A private knowledge layer with citations

Year:

2026

Service:

Ready-made Solutions

Industry:

Professional Services

Team:

3 specialists, 7 weeks

Reference scenario: an Edinburgh professional services firm deploys the Sovereign Knowledge Core in a private tenancy it controls. Answers cite their sources, respect matter-level permissions and are measured on a 400-question evaluation set.

Introduction

The firm in this scenario is based in Edinburgh and advises asset managers and pension schemes on legal and regulatory matters. Twenty years of advice notes, precedents and fund documentation sit in its document management system, protected by matter-level permissions and ethical walls. Finding the relevant prior advice takes an associate hours, and the partners have banned public chat tools after a client draft was pasted into one.

The firm wants what those tools promise without what they risk: answers grounded in its own documents, with citations, visible only to people entitled to see the sources, on infrastructure it controls. Keter AI deploys the Sovereign Knowledge Core, our accelerator for a private retrieval and knowledge layer, and adapts it to the firm's permission model in seven weeks.

Challenge

Retrieval technology is available off the shelf. The hard parts are access rights and proof of quality.

  • Permissions are the product. An answer that draws on a document behind an ethical wall is a professional breach, not a bug. Access has to be enforced at query time, for every passage.

  • Client terms restrict processing. Several engagement letters limit where client material may be processed and by whom. External model APIs are ruled out for this content.

  • Quality argued by anecdote. Earlier trials ended in arguments between enthusiasts and sceptics, because nobody had a set of real questions with agreed answers. Published vendor accuracy figures do not transfer between document collections.

  • Stale and duplicated content. Superseded advice sits next to current advice with nothing to tell them apart.

  • No statute to lean on. The UK has no AI-specific law. The firm's duties come from UK GDPR, professional confidentiality and client contracts, so the controls must be its own.

Solution

The order of work is deliberate: access rights first, then proof of quality, then the model.

Permissions first. Nothing is indexed without an access rule. The index mirrors the document system's permissions and ethical walls, and every retrieved passage is checked against the user's rights at query time.

An evaluation set before launch. The firm's knowledge lawyers write 400 real questions with reference answers and source passages. A held-out part is never used for tuning. Every change to retrieval, prompts or model is scored against it.

Private serving. An open-weight model runs on infrastructure the firm controls, in a private UK-hosted tenancy. No client content leaves it.

What is deployed:

  • Permission-aware connectors to the document management system, exposed to the agent through MCP with scoped access.

  • Hybrid retrieval - lexical and vector search with a reranker, plus metadata for matter, date and superseded status.

  • Agent loop that plans multi-step lookups, quotes the passages it relies on and declines to answer when no source supports one.

  • Citation and grounding checks on every answer before it is shown.

  • Model serving - Mistral Small 4, released under Apache 2.0, served with vLLM; the model can be replaced without changing the rest.

  • Tracing and evaluation in MLflow, with feedback capture from users.

  • Review screen where knowledge lawyers mark content as current, superseded or restricted.

A content owner role is created inside the firm, because quality after launch depends on the documents as much as on the model.

Result

These are the pilot acceptance criteria and targets set in the scenario, not audited outcomes.

  • Citations - target: at least 95 percent of answers carry a valid citation to a source the user can open.

  • Permissions - acceptance criterion: zero answers in the access test suite draw on a document outside the user's rights. One failure blocks release.

  • Answer quality - target: knowledge lawyers rate at least 85 percent of held-out answers as correct and complete; the threshold is reviewed after the pilot.

  • Refusals - acceptance criterion: a question with no supporting source gets a clear "not found", not a guess.

At the end the firm owns the deployment, the index, the evaluation set and the runbooks, and its own team operates them. There is no per-seat dependency on a model vendor, and the model can be swapped as better open-weight options appear. The evaluation set stays valuable whatever the firm runs next.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.