Define who the agent is for
“Employees” is often too broad. A new starter, frontline operator, manager, and IT administrator may have different permissions and need different answers. Define the audience before collecting content.
Separate knowledge by sensitivity
- Shared guidancePolicies, procedures, definitions, and resources appropriate for the whole audience.
- Role-specific knowledgeInstructions that apply only to a team, location, or responsibility.
- Private recordsPersonal, customer, financial, health, security, or case data that does not belong in a general knowledge agent.
- CredentialsPasswords, access codes, secret keys, and recovery information that must never be added.
Keep the source authoritative
The agent should point back to the maintained policy or procedure where appropriate. When the source changes, update the authoritative copy and then update or re-index the agent. Do not let a generated answer become an unofficial competing policy.
Design escalation by subject
HR interpretation, security incidents, safety exceptions, system access, customer commitments, and approvals each need an explicit owner and channel. “Ask someone” is not a usable handoff.
Review questions as process evidence
A repeated knowledge gap can mean the source is missing, the terminology is unclear, or the process itself is inconsistent. Fix the operating knowledge, not just the generated response.