AI search for policies and procedures, and the day it reads out the payroll file

AI search over your documents is genuinely useful and genuinely dangerous. The difference is whether permissions and versions are enforced where it counts, not bolted on.

Someone asks three colleagues where the current expenses policy lives. Someone else guesses which folder holds the latest version of a procedure and picks wrong. A third can’t remember whether the rule was in an email, a PDF, the staff handbook or somewhere on the shared drive, so they just make a call and hope. That hunt happens dozens of times a week in most offices, and every minute of it is wasted.

A private AI search layer over the documents you already have kills most of that. Ask a plain question, get a plain answer with a link to the source. It’s one of the most useful things AI does for a business, and one of the easiest to build badly, because the same system that answers “what’s our leave policy?” will just as happily answer “what’s the CEO on?” if you point it at the wrong folder.

Why keyword search never worked here

Ordinary search only finds a document when it uses the same words you typed, and policies never cooperate. You ask “can I approve this expense?” and the document that answers you is titled “Delegations of Authority” and never once says the word expense. A technician searches a fault symptom and the manual has it filed under a formal part number nobody says out loud. So people give up and ask a human, which is the whole problem.

AI search closes that gap. It finds the passage that actually answers the question even when the wording is nothing alike, and it gives the answer back in plain English with the source attached. That’s the part worth having. Everything after this is about not shooting yourself in the foot while you build it.

The Tuesday this is meant to fix

Picture an aged care provider on the Darling Downs. A new casual on the evening shift needs to know whether she can give a resident’s daughter an update over the phone. The privacy procedure covers it exactly, but the shared drive holds three files with “privacy” in the name, two of them superseded and one a draft somebody never deleted, and the coordinator who’d know is at dinner. So the casual asks the nurse on shift, who half-remembers the old rule, and the answer that gets given is folklore.

Nothing goes wrong that night. That’s the trap. Multiply the moment across handovers, new starters, contractors and night shifts, and you get a business that paid consultants to document its procedures and runs on memory anyway. Each hunt only costs a couple of minutes, but there are dozens of them a week across a team, so call it a few hours of interrupted work every week, before you price a single decision made off the wrong version.

The fixed version of that Tuesday looks like this. The casual types the question, gets the relevant passage from the current procedure, sees which document it came from and when it was last updated, and reads the source herself before picking up the phone. Thirty seconds, no folklore, and a record showing the current procedure was actually consulted. Everything below is about what it takes to get that version instead of the other one.

Permissions are where this goes badly wrong

This is the failure that ends up in an incident report, so start here. If a staff member can’t open a document the normal way, the AI must not read its contents out to them either. Obvious when you say it. Routinely broken in practice.

It breaks because the easy way to build one of these is to dump every file into one big index and let the assistant answer from all of it. Do that and you’ve built a machine that cheerfully surfaces the payroll file, the disciplinary record, the draft restructure, and the board pack to anyone who asks the right question. The interface might hide a button, but the model behind it has already read everything, and hiding a button is not the same as blocking access.

A serious build enforces the same permissions the person already has on the files themselves, down in the retrieval layer, so the assistant can only ever draw on documents that person is actually allowed to open. That’s not a nice-to-have you add later. It’s the difference between a useful tool and a leak with a friendly chat interface. Ask any vendor selling you internal AI search exactly how permissions are enforced, and if the answer is vague, walk.

There’s a slower version of the same failure that catches even careful teams. Most shared drives carry a decade of permission rot: a folder opened up for a project in 2019 and never closed again, a finance directory the whole office can technically read and nobody ever has. Ordinary search never exposed any of it, because nobody went looking. An assistant that reads everything and answers questions will surface it in the first week. So an AI search project is also a permissions audit, whether you planned one or not. Budget for it up front. Getting the access model straight is part of the build, and it’s exactly the groundwork a private AI deployment either does properly or fails on.

The confidently stale answer

The second way this bites is subtler and slower. An AI assistant will give you a fluent, confident, well-formatted answer pulled from a procedure that was superseded two years ago, and it will sound exactly as sure of itself as it does when it’s right. A confident wrong answer about a safety procedure or a compliance step isn’t a minor annoyance. It’s the kind of thing that ends up in a regulator’s questions.

So before you point AI at anything, do the unglamorous work on the source set. Archive the superseded files so they’re clearly historical. Name documents so a human can tell the current one from last year’s. Decide who owns keeping each collection up to date. And make every answer show which document it came from and when that document was last updated, so a person can sanity-check the source rather than trusting the fluent paragraph. The AI is only ever as current as the pile you feed it.

Feed it the right pile, not every file you own

The strong first collections are the documents people keep asking about and that someone clearly owns: HR policies, safety procedures, operating manuals, finance delegations, IT guides, the customer service playbook, compliance instructions. Bounded sets, clear owners, real demand.

The failure mode is indexing everything the organisation has ever saved, because that’s how you get noise, stale answers and a permissions nightmare all at once. Start narrow, on a collection where you can actually vouch for what’s in it, and grow from there once you trust it.

And keep the source document as the authority. AI search should point a person to the right policy and explain the relevant passage, not become the final word on a decision that carries weight. Staff should be able to open the document and read it for themselves, and on anything high-risk they should. This doesn’t replace policy discipline. It makes the discipline something people can actually follow instead of guess at.

Break it yourself before your staff do

Before any of this goes near the team, spend an hour trying to make it misbehave, and do it from the least privileged account you have, not the admin login the project was built on. Ask it what the CEO earns. Ask about the restructure, or the disciplinary history of a named colleague, or anything else that account has no business reaching. Then ask a question that a superseded procedure answers differently from the current one, and see which answer comes back. Finish with a question the documents don’t cover at all, and watch whether it says so or bluffs.

You’re testing three things at once: does it refuse what it should refuse, does it cite what it should cite, and does it admit what it doesn’t know. Write down every miss. Each one is a permissions fix, a source-set fix, or a reason to delay the launch, and all three are cheaper to deal with now than after a staff member finds the gap for you. Then rerun a slimmer version of the same hour every month or so once it’s live, because document piles drift and permissions rot faster than anyone expects.

While you’re at it, put a number on the upside. Ask five staff what they went hunting for last week and how long the hunt took; that’s your baseline. If the assistant isn’t clearly beating it within the first month, either the source set is wrong or the answers aren’t trusted yet, and both problems show up early when someone’s actually watching.

Built with permissions enforced where it counts and a source set you’ve actually tidied, AI search is one of the quiet wins in business AI. Built by pointing a model at the whole shared drive and hoping, it’s a breach with good manners. If you want the first version and not the second, tell us what your staff keep hunting for and we’ll scope it properly.

All insights

Turn the thinking into a plan.

Send the process, risk or idea. We will help you work out what is worth doing first.