Production ready

Knowledge Agent · AI-enabled knowledge

Company knowledge for everyone, from approved documents only.

A single source of truth for strategy, policies, OKRs and guides. It answers questions and only answers questions: no action, no write, no exception. If leadership has not published it, the agent does not say it. If leadership retires it, the agent stops citing it on the next question.

What it answers, and where it stops, stated plainly

  • Answers from the published corpus: strategy, policies, OKRs, project overviews and onboarding guides. Every answer names the document and links to the original so the reader can verify it
  • Answers only from what leadership has approved. A document becomes answerable through the publishing pipeline, and one retire command removes it from answers on the very next question
  • No actions, ever. The agent sends no email, files nothing, changes no record and starts no process. Its only output is an answer with its sources
  • It cannot read outside the knowledge library. Confidential libraries return access-denied to the agent’s own identity, at the platform layer rather than by prompt
  • No document, no answer. It says the topic is not published yet and names the team that owns it, instead of filling the gap from general knowledge
  • Document stores beyond Microsoft 365 and SharePoint: an extended capability adapted per engagement, on the same publishing gates and the same audit trail
Knowledge Agent
What is our remote work policy?
Published policy: up to 2 remote days per week with line-manager approval, and core hours from 10:00 to 15:00 for meetings.
Approved source ✓Remote-Work-Policy_v2

Was this answer helpful?

👍👎
What are the company objectives this quarter?
Four objectives are published for the quarter, each with a named owner and its measures. This is the approved version, so it is the version everybody is answered from.
Approved source ✓Company-Objectives-2026-Q3

Was this answer helpful?

👍👎
What discount can we give enterprise clients?
That topic is not on the knowledge hub yet, so I cannot answer it. Pricing guidance is owned by the Sales team. Documents appear here only after leadership approval.
Not published · referredMiss logged

Thanks. What was wrong with it? (optional)

Sales published the pricing guide last week, this should be findable now.
Send

✅ Thanks, this is recorded and will be reviewed.

What this AI agent does for your whole company

One source of truth, always cited

Strategy, policies, OKRs, project overviews and onboarding guides, answered with the document name and a link to the original, so the reader can always verify.

A leadership-approved corpus

A document reaches employees only through a publishing pipeline with a recorded approval per document. Naming checks, content scans and a staging area run before a single byte becomes public.

Cannot read what it must not

The agent’s credentials are scoped at the platform layer to the knowledge library alone. In verification, 12 of 12 out-of-scope access attempts were denied, including direct addressing of confidential libraries.

Unpublish is instant

One retire command and the agent stops citing the document on the very next question. There is no stale index copy that keeps answering after a document is withdrawn.

Bilingual search that fits your language

Full-text search built at publish time, with accent-folding tuned for Vietnamese. Ask in English or Vietnamese and find documents written in either.

Honest when it does not know

No document, no answer. The agent says the topic is not published yet and names the owning team, and every retrieval miss is visible to operations so the next publish fills the gap.

From draft to answerable, with a paper trail

Publishing is the pipeline, not a checkbox. Each stage is automated, and each stage can refuse.

Author

The owning team writes the document in its own workspace, in Word, markdown or PDF.

Approve

Leadership posts a recorded approval. The approval link is a mandatory field: no link, no publish.

Gate

Naming rules, a full-page scan for pay, credentials and account numbers, and a staging area invisible to the agent.

Publish

The file lands in the taxonomy under a named human identity, with checksum and audit entry. The search index updates in the same command.

Answer or retire

The agent can cite the document within minutes. One retire command removes it from answers immediately.

Access model: every employee in your company group gets the full published corpus, because everything in it was approved for all staff. Guests and external accounts get a polite refusal, and one guest in a group chat means the agent declines for the whole chat.

Under the hood

The publishing pipeline and the agent are separated by design: the agent can never write, and publishing always happens under a named human identity. Readers rate every answer as well, so a missing or stale document surfaces as a counted signal instead of a silent gap.

  • 535 automated tests, plus a 28-case adversarial compliance evaluation and a 12-case platform isolation check, re-run quarterly
  • Every answer rated by its reader: thumbs-down votes and their optional notes, together with the logged retrieval misses, rank which document the company should publish or fix next
  • Read-only forever: the agent’s identity holds no write permission of any kind, and no long-lived publishing secret exists anywhere
  • Search without a crawler: the full-text index is built by the publish command itself, so new documents are findable in minutes, at zero extra infrastructure
  • Stale index cannot leak: every search candidate is re-checked against its live location before use, so retired documents drop out by construction
  • Deterministic citation check: a fabricated file name is worse than a refusal, so sources are verified in code, not by the model
  • Architecture pinned by tests: the build fails if anyone reintroduces the platform search endpoint that leaked cross-site metadata

Read the full XNOR Agents security model

Publish path · named human identity A person runs the publish on their own credential, never the agent’s Six gates must pass naming rules, content scan, staging area Library write the file, its checksum and one audit row The agent holds no write permission one way Answer path · agent, read-only Question in chat asked in English or Vietnamese Index built at publish time no crawler, findable in minutes Live location re-check retired documents drop out here Citation check in code a source it did not retrieve is rejected

The agent and the publisher are two different identities. Only approved documents cross between the two paths, and only in one direction.

Common questions

What keeps confidential files out of the answers?

The strongest control sits at the platform layer: the agent’s credentials are granted access to the knowledge library alone, so confidential libraries return access-denied to the agent itself. Verification attacked this from 12 angles, including addressing confidential storage directly by its internal id, and all 12 were denied.

Can this agent take actions the way the CFO and HRM agents do?

No, and that is a design decision rather than a roadmap gap. This agent is read-only by construction: its identity holds no write permission of any kind, so there is nothing to gate, nothing to approve and nothing that can be sent by mistake. Publishing and retiring documents are operator commands run under a named human identity on a separate credential the agent never holds. If you want an action automated on top of company knowledge, it belongs in a function agent with its own approval flow, not here.

How fast can a new document become answerable?

Minutes. The index is written by the publish command, not by a crawler, so recency and folder questions pick the document up immediately and keyword search within about five minutes.

What happens when someone asks about an unpublished topic?

The agent says the topic is not on the knowledge hub yet, explains that documents appear only after leadership approval, and names the team that owns the topic. The miss is logged, so operations can see which documents people actually need next.

Do we need a vector database for this?

No, and that is deliberate. Retrieval combines full-text ranking over a purpose-built index with folder and recency logic, all filtered by a deterministic allowlist. It is transparent, cheap to run, and retire-safe: nothing keeps answering from a stale copy.

How do you measure whether the answers are any good?

Every answer carries a thumbs up or down, recorded on the same audit row as the sources it cited, and a thumbs down opens an optional note of up to 300 characters. For a knowledge base this doubles as a content radar: votes and notes, combined with the logged retrieval misses, rank which documents people actually need published or updated next, so the corpus improves in the order readers feel the gaps.

Next step

Give every employee the same trusted answer.

Book a 30-minute demo: publishing, answering, refusing and retiring, live in production.

We sketch your knowledge taxonomy and publishing flow in the same call.