TOOKLI

An assistant that respects who is allowed to see what

Enterprise knowledge systems where retrieval inherits your existing permissions — because an assistant that leaks a salary review is worse than no assistant.

The problem

The demo works. Then someone asks a question they should not be able to ask.

Internal knowledge assistants are easy to prototype and hard to deploy, because the prototype indexes everything with a service account. The moment real employees use it, the index becomes a way to read documents the person was never granted.

Our approach

Permissions travel with the document, all the way to the answer

We carry the source system's access control into the index itself, filter retrieval by the signed-in user's entitlements before anything reaches the model, and cite every claim back to a document the user can actually open. If they cannot open it, it cannot be retrieved.

What we build

Capabilities

  • Enterprise Knowledge Assistants

    Question answering over internal documentation, scoped to each employee's access.

  • RAG Systems

    Retrieval-augmented generation with citations, evaluation and a measured baseline.

  • Document Intelligence

    Extraction and classification across contracts, policies and operational documents.

  • Internal AI Search

    Semantic search across systems that each have their own, worse search.

  • AI Knowledge Bases

    Curated, versioned content designed to be retrieved rather than merely stored.

  • AI-powered Reporting

    Narrative summaries generated from governed data, with the figures traceable.

  • AI Copilots

    Role-specific assistants embedded in the tools a team already has open.

Architecture

How it fits together

Secure retrieval architecture

The secure retrieval layer is the load-bearing component. It filters by entitlement before the model sees anything — the model itself is never a security boundary.

  1. 01Company documentsWith their source ACLs
  2. 02SharePoint
  3. 03Policies
  4. 04Database
  5. 05Knowledge base
  6. 06Secure retrieval layerFilters by the user's entitlements
  7. 07AI assistantAnswers only from what was returned
  8. 08EmployeeSees citations they can open

The ingestion pipeline

Permissions are captured at ingestion and re-checked at query time, because entitlements change after a document is indexed.

  1. 01Document ingestionSource ACLs captured with the content
  2. 02ChunkingStructure-aware, not fixed-size
  3. 03Embeddings
  4. 04Vector searchFiltered by entitlement
  5. 05RetrievalRe-ranked, permission re-checked
  6. 06Context constructionBudgeted, deduplicated
  7. 07LLM generation
  8. 08CitationEvery claim linked to a source
  9. 09Access controlEnforced again on the citation link
  10. 10EvaluationAnswer quality and retrieval recall
  11. 11MonitoringUsage, cost, refusals, drift
Integrations

Systems we build against

Platforms and services TOOKLI actively works with on client engagements.

Content sources

  • SharePoint
  • Microsoft 365
  • Teams
  • Confluence-style wikis
  • File shares

Retrieval

  • pgvector
  • PostgreSQL
  • Azure AI Search

Models

  • Azure OpenAI
  • OpenAI
  • Anthropic

Identity

  • Microsoft Entra ID
  • SAML
  • OIDC

This list reflects systems we integrate with, not partnerships, resale agreements or certifications. If something you rely on is missing, ask — we will tell you honestly whether we have used it.

Use cases

What this looks like in practice

Examples of what we can build for each sector. Work we have actually delivered appears in our case studies, with named outcomes.

  • Professional services

    Answering policy and process questions

    The questions that currently interrupt a senior colleague several times a day.

  • Construction

    Finding the clause in the specification

    Search across drawings, specifications and change orders, with the source cited.

  • Healthcare

    Administrative document assistance

    Summarising and locating administrative material. Not clinical decision support.

  • Finance

    Internal reporting and policy retrieval

    Internal-facing only, with every generated figure traceable to a governed source.

How we work

Delivery process

  1. 01

    Inventory the sources

    What exists, who owns it, how current it is, and who is allowed to read it.

  2. 02

    Model the permissions

    The hardest part, done first. If entitlements cannot be resolved, nothing else matters.

  3. 03

    Build the ingestion pipeline

    Chunking, embedding and ACL capture, re-runnable and incremental.

  4. 04

    Establish an evaluation set

    Real questions with accepted answers, including ones the system should refuse.

  5. 05

    Build retrieval and generation

    Filtered search, re-ranking, context budgeting, mandatory citation.

  6. 06

    Pilot with one department

    Narrow scope, real users, measured. Expand only after the numbers hold.

  7. 07

    Monitor and re-index

    Content changes, permissions change, models change. The pipeline is a running system.

Security and reliability

How we keep it safe and accountable

Engineering practices, not certifications. TOOKLI holds no security certifications and does not claim any.

  • Permissions are preserved end to end

    Source ACLs are captured at ingestion and enforced at query time. A user cannot retrieve what they cannot already open — no exceptions, and no reliance on the prompt.

  • Citations, always

    Every answer links to its sources. An uncited answer is treated as a failure, because an employee cannot verify what they cannot trace.

  • Refusal is a correct answer

    When retrieval returns nothing relevant, the system says so. Confidently wrong is the expensive failure mode in an enterprise setting, and we measure it separately.

  • No confidential content leaves without a decision

    Which content is sent to which provider is an explicit, documented choice. Where data residency requires it, we deploy against models hosted in your own tenancy.

  • Auditability

    Who asked what, what was retrieved and what was returned — logged and reviewable, which is usually a condition of approval from security and legal.

Common questions

Related services

  • AI Agents & Intelligent Automation

    Agents and automated workflows that connect your data, applications and processes — built with human approval, permission controls and monitoring from the first design.

    Learn more
  • AI Integration

    Bring AI capabilities into your existing applications — search, extraction, classification, summarisation and assistants — without building or training models yourself.

    Learn more
  • AI, Data & Business Intelligence

    AI-assisted dashboards, natural-language analytics, automated reporting and data quality automation, built on a semantic layer people already trust.

    Learn more

Have an internal knowledge problem?

The first conversation is about permissions and sources, not about models. That is usually where the project is won or lost.

Scope a knowledge system