Case study

How we turned fragmented insurance knowledge into a secure AI assistant

Building a permission-aware knowledge platform that helped office and field teams find reliable answers across policies, procedures, and internal documents.

  • Insurance
  • AI Enablement & Intelligent Automation
  • Knowledge management
  • RAG
  • Knowledge source integration
  • Permission-aware retrieval
  • AI-assisted question answering
  • Human-in-the-loop quality control
Client
Knowledge Compass
Industry / Domain
Insurance
LLI role
AI solution strategy, architecture, and product development
Scope
Data and infrastructure assessment, knowledge ingestion, access-control design, RAG architecture, answer traceability, quality-control workflows, and source integrations

Overview

Insurance teams often depend on a large body of policies, procedures, forms, and regulatory documents. The information exists, but finding the right clause at the moment it is needed can require searching through multiple systems and reading dozens of pages.

LLInformatics designed and developed a centralised, permission-aware knowledge assistant for an insurance organisation. The platform brings distributed sources into a governed retrieval layer and allows employees to ask questions in natural language. Each response is grounded in the organisation's documents and supported with citations and source excerpts.

The result is a more direct path from a business question to the relevant organisational knowledge, without weakening the access controls required for sensitive information.

The problem

The client's knowledge was spread across policies, regulations, forms, shared drives, and other internal sources. This created several connected challenges:

  • Employees had to search large and complex documents for individual policy details.
  • Field teams needed answers while handling cases away from the office.
  • Repetitive questions placed additional pressure on subject-matter experts.
  • Different roles required access to different categories of information.
  • Documents could become inconsistent or outdated as policies changed.
  • Knowledge risked leaving the organisation when experienced employees moved on.
  • Existing data and document structures were not immediately ready for reliable AI use.

For example, when assessing a claim after a flooded property, a field employee might need one precise condition from a long insurance policy. The information could be available, but reaching it quickly and confidently was the real operational problem.

Our approach

We treated data readiness and governance as the foundation of the solution, not as follow-up work.

  1. 01

    Assess the existing data environment

    We examined how information was structured, where it was stored, and which inconsistencies, duplicates, and dependencies could affect retrieval quality.

  2. 02

    Create a governed source model

    We designed a tiered access system so that every source could be connected to an appropriate permission level. Personal material could remain visible only to its owner.

  3. 03

    Ground answers in organisational evidence

    We used a retrieval-augmented generation approach so that answers were produced from approved sources rather than from the language model alone.

  4. 04

    Keep experts in the quality loop

    We created a workflow in which users could flag an unhelpful answer, assign it to a subject-matter expert, and use the corrected response to improve future results.

  5. 05

    Design for different deployment constraints

    The architecture allowed the language-model layer to be selected according to data sensitivity, infrastructure requirements, and operating cost. This supported both commercial API models and privately deployed models.

The solution

We delivered a centralised knowledge platform with separate user and administrative workspaces.

Core capabilities

  • Multi-source knowledge ingestion

    The platform can process PDFs, documents, presentations, Markdown, CSV, HTML, URLs, and selected Google Drive folders. Further integrations can be added for systems such as Slack and Notion.

  • Permission-aware retrieval

    Sources are assigned to access tiers. A retrieval gateway filters the available context before an answer is generated, preventing users from retrieving content outside their permission level.

  • Evidence-backed answers

    Users receive natural-language answers together with citations, source documents, and the relevant supporting excerpts.

  • Conflicting-source detection

    When two documents contain contradictory information, the system can expose the conflict instead of presenting an unsupported answer as certain. This helps users identify outdated policies and decide when additional verification is required.

  • Change-aware knowledge

    The platform periodically checks connected sources for updates, refreshes the index, and can alert users when a document related to an earlier question has changed.

  • Human-in-the-loop answer review

    Users can flag incorrect or unhelpful responses. Administrators can route them to subject-matter experts, assign ownership, monitor resolution against an SLA, and incorporate corrected knowledge into later answers.

  • Operational oversight

    The administrative workspace provides ingestion status, indexing and embedding monitoring, retry controls, logs, alerts, answer-quality signals, latency information, agent versioning, and dry runs before configuration changes are published.

  • Personal knowledge context

    Employees can add private notes or files that enrich their own answers without exposing those sources to other users.

Technology stack

  • Relational database

    Governed source metadata

    Stores source metadata, access tiers, and the relationships required to govern retrieval.

  • Vector database and embeddings

    Semantic retrieval

    Support semantic retrieval across the connected knowledge base.

  • Retrieval-augmented generation

    Organisational context

    Provides relevant organisational context to the language model for each question.

  • Access-control gateway

    Permission tiers

    Limits retrievable content according to the user's permission tier before it reaches the answer-generation layer.

  • Document parsing and text recognition

    Format coverage

    Extract knowledge from different file formats and scanned materials.

  • Configurable language-model layer

    Model flexibility

    Supports commercial models through an API or a privately deployed model when sensitive data or token economics require greater control.

  • Source integrations

    Connectors

    Google Drive is supported, with additional connectors such as Slack and Notion available according to the client's environment.

Why this architecture?

The architecture separates knowledge storage, permissions, retrieval, and answer generation. This makes it possible to change the selected model or add new source systems without removing the governance controls around the client's data.

It also addresses a critical limitation of generic AI assistants: an answer is not useful in a regulated environment unless users can see where it came from and the system can restrict which evidence they are allowed to retrieve.

Results and impact

For employees

  • A faster route to specific information in long policies and internal documents
  • Access to organisational knowledge from both office and field workflows
  • Evidence attached directly to answers for easier verification
  • Visibility into conflicting or potentially outdated source material

For subject-matter experts

  • Fewer repetitive information requests
  • A structured queue for answers requiring human review
  • Ownership and SLA tracking for unresolved questions
  • A feedback mechanism for improving answer quality over time

For the organisation

  • Reduced dependence on knowledge held by individual employees
  • Governed access to information across roles and departments
  • A reusable foundation for connecting further knowledge sources
  • Flexibility to choose a model and deployment pattern appropriate to sensitive data
  • Greater traceability than a general-purpose conversational AI tool

Why this case matters

Introducing AI into a knowledge-heavy organisation is not primarily a chatbot project. The difficult work lies in understanding the data, resolving structural problems, enforcing access rules, and creating a process for handling uncertainty when documents disagree.

This case demonstrates LLInformatics' ability to:

  • Assess whether organisational data is ready for AI
  • Turn fragmented documents into a governed retrieval environment
  • Design AI workflows around existing roles and permissions
  • Combine automated answers with human accountability
  • Support sensitive and regulated information without relying on a single model provider
  • Build a platform that can evolve with new sources, integrations, and business requirements

Value delivered: Fragmented insurance knowledge became a governed, evidence-backed assistant that gave employees a more direct way to find answers while preserving access control and expert oversight.

More case studies

Start the conversation

Build the right technology with the right engineering partner.

Tell us what you are planning, and our senior team will help you define the strongest way forward.

Talk to our team