18. Keep enterprise AI search fresh and private
Handle document changes, ACL revocation and deletion across a retrieval pipeline.
The brief
Design an internal question-answering product over enterprise documents. Focus on the lifecycle from ingestion to a cited answer, especially when permission or source content changes. Explain a useful degraded response when freshness or authorization cannot be established.
- Ten million documents change at up to 200 updates/second; the product serves 400 questions/second.
- Permissions exist at both workspace and document level. A user can lose access while a retrieval or generation request is running.
- Documents may contain instructions aimed at the assistant. Answers must distinguish source evidence from model assumptions.
Constraints
- Content freshness target≤ 300 seconds
- Declare the p95 delay from an accepted source update to retrieval reflecting it under normal operation.
- Access revocation target≤ 60 seconds
- Declare the maximum intended stale-access window and specify where authorization is rechecked.
- Deletion lifecycle
- Track removal across source cache, chunk store, embeddings and answer caches; describe backup retention separately.
- Grounding and untrusted documents
- Source text cannot override system instructions or authorization; unsupported answers need an explicit abstention or uncertainty path.
What to cover
- 01
Data and query paths
Show ingestion, versioned chunks/indexes, retrieval, authorization checks and cited answer assembly.
- 02
Change and deletion protocol
Trace an ACL revoke and a deleted document during an in-flight question; explain cache invalidation and reconciliation.
- 03
Quality and security evaluation
Define test slices, relevance/grounding/leakage measures, a baseline and launch thresholds.
- 04
Latency, cost and failure budget
Size ingest/query load, estimate per-answer cost assumptions and choose a degraded behavior when dependencies fail.
Worked designs
No worked design has been published for this brief yet. You can start an attempt and share your approach in the discussion.
Review rubric
AI feedback uses these criteria. Scores are practice feedback.
Version and authorization lifecycle
Explains enforcement, race handling, stale indexes/caches and deletion propagation with bounded claims.
Grounding and evaluation
Measures retrieval, citation correctness and permission leakage on meaningful slices; treats document instructions as data.
Capacity and degraded behavior
Calculations and operating policies support the stated freshness/cost/latency goals.
Alternatives and assumptions
Makes retrieval/model choices conditional on evidence and explains a viable alternative.
Discussion
Share an approach, ask a question, or tag @Coach.
Loading discussion…