AI guide
What is RAG in generative AI?
RAG means the model is handed excerpts from your own material before it answers. It is how you stop a chatbot inventing policy. It only works if the right excerpt is found and the person asking is allowed to see it.

The moving parts
Documents are split into passages and indexed. A question is used to retrieve a handful of passages. Those passages are placed in the prompt, and the model is told to answer from them and to say when they are not enough. The index is not the product. The product is the answer a specific person was allowed to receive, with a way back to the source.
Vectors are a common way to search by meaning. Filters on department, date, and document type still do a lot of the work. A RAG system that is “just a vector database” will mix last year’s policy with this year’s.
Where it fails
The right paragraph was never retrieved, so the model fills the gap. Two documents disagree and the model blends them. A scanned PDF was indexed as garbage. A user retrieves a file their colleague should not have shared. None of these are fixed by a more confident prompt. They are fixed by the corpus, the permissions, and a test set of real questions.
Fine-tuning does not replace this. Fine-tuning changes style or behaviour. It does not keep a living policy library up to date. Most companies should spend the first budget on retrieval and evaluation.
A sensible first version
One collection with an owner. Permissions copied from the source. Citations on every answer. A refusal when retrieval is weak. A pilot group and a list of failures. The knowledge assistant sample shows that shape. It is a concept, not a client claim. The RAG development page is how we deliver it.
Retrieval is permissions plus sources
RAG is
- Search over documents you control
- An answer with something the user can open
- A refusal when the source is not there
RAG is not
- The model memorising your company
- A licence to ignore access control
- A guarantee of truth
Questions that define a RAG project
Which files
Current policy is in. Personal drives are a decision.
Which user
The index has to respect the same permissions as the files.
Which update
A replaced document has to leave the answers. Say who checks.
Test the idea against your files
- 01
A current policy
One document the answer should cite.
- 02
A retired policy
One document the answer must not use.
- 03
A role
A person who must not see the first document.
- 04
A refusal
A question with no source, which should not be invented.
Marks this RAG explainer stays precise
- 01
A source is required
The article says an answer should point at a document.
- 02
Missing is an answer
“Not in the files” is described as a valid result.
- 03
Access follows files
Retrieval does not bypass who may open the document.
- 04
Not a chatbot slogan
The piece separates retrieval from a bot that only chats.
Related reading
Questions we hear
Is RAG the same as search?
Search returns documents. RAG returns an answer composed from retrieved passages, and it can still be wrong. Keep the citation so a person can check. For some tasks, ordinary search is the better product.
Can RAG use our CRM as well as files?
Yes, if you treat records as documents with permissions. A customer-facing bot and a staff assistant should not share one unrestricted index.
Does the model store our documents?
Your index stores the passages. Whether a model provider also retains prompts is a contract and configuration question. We do not send material to a service your policy forbids, and we say which service is in the design.



