

Aug 4, 20263 min readBy Dalton Anderson

How to Use a Source-Grounded Assistant With Company Documents

Start with a small, authoritative source set and a low-risk question. Control who can access the material, require citations, open the cited passages, and keep consequential decisions with the person or process that already owns them.

1. Define the job

Choose a task such as locating a policy passage, comparing two manuals, preparing a study guide, or summarizing a set of meeting notes.

Do not begin with a vague goal to make the assistant an expert in the company. Name the users, questions, documents, expected output, and decisions that remain outside the tool.

2. Classify the information

Identify confidential, regulated, personal, privileged, licensed, copyrighted, export-controlled, security-sensitive, or contract-restricted material before uploading anything.

Check the organization’s approved tools, data-processing terms, account configuration, retention rules, feedback handling, geographic requirements, and access controls. A consumer account and an enterprise-managed account may not receive the same protections.

3. Build an authoritative source set

Use current documents with clear owners, effective dates, version numbers, and approval states. Remove superseded duplicates or label them so the assistant cannot present an old rule as current.

Record the collection scope. A notebook containing one department’s manual should not answer as if it represents the whole company.

4. Test retrieval before synthesis

Ask questions whose answers are already known. Confirm that the assistant finds the right document and passage, respects the selected source set, and declines when the information is absent.

Test conflicting documents, exceptions, tables, footnotes, scanned files, images, and ambiguous terms. These cases reveal more than a simple happy-path question.

5. Require citations

Make the response point to the supporting passage. Open the citation and read enough surrounding text to understand conditions, definitions, exceptions, and effective dates.

If the tool cannot show its support, treat the response as a lead for further research rather than an answer ready for action.

6. Separate fact, interpretation, and action

Ask the assistant to distinguish what the document says from its own summary or comparison. Do not let a generated interpretation appear as if it were policy text.

Keep the final decision with the role that owns it. An assistant can locate an underwriting guideline without becoming an underwriter. It can surface a compliance passage without giving legal authorization.

7. Record failures

Capture unsupported answers, weak citations, missed documents, version confusion, access problems, and questions the tool should have declined.

Use those failures to improve the source collection, instructions, permissions, and review process. Do not hide them by rewriting the answer manually and calling the test successful.

8. Monitor the source set

Assign an owner for adding, updating, and retiring documents. Re-test important questions when the model, interface, policy, or source collection changes.

If the tool imports copies rather than live references, define how updates will be synchronized. A grounded answer can still be wrong because it is grounded in an old version.

The boundary

This workflow is a general knowledge-management method. It does not replace legal, privacy, security, compliance, records-management, insurance, medical, safety, or other professional review. Use the requirements and accountable authority appropriate to the organization and the decision.

Sources

Follow the evidence.

  1. Gemini 1.5 developer updateblog.google
  2. May 2024 AI Overviews announcementblog.google
  3. Google I/O 2024 announcement indexblog.google
  4. Current Google Search AI feature documentationdevelopers.google.com
  5. NotebookLM June 2024 global updateblog.google
  6. Gemini Notebook privacy and termssupport.google.com
  7. Current Gemini Notebook helpsupport.google.com
  8. NotebookLM December 2023 updateblog.google
  9. Gemini Advanced May 2024 updateblog.google
  10. Gemini API changelogai.google.dev
  11. Gemini Notebook product renameblog.google
  12. SynthID text and video announcementdeepmind.google
  13. Original NotebookLM announcementblog.google
How to Use AI With Company Documents Safely