Case study
How we turned fragmented insurance knowledge into a secure AI assistant
Building a permission-aware knowledge platform that helped office and field teams find reliable answers across policies, procedures, and internal documents.
- Insurance
- AI Enablement & Intelligent Automation
- Knowledge management
- RAG
- Knowledge source integration
- Permission-aware retrieval
- AI-assisted question answering
- Human-in-the-loop quality control
- Client
- Knowledge Compass
- Industry / Domain
- Insurance
- LLI role
- AI solution strategy, architecture, and product development
- Scope
- Data and infrastructure assessment, knowledge ingestion, access-control design, RAG architecture, answer traceability, quality-control workflows, and source integrations
Overview
Insurance teams often depend on a large body of policies, procedures, forms, and regulatory documents. The information exists, but finding the right clause at the moment it is needed can require searching through multiple systems and reading dozens of pages.
LLInformatics designed and developed a centralised, permission-aware knowledge assistant for an insurance organisation. The platform brings distributed sources into a governed retrieval layer and allows employees to ask questions in natural language. Each response is grounded in the organisation's documents and supported with citations and source excerpts.
The result is a more direct path from a business question to the relevant organisational knowledge, without weakening the access controls required for sensitive information.
The problem
The client's knowledge was spread across policies, regulations, forms, shared drives, and other internal sources. This created several connected challenges:
- Employees had to search large and complex documents for individual policy details.
- Field teams needed answers while handling cases away from the office.
- Repetitive questions placed additional pressure on subject-matter experts.
- Different roles required access to different categories of information.
- Documents could become inconsistent or outdated as policies changed.
- Knowledge risked leaving the organisation when experienced employees moved on.
- Existing data and document structures were not immediately ready for reliable AI use.
For example, when assessing a claim after a flooded property, a field employee might need one precise condition from a long insurance policy. The information could be available, but reaching it quickly and confidently was the real operational problem.
Our approach
We treated data readiness and governance as the foundation of the solution, not as follow-up work.
- 01
Assess the existing data environment
We examined how information was structured, where it was stored, and which inconsistencies, duplicates, and dependencies could affect retrieval quality.
- 02
Create a governed source model
We designed a tiered access system so that every source could be connected to an appropriate permission level. Personal material could remain visible only to its owner.
- 03
Ground answers in organisational evidence
We used a retrieval-augmented generation approach so that answers were produced from approved sources rather than from the language model alone.
- 04
Keep experts in the quality loop
We created a workflow in which users could flag an unhelpful answer, assign it to a subject-matter expert, and use the corrected response to improve future results.
- 05
Design for different deployment constraints
The architecture allowed the language-model layer to be selected according to data sensitivity, infrastructure requirements, and operating cost. This supported both commercial API models and privately deployed models.
The solution
We delivered a centralised knowledge platform with separate user and administrative workspaces.
Core capabilities
Multi-source knowledge ingestion
The platform can process PDFs, documents, presentations, Markdown, CSV, HTML, URLs, and selected Google Drive folders. Further integrations can be added for systems such as Slack and Notion.
Permission-aware retrieval
Sources are assigned to access tiers. A retrieval gateway filters the available context before an answer is generated, preventing users from retrieving content outside their permission level.
Evidence-backed answers
Users receive natural-language answers together with citations, source documents, and the relevant supporting excerpts.
Conflicting-source detection
When two documents contain contradictory information, the system can expose the conflict instead of presenting an unsupported answer as certain. This helps users identify outdated policies and decide when additional verification is required.
Change-aware knowledge
The platform periodically checks connected sources for updates, refreshes the index, and can alert users when a document related to an earlier question has changed.
Human-in-the-loop answer review
Users can flag incorrect or unhelpful responses. Administrators can route them to subject-matter experts, assign ownership, monitor resolution against an SLA, and incorporate corrected knowledge into later answers.
Operational oversight
The administrative workspace provides ingestion status, indexing and embedding monitoring, retry controls, logs, alerts, answer-quality signals, latency information, agent versioning, and dry runs before configuration changes are published.
Personal knowledge context
Employees can add private notes or files that enrich their own answers without exposing those sources to other users.
Technology stack
Relational database
Governed source metadata
Stores source metadata, access tiers, and the relationships required to govern retrieval.
Vector database and embeddings
Semantic retrieval
Support semantic retrieval across the connected knowledge base.
Retrieval-augmented generation
Organisational context
Provides relevant organisational context to the language model for each question.
Access-control gateway
Permission tiers
Limits retrievable content according to the user's permission tier before it reaches the answer-generation layer.
Document parsing and text recognition
Format coverage
Extract knowledge from different file formats and scanned materials.
Configurable language-model layer
Model flexibility
Supports commercial models through an API or a privately deployed model when sensitive data or token economics require greater control.
Source integrations
Connectors
Google Drive is supported, with additional connectors such as Slack and Notion available according to the client's environment.
Why this architecture?
The architecture separates knowledge storage, permissions, retrieval, and answer generation. This makes it possible to change the selected model or add new source systems without removing the governance controls around the client's data.
It also addresses a critical limitation of generic AI assistants: an answer is not useful in a regulated environment unless users can see where it came from and the system can restrict which evidence they are allowed to retrieve.
Results and impact
For employees
- A faster route to specific information in long policies and internal documents
- Access to organisational knowledge from both office and field workflows
- Evidence attached directly to answers for easier verification
- Visibility into conflicting or potentially outdated source material
For subject-matter experts
- Fewer repetitive information requests
- A structured queue for answers requiring human review
- Ownership and SLA tracking for unresolved questions
- A feedback mechanism for improving answer quality over time
For the organisation
- Reduced dependence on knowledge held by individual employees
- Governed access to information across roles and departments
- A reusable foundation for connecting further knowledge sources
- Flexibility to choose a model and deployment pattern appropriate to sensitive data
- Greater traceability than a general-purpose conversational AI tool
Why this case matters
Introducing AI into a knowledge-heavy organisation is not primarily a chatbot project. The difficult work lies in understanding the data, resolving structural problems, enforcing access rules, and creating a process for handling uncertainty when documents disagree.
This case demonstrates LLInformatics' ability to:
- Assess whether organisational data is ready for AI
- Turn fragmented documents into a governed retrieval environment
- Design AI workflows around existing roles and permissions
- Combine automated answers with human accountability
- Support sensitive and regulated information without relying on a single model provider
- Build a platform that can evolve with new sources, integrations, and business requirements
Value delivered: Fragmented insurance knowledge became a governed, evidence-backed assistant that gave employees a more direct way to find answers while preserving access control and expert oversight.
More case studies
Start the conversation
Build the right technology with the right engineering partner.
Tell us what you are planning, and our senior team will help you define the strongest way forward.
Talk to our team