Every UAE enterprise IT organisation we work with has been asked the same question by their leadership: 'why can't we have ChatGPT for our documents?' The answer is that a generic chatbot pointed at enterprise content is a liability. It hallucinates confidently. It ignores access controls. It cites nothing. It creates audit trails no compliance team will sign off.
The instinct is to buy a productised assistant and hope. The instinct is wrong. What is missing is not the model — it is the retrieval discipline, the permission-aware architecture, the evaluation harness, and the ownership of source content. B2 builds an assistant that retrieves before it answers, cites what it retrieved, respects who can see what, and is measured against your actual questions — not vendor benchmarks.
Six streams,
ending in cited answers.
Source onboarding and metadata design front-load in weeks 1–3. RAG build and evaluation overlap through weeks 4–9. Permission enforcement, dashboards, and handover close weeks 10–12.
Source onboarding
Document sources catalogued and prioritised. Ingestion paths agreed for each. Refresh cadences defined per source (real-time / scheduled / manual). Ownership assigned per source.
Metadata & permission model
Metadata schema designed for retrieval quality (source type, effective date, sensitivity, department). Permission model mapped from source-system ACLs to retrieval-time filters.
RAG implementation
Chunking strategy tested against actual corpus. Embedding model selected. Vector store deployed. Retrieval pipeline built with permission enforcement at query time — not at generation.
Evaluation harness
Gold-standard test set curated with business owner. Automated evaluation of helpfulness, citation quality, unsupported-answer rate. Threshold gates for deployment.
Ingestion & refresh workflows
Automated pipelines for each source type. KnowledgeOps ownership handed to the business owner's team. Content-quality reporting instrumented.
Handover
Structured knowledge-transfer sessions (4–6 typically). Runbooks for the three most likely failure modes. 30/60/90-day post-handover check-ins.
Twelve weeks maximum.
Eight minimum. Four phases.
Phase count is fixed. Duration flexes with corpus size and permission complexity. Milestones are signed gates — not aspirations.
Assistants scored,
not on vendor slideware.
Every RAG platform choice runs a six-criteria scorecard in weeks 1–2. Each criterion scored 1–5 with documented evidence. Signed by the business owner before Phase 2 begins.
From generic search
to cited retrieval.
A typical UAE enterprise arrives with fragmented document search across SharePoint, network shares, and departmental portals — most returning outdated or unattributed results. The engagement consolidates to a permission-aware retrieval pipeline plus a single conversational surface.
Reference pattern. Some engagements retain a specialised search index for structured content (product catalogues, part numbers) alongside the RAG pipeline. What always consolidates is the answer surface. Never the underlying document sources.
A government knowledge
hub, measured.
Representative pattern for a UAE government or semi-government entity of this scale — 4,500 staff, ~120k policy and procedural documents across seven departments. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.
Five artifacts,
each with signed acceptance.
Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.
RAG Assistant MVP
Working assistant deployed to the pilot department. Teams/portal integration. Cited responses. Permission enforcement live.
Ingestion & Refresh Workflows
Automated pipelines per source type. Refresh cadences per source. Content-quality reporting instrumented.
Evaluation Report
Gold-standard test-set results at each phase gate. Helpfulness, citation quality, unsupported-answer rate. Threshold-gate evidence for go-live.
RBAC & Audit Logs
Permission model implemented. Retrieval-time audit log spec. Evidence pack for compliance sign-off.
Ops Readiness Pack
Runbooks for the three most likely failure modes. Monitoring dashboards. KnowledgeOps ownership document. 30/60/90-day check-in schedule. The document your team runs the assistant from.
Six outcome metrics,
measured pre and post.
Success is not “the assistant is deployed.” It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at steady state.
Honest scoping.
B2 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.
If content is inconsistent, out of date, or ownerless, we surface that in discovery. Bad content produces bad citations regardless of platform.
Signs off metadata model, evaluation gates, ingestion cadences. 30% time commitment.
If ACLs are inconsistent, we scope the pilot to a well-permissioned corpus rather than extending timeline for remediation.
For personal data, DPIA scoped. For regulated sectors, evidence expectations agreed with compliance before Phase 2.
Teams, portal, or standalone. Deep custom UI is a separate engagement scoped alongside.
Bad documents don't get better with retrieval. Start with a content-quality remediation programme or A6 Data Trust Sprint™.
That's B14 Agentic Workflow Agent Build™ — agent that executes with approval gates, not assistant that answers.
For ticket-deflection-first framing, B7 Service Desk AI Assist Build™ is a better fit.
Eight weeks is our minimum. We can accelerate discovery into A6 Data Trust Sprint™ to produce the corpus-readiness report within 3 weeks, then B2 begins with Phase 2.
Fixed fee.
Milestone-based.
Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.
Five, most asked.
Q_01Does RAG actually reduce hallucinations, or does it just move the problem?
It moves the problem — and that move is the point. A generative model with no retrieval hallucinates from parametric memory. A retrieval-grounded model can still misinterpret retrieved passages, but the failure mode shifts from 'confidently wrong invention' to 'wrong summary of a source you can inspect.' Citations make wrong answers auditable.
B2 pairs this with an evaluation harness that measures unsupported-answer rate — the metric that actually matters — and threshold gates that block deployment until it is below your tolerance.
Q_02How do you handle documents that some users shouldn't see?
Q_03Which LLM do you use?
Q_04How do you keep the knowledge current?
Q_05Can this integrate with Teams, SharePoint, our intranet?
One name
on the engagement letter.
A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.
Practice Lead — AI
Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.
Including scope amendments.
Signs off all 5 deliverables.
With executive sponsor.
Authorised to negotiate.
CEO within 24 hours.
30/60/90-day check-ins.
Prior. Peer. Next.
Data Trust Sprint™
3-week diagnostic of document estate readiness. Sensible if source content quality is unknown before committing to B2.
Service Desk AI Assist Build™
Peer build for organisations where the knowledge assistant target audience is service-desk agents and the KPI is ticket deflection.
CoE-as-a-Service™
Managed AI CoE. Scales knowledge-assistant governance and additional agent deployments across the enterprise.
Thirty minutes.
No slide deck.
A structured 30-minute scope conversation with the Practice Lead. You describe the current document estate, access-control complexity, and organisational pressure. We describe whether B2 is the right engagement — and if not, what is.
