RAG Systems

Approved sources · Control · Escalation Swiss SMEs

Your company knowledge. Securely accessible and traceable.

Employees should receive authoritative answers from approved sources — not from a general language model.

RAG is not a chatbot showcase. First we clarify whether controlled access is the right lever at all.

Sources
Only approved company information
Retrieval
Relevant passages before the answer
Control
Refusal when the source is missing
Escalation
A person reviews sensitive cases

BUSINESS PROBLEM

Knowledge is scattered. Answers take too long.

When teams search PDFs, folders, CRM and ERP, they lose time, duplicate work and risk giving customers inconsistent answers. A general chatbot does not solve this because it does not know which company information is approved.

Authoritative answers

Only approved sources may form the basis.

Less search time

Answers to recurring questions should be easy to find without copying information between tools.

Clear responsibility

If the source is missing, the system escalates instead of guessing.

FIT

When RAG helps — and when it does not

RAG is often useful

  • Many authoritative documents that come up regularly
  • Answers must be grounded in approved sources and constrained by access rules
  • Roles decide who may see which knowledge

A simpler solution may be better

  • A few stable FAQs or a clear process handbook
  • Rare one-off cases without a recurring pattern
  • Decisions that always need a person for legal or financial reasons

FLOW

From source to a controlled answer

The flow stays deliberately simple. Technology follows the required protection level, not the other way around.

Approved sources

Only content you have explicitly released.

Retrieval

The system finds the relevant passages for the question.

Controlled answer

The answer stays bound to the retrieved context.

Source evidence

It is clear where the statement comes from — or the system refuses.

CONTROL

Roles, refusal and human escalation

Roles and access

Public, internal and sensitive knowledge are considered separately.

Refusal

If a suitable source is missing, the system says it does not know the answer.

Escalation

Sensitive or unclear cases go to a responsible person.

Data minimisation

Only necessary information is processed or stored.

QUALITY ASSURANCE

A plausible answer is not enough.

A RAG system is useful only when it retrieves relevant knowledge, keeps claims grounded in approved sources, respects access rules, and refuses or escalates when confidence is insufficient.

Retrieval quality

Does the system find the relevant, approved passages for the question?

Source grounding

Can the answer’s claims be supported by the retrieved context?

Access and boundaries

Do roles, permissions, refusal behaviour and human escalation work as intended?

Operations and security

Are data flows, sensitive information, prompt-injection risks, logging and deletion handled transparently?

Automated metrics provide signals, not a final quality verdict. Critical cases are checked against subject-matter-approved reference questions and reviewed by people.

DATA FLOW

Documented decisions instead of a blanket assurance

Swiss hosting or on-premise

Both are conditional architecture choices based on the required protection level — not a default promise.

Documented data flow

Which sources, which processing, which provider: named before work starts.

No-training only after review

Only where the provider and agreement support it. No blanket no-training guarantee.

nDSG-aware

We work with privacy in mind. This is not legal advice.

WHAT YOU RECEIVE

What the introductory call clarifies

Suitability and scope are clarified in the introductory call.

Initial assessment

Whether RAG, a simpler structure or visibility work first makes more sense.

Data-flow note

Which sources may be used and where processing happens.

Evaluation approach

Test questions, refusal rules and the escalation path.

Next step

Only if the usefulness justifies the control effort.

FAQ

Definition and limits

What is a RAG system?

RAG first retrieves approved company information and then forms an answer. That makes answers more traceable and easier to constrain. AI output remains probabilistic and needs human review for important decisions.

When is RAG useful?

When employees repeatedly search documents, folders, CRM or ERP for authoritative answers, and those answers must be grounded in approved sources and constrained by access rules.

When is a simpler solution better?

When the knowledge base is small, questions are infrequent, or the answers already exist in a clear FAQ, intranet or process handbook. In those cases, better structure is often enough — without a retrieval system.

What happens if the system does not know the answer?

It should refuse or say “I do not know” and escalate to a responsible person. The system must not guess in unclear or sensitive cases.

Does all data stay in Switzerland automatically?

No. Swiss hosting or on-premise are architecture choices based on the required protection level. Data flows are documented. This is not a residency or compliance guarantee.

Does this automatically mean no-training?

No. No-training language applies only where the selected provider and agreement actually support it. We review that before use and do not invent a blanket assurance.

What do we receive from the introductory call?

An initial assessment of whether RAG is suitable, which sources can be used and which data flows must be documented first. Suitability and scope are clarified in the introductory call.

NEXT STEP

An introductory call or a RAG suitability discussion

We clarify whether a controlled knowledge system is the right next step.