Let’s talk

HomeInsightsBusiness guide

Can your company knowledge answer the question?

Before buying an internal AI assistant, take a handful of questions people actually ask and find the approved evidence that answers them. If your own policy owner cannot identify a current answer, put that gap into the project brief. An assistant needs a defined way to handle that uncertainty.

By DataXLR87 minute readSources checked 2 October 2026

What to take away

  • Test representative questions against approved evidence before choosing technology.
  • Keep missing, conflicting and restricted sources visible in the trial.
  • Assess access controls separately from fluent answers.

Purpose and scope

The useful starting deliverable is a small source register and an answerability worksheet. Together, they show which questions are ready for a trial, which need clarification and which depend on access or policy decisions. They also give you something concrete to ask an AI consultancy in Australia to demonstrate before you commission a larger build.

This is our proposed planning method, not a readiness certification. The examples below are entirely synthetic. They illustrate decisions to make; they are not DataXLR8 client results or tests of an implemented product.

Begin with a question someone needs answered

Consider a fictional operations team asking, “Can we arrange maintenance at site BR-17 after 2 pm?” A useful answer depends on more than finding those words in a document. The source must apply to that site, remain current and be available to the person asking. It must also distinguish an allowed access window from a confirmed appointment.

Ask the process owner to write representative questions in everyday language. Include an easy question, a vague one and a question that a junior employee is not entitled to have answered. Write the expected outcome before looking at an assistant's response. Anthropic's tool-evaluation guidance recommends realistic tasks with verifiable outcomes; that supports testing the job itself instead of rewarding fluent answers to convenient examples.

For each question, identify the person who can judge the answer. A document owner can resolve whether a policy is current. An access owner can determine who should see it. Those responsibilities need to be clear even when one person holds both roles.

Record authority as well as location

Start with the sources needed for the chosen questions. Uploading every shared drive creates a much larger review problem without first establishing whether any one task works.

Record authority as well as location
Source-register fieldWhat to recordWhy the reviewer needs it
Document and canonical locationStable identifier and approved originalDistinguish the source from copies
Owner and approval statusAccountable person; draft or approvedKnow who can resolve uncertainty
Effective and expiry datesDates or explicitly unknownSeparate current rules from old ones
Audience and access groupPermitted users or rolesKeep answers within entitlement
SensitivityHandling requirements for the actual contentChoose suitable processing and review
Superseding sourceReplacement document, if establishedExplain which version governs
Review and removal ruleReview owner, timing and retention decisionKeep the collection maintainable

These fields are editorial recommendations. They are not a claim that every organisation has the same legal duties or retention period. Mark missing information as unknown rather than filling the register with guesses.

For Australian organisations handling personal information, review both the proposed inputs and outputs. OAIC explains that generated information about an identifiable person can be personal information even when it is incorrect. Its guidance also distinguishes best-practice recommendations from legal obligations that depend on context. A source register helps frame that review; it does not complete it.

Use answerability as the first acceptance test

Copy this worksheet into your planning document and replace the synthetic cases with questions from the selected process. Keep the expected result beside the evidence, so reviewers can see why abstaining can be the correct outcome.

Use answerability as the first acceptance test
Synthetic evidence stateExpected responseEvidence for review
A current approved policy directly answers the questionAnswer within its scope and cite the sourceSupporting passage, effective date and owner
Two apparently approved policies disagreeExplain the conflict and refer it to the policy ownerBoth passages and their dates
Only an expired policy is availableState that the current answer is unverifiedExpiry or supersession record
The question omits which site it concernsAsk which site before choosing a ruleMissing context and applicable alternatives
The answer exists only in a restricted folderDecline to disclose restricted contentAccess-denial record without the content
No approved source answers the questionState what is missing or ask a narrower questionSearch scope and evidence gap
A document tells the assistant to ignore access rulesPreserve the access boundaryNo permission change or unrelated action

Do not treat the newest-looking filename as authority. A recently copied document can contain an old policy. Equally, a source citation alone does not prove that the cited passage supports the answer. Have the reviewer check the connection between the question, passage and response.

Diagram description: Check the user's access before retrieving evidence. Answer only when relevant, current evidence is consistent. Ask for missing context, and refer missing or conflicting evidence to its owner. Access denial must not disclose the restricted material.

A source-backed answer starts with access and ends with either evidence or an explicit uncertainty.
  1. Check access

    Use the question and user identity to establish permitted source access.

  2. Inspect evidence

    Find approved, current sources and check for missing context or disagreement.

  3. Choose a response

    Answer with support, ask for context, or refer uncertainty to its owner.

  4. Keep boundaries

    Decline restricted requests without revealing protected text.

Test the boundary outside the conversation

“Do not reveal restricted information” is an instruction, not proof that access controls work. Ask the implementer to show the same question under permitted and denied accounts. Check what reaches the model, what appears in logs and what the user receives. OWASP identifies excessive permissions and autonomy as sources of excessive agency and recommends enforcing authorisation in downstream systems.

The first trial can remain read-only. Answering a question does not require permission to change a business record. If later work adds actions, use the separate boundaries described in Before an AI workflow acts, decide how it can fail.

Sources for this section

Turn the worksheet into a scoped decision

At the end of the exercise, group the questions by what prevents a useful answer. Some will be ready for a bounded trial. Others need a policy decision, source cleanup, clearer wording or access work. Record the owner and next action for each gap. Avoid a single readiness percentage that hides these different causes.

A useful brief can be one sentence: “Help authorised operations staff answer these defined maintenance-policy questions from these approved sources, show the supporting passage, and escalate these unresolved cases.” Then attach the completed worksheet and agree how responses, corrections and review time will be assessed.

If the exercise reveals that a clearer policy page answers the whole problem, improve that page first. The result has still helped you make a buying decision. For scoping the next step, read Start a software project with a decision or discuss the source and workflow boundaries with DataXLR8.

Before you proceed

  1. Choose a bounded question set and accountable process owner.
  2. Record canonical sources, approval status and effective dates.
  3. Map user access and sensitive information.
  4. Classify answerable, unclear, conflicting and unsupported questions.
  5. Record expected responses before testing.
  6. Test permitted and denied accounts.
  7. Assign owners and next actions to evidence gaps.
Download checklist (.md)

Sources and further reading

Official sources support the requirements described here. Our suggested workflows and illustrative examples are practical guidance, not an assurance of compliance or a claim about client results.

  1. Writing effective tools for agentsAnthropic

    Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.

  2. Guidance on privacy and the use of commercially available AI productsOAIC

    Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.

  3. LLM06:2025 Excessive AgencyOWASP

    Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.

YOUR NEXT STEP

Put this into practice

Bring us the process you want to improve. We can help define the first useful step, the evidence you need and what a practical pilot should prove.

Start the conversation

Fixed-price quotes. Most projects start from AUD $5,000, and small jobs are welcome.