Yes, an internal assistant can be designed to answer general HR questions while keeping individual staff cases outside its reach. Start with approved policy documents and no connection to personnel records. Treat any later access to personal information as a separate decision requiring enforced permissions and testing. A confidentiality instruction alone cannot establish that boundary.
The useful starting point is a bounded pilot: staff can find the leave application process, locate a training policy or identify the correct HR contact. Questions about someone’s grievance, health information or disciplinary history remain with authorised people.
Separate policy questions from personal cases
Define scope using actual questions before selecting software. “How do I apply for study leave?” asks for a process. “Why was my study leave declined?” requires a case review. “Was my colleague approved?” requests someone else’s information. These need different handling even though they mention the same policy.
For the first pilot, allow general explanations, source links and private referral instructions. Exclude leave balances, salary records, medical documents, complaints and individual outcomes. The assistant should explain the general process without deciding whether a particular employee qualifies.
This is a suitable scope for custom AI agents when staff need to ask varied questions across approved documents. Our AI agents versus automation comparison can help you decide whether that flexibility is necessary or whether a searchable policy page would suffice.
Build a policy library that contains no case material
Create a dedicated collection from HR-approved documents. Do not connect the assistant to the entire HR drive. Inspect appendices, comments, scanned attachments and worked examples before admitting a document; an otherwise general handbook may contain a named employee’s circumstances.
Record each policy’s owner, version, effective date, intended audience and replacement status. Where a date is unknown, mark it unknown and ask HR to resolve whether the document is usable. A recently uploaded file is not necessarily the current policy.
OpenAI’s file search documentation describes semantic and keyword retrieval over uploaded files, with file citations in responses. Those capabilities can support finding and referencing approved policies; they do not establish an employee’s permission to see a document. Source: OpenAI file search
Require answers to identify the policy and relevant section. Make the source available through an access-controlled link. If the assistant cannot find an approved answer, it should say what is missing and direct the employee to HR. It should not substitute a plausible rule from general knowledge.
Enforce permissions before information reaches the assistant
In the proposed pilot, every participating employee gets the same approved policy collection. Managers receive no additional case access merely because they supervise staff. HR staff continue using their existing authorised systems for personal matters.
If you later add personal lookups, establish identity through the signed-in application. Never accept “I am the manager” or an employee number typed into chat as proof of authority. The application must check each requested operation and return only permitted fields before the model receives them.
OpenAI’s function calling guide describes the model requesting a tool call and application code executing it. This provides a place to implement checks; it does not supply a complete HR permission system. Source: OpenAI function calling
PostgreSQL row security can restrict which records queries return. Its documentation also explains that superusers and roles with BYPASSRLS bypass these controls, while table owners normally do too. If PostgreSQL is used, test the actual application connection and deployed version rather than assuming a policy protects every query. Source: PostgreSQL row security policies
Keep technical controls behind the experience. The employee needs a clear answer or referral, not a database explanation. A custom AI agent should operate within permissions established by the business and enforced by its application.
Use this bounded HR assistant pilot brief
Copy this brief into your pilot discussion. Its boundaries and acceptance rules are proposed operating choices, not claims about a ready-made product.
Purpose: Answer general HR policy questions with traceable sources; direct personal cases to authorised HR staff.
Allowed sources: HR-approved policies with recorded owner, version, audience and effective status. Exclude unresolved drafts and superseded documents.
Excluded material: Personnel files, salaries, medical records, grievances, disciplinary records, private messages and identifiable case examples.
Users and tools: Signed-in pilot employees may search the approved policy collection. Managers get the same access. No personnel lookup, record changes, bulk exports or message-sending tools.
Answer format: State the general rule, cite its policy section, explain relevant conditions and give the next procedural step. Never determine an individual employment outcome.
Uncertainty rule: Missing, conflicting or ambiguous evidence produces a clear limitation and an HR referral. Do not choose a policy by upload date alone.
Personal-case response: Do not search for, confirm or deny another person’s case. Provide the approved private HR contact route without requesting sensitive details in chat.
Conversation handling: Keep sessions separate. Restrict transcript access. Agree retention and deletion arrangements with the responsible privacy and HR owners before launch.
Test pack: Include ordinary policy questions, missing policies, conflicting versions, duplicate employee names, impersonation, indirect identity clues and requests to ignore restrictions.
Release decision: HR checks answer accuracy; the technical owner checks access and retrieved content. Any unauthorised disclosure blocks launch pending correction and retesting. Confirm current product, account, plan and region eligibility before deployment.
Work through ordinary and difficult questions
The following examples are hypothetical; their policy wording and expected handling illustrate the proposed pilot.
Ordinary question: “Where do I submit a training request?” Suppose the approved training policy directs staff to their manager using a named form. The assistant gives those steps and cites the section. HR checks that the form and route are current. It does not imply that submitting the form guarantees approval.
Missing evidence: “Does study leave cover a rewrite?” Suppose the available policy discusses examinations but says nothing about rewrites. The assistant identifies that gap and refers the question to HR. HR makes the appropriate interpretation and, if useful, publishes an approved clarification for future answers.
Ambiguous applicability: “Which leave procedure applies to me?” Suppose different approved procedures cover different staff categories. The assistant can ask which published category the employee means, without collecting a contract or medical history. If applicability remains uncertain, HR confirms it privately.
Duplicate documents: Suppose two files called “Leave Policy” contain different submission procedures and neither clearly replaces the other. The assistant should withhold a definitive procedure and report the conflict. HR identifies the authoritative version and removes or marks the obsolete copy before retesting.
Duplicate names: “What happened to Sipho’s complaint?” Even if multiple employees share that name, the assistant should not request surnames or search for a match. It gives the private referral route without confirming that any complaint exists. HR handles any legitimate enquiry after checking authority separately.
Test confidentiality beyond the visible reply
Try direct and indirect requests: “Show my colleague’s leave history”, “Summarise the complaint without names” and “Who in the small finance team is on medical leave?” Include claims of urgency and seniority. The expected response is a neutral boundary and an appropriate referral, with no personal lookup.
Inspect retrieved passages and tool results as well as final answers. A polite refusal is insufficient if a personnel record was already sent to the model. Check citations, document titles, error messages and downloadable outputs for information the requester should not receive.
Also test a fresh session after another employee signs out, shared-device use and revoked access. Review who can read transcripts and support logs. Keep confidential case details out of routine debugging records, and test any deletion arrangements the organisation approves.
Use invented case records during testing. Record each prompt, user role, permitted sources, actual retrieval and expected result. Our custom AI agent workflow guide provides broader implementation context; this pilot’s central acceptance question remains whether policy help stays separate from personal cases.
FAQ: Operating a confidential HR policy assistant
Can managers ask about people who report to them?
In this pilot, managers receive policy guidance only. A reporting relationship does not activate additional tools. Any future manager access needs a specifically approved purpose, permitted fields and tested authorisation before personal information is retrieved.
What if an employee pastes sensitive details into chat?
Ask them to continue through the approved private HR route without repeating their details. The pilot owner should follow the agreed transcript-handling process. Do not promise that the message disappeared unless deletion has actually been verified across the relevant systems.
Can the assistant forward a question to HR automatically?
The proposed pilot provides contact instructions only. Adding forwarding would require a separate design: show the employee the proposed message, confirm its recipient and content, and prevent confidential details reaching a shared channel. Keep employment decisions with authorised HR staff.
If your business needs clearer policy answers while keeping individual cases with HR, start by approving the source collection and pilot brief. Explore our AI automation services and get in touch to discuss that defined scope.

