SME note · operations
Internal copilots that earn their keep
An internal copilot is not “ChatGPT with your logo”. It is a flow: a staff question, a set of sources the company controls, an answer you can check, and a person who answers when the system does not know.
We see two failure modes in SMEs. One: a generic account where everyone pastes anything, including customer lists. Two: a “corporate assistant” that talks about everything and cites nothing. Both die at the third hallucination.
The design that survives is narrower and more honest. Here is how we set it up.
What problem it solves (and which it does not)
It solves internal search: hours, policy, catalogue, how a return works, what the agreement says. It saves the walking encyclopedia and cuts contradictory answers.
It does not solve an unwritten process. If nobody knows how a credit note works, the copilot will invent one. It does not replace the person who signs a quote. If you sell it as an oracle, the team will use it as an oracle — that is a delayed incident.
Minimum design you can operate
- Named sources. A closed corpus: manual, FAQ, prices, procedures. If it is not in the corpus, the system says “I do not have that” and offers a human.
- Visible citation. Every answer points at a document. No citation, no publish to the team.
- Human queue. New or sensitive questions go to a person. The copilot does not invent policy.
- Perimeter. No ID numbers, health, salaries, credentials or live contracts in the prompt.
- Kill switch. Someone can turn it off on a Friday without calling the vendor.
What a good first month looks like
Week 1: pick one domain (store floor questions, for example) and gather twenty real documents, not the marketing manual. Week 2: the copilot answers in an internal channel, with citations, and a champion reviews 100%. Week 3: you measure accept / rewrite / discard. Week 4: you cut sources that hallucinate and add the questions that actually arrive.
If at day 30 the metric is “40 questions were asked” with no quality, you have a toy. The metric that matters is accepted answers and hours the team stops losing to search.
Limits worth writing on the wall
The copilot does not sign. It does not change prices. It does not talk to the end customer until the internal version has a month of numbers. It is not trained on the manager’s personal mail. It is not wired to the ERP “just in case” in month one.
That poster prevents the classic accident: someone pastes a payroll sheet “to summarise”. A 30-minute perimeter briefing beats another week of fine-tuning.
Tool after design
Once the flow is written, the tool is a boring decision: data residency, whether it trains on your inputs, unit price, and whether you can switch it off. Not the other way around.
Sensitive data: private path or a clear processor contract. Internal public FAQ: an API model may be enough. Sensitivity leads, not the model brand.
Training and programme fit
A copilot without champions is an icon nobody opens. Train on your real questions, not the vendor demo. Two people with protected time are enough for month one.
Under Kit Consulting this is advisory and training. Under Kit Digital it can live inside management or the site if the deliverable is operable. We ask for the corpus and the owner, not “we want our own ChatGPT”.
Corpus: what goes in and what stays out
In: what the team can already show a new colleague — shop manual, non-confidential prices, returns policy, hours, how to request a day off. Out: live negotiations, salaries, people incidents, a customer document with a non-disclosure clause.
A corpus of 20–40 well-named documents beats 4,000 files in a Drive. The model does not “find” the truth in chaos; it cites the chaos. Spend an afternoon on titles and dates. That dirty work is what makes the copilot useful.
Review the corpus on day 14: which source produced a hallucination, which was never used, which is missing (the question that arrived five times). The corpus is a habit, not a one-off upload.
Frequently asked questions
Can it serve website customers from day one?
No. Internal first, with citations and a queue. Visitors do not forgive a vague answer; a colleague can correct it.
Do we need to train a model on our PDFs?
Almost never. Retrieve-and-cite on a closed corpus is enough and easier to switch off and audit.
What if it gets a price wrong?
That is why it cites and does not publish prices missing from the source. If the source is wrong, you fix the source, not the model.
Next: training the team still uses and minimum viable security. To size it, tell us the corpus and question volume.
Studio in Barcelona. Part of Clutch Developer. Oriented to Spain’s SME digitalisation programmes. Request an assessment.