Private AI
Private AI for administration: start with one testable workflow
Select an administrative process, prepare documents and permissions, and evaluate an AI assistant before connecting it to operational systems.
AI (Artificial Intelligence) can help staff find procedures, summarise documents, and prepare administrative drafts. Start with one repetitive task and clear source data. A pilot should demonstrate quality and practical value before wider deployment.
Choose work with verifiable outputs
Proposed workflow illustration, not a customer project result: a staff member searches for purchasing procedures, AI retrieves permitted documents, and drafts an answer with references. For invoices, AI can prepare draft fields while staff check amounts and suppliers before saving. This supports preparation without removing approval responsibilities.
How does AI use company documents?
RAG (Retrieval-Augmented Generation) retrieves relevant source information to help a model compose answers. IBM describes using external knowledge without retraining the model. Document references support verification, but do not guarantee correct answers.
Technical source: IBM: retrieval-augmented generation
A documented deployment example
NVIDIA publishes a RAG Blueprint walkthrough using self-hosted models. This is an inspectable technical example, not a claim of a Manciti deployment or a mandatory package. Technology and capacity choices follow requirements and pilot measurements.
Technical source: NVIDIA: self-hosted RAG deployment example
What does private deployment mean?
Define privacy across the entire data path, not just the model. Map documents, OCR (Optical Character Recognition), search embeddings, models, logs, and backups. If information must stay within the company network, every processing component must respect that boundary. Private cloud and on-site servers have different operating requirements.
- Approved sample documents, languages, formats, scan quality, and source-update ownership.
- User groups and document permissions; integration accounts receive only necessary access.
- Concurrent users, response-time targets, server location, networking, and operations ownership.
Design integration and approval from the outset
OWASP documents prompt injection, including malicious instructions in retrieved documents. Controls include separating external content, limiting privileges, and human approval for high-risk actions. Manciti’s proposed design enforces permissions and data validation in application code, rather than relying only on model instructions.
Technical source: OWASP: prompt injection
Evaluate the pilot before a full rollout
Use approved test questions and documents. Measure answer accuracy, reference relevance, permission enforcement, staff task time, and operating costs. Test missing information: the system should state its limitations rather than invent an answer.
Handover scope can include connected sources, access configuration, evaluation results, training, monitoring, and update/recovery procedures. Agree support and subsequent development in the quotation.
Questions before buying
- Do we need to buy a GPU?
- Not necessarily. A GPU (Graphics Processing Unit) and server capacity depend on model selection, document volume, speed targets, and simultaneous users. Size infrastructure after discovery and benchmarking.
- Can AI change operational records directly?
- Only after permissions and approval workflows are agreed and integration is tested. Start a pilot with search and drafts without write access.
- What determines the price?
- Workflows and data sources, document quality, model/infrastructure choices, integration, evaluation, and support. Manciti scopes discovery, pilot, and deployment separately.
