How to Build an Internal AI FAQ and Help Desk Before Rolling Out Generative AI Across Your Organization

Column
How to Build an Internal AI FAQ and Help Desk  Before Rolling Out Generative AI Across Your Organization

Introduction

A practical guide to the internal FAQ, enquiry desk, first-line triage and escalation design worth putting in place before rolling generative AI out across the company. Aimed at IT, DX, HR, legal and security teams.

Tatsuya Ito

Tatsuya Ito

Artificial Intelligence Consultant

company-icon

Third Scope Ltd.

Born in 1985 and originally from Mie Prefecture, Japan. In 2012, he joined an AR startup in Hong Kong as an engineer. Since then, he has been involved in new business development and AI service launches at several AI startups. In 2018, he founded the current ThirdScope Inc. by taking over an AI service and its development team. He now supports companies in adopting and utilizing AI, with a focus on AI-driven business development, operational transformation, and product development. He has also been involved in AI research as a Project Researcher at the University of Tokyo. Today, he continues to work at the forefront of AI project development, providing practical consulting from both technical and business perspectives.

Before you roll out generative AI across the whole company, the first thing to settle is not simply “which AI shall we use”.

Take Sato (a pseudonym) in IT, for example. From the day after the rollout briefing, questions started landing on his desk from sales, HR, legal and security:

“Am I allowed to enter customer information?” “Can I use it for externally facing documents?” “Who do I ask when an error comes up?”

Previously, a handful of people explained the rules for AI use by word of mouth and dealt with each query as it arrived. These days, however, designing your internal FAQ, your enquiry desk, your first-line triage and your escalation routes before rollout has become an essential part of preparing for company-wide adoption.

In this article we set out, for support-desk, IT and DX teams as well as the HR, legal and security departments that field these enquiries, the FAQ items and intake arrangements worth putting in place before you go live. The aim is straightforward: rather than have people start using the tool while quietly carrying their worries, you want them to know where to turn when in doubt, and you want the responsible departments judging by the same yardstick. That said, building an FAQ and a desk will not, on its own, make every concern vanish. The sensible course is to grow a support setup that suits your organisation by combining it with operating rules, training and regular review.

Generative AI adoption calls for “enquiry design”

Generative-AI adoption calls for “enquiry design”

Once generative AI is available to everyone, questions are bound to follow — and they are rarely confined to how the buttons work.

Many of them require judgement that spans several departments: which information may be entered, who is accountable for checking the output, whether something may be used externally, and whom to notify when things go wrong.

Handle each of these individually and your response quickly becomes dependent on particular people. The practical answer is to decide, in advance, where the first enquiry should go and who makes the call behind the scenes.

If you happen to be using a tool that lets you carve up access by project and permission, it pays to settle “which task it is for” and “who checks it” before you get drawn in by how convenient the features are; operation tends to be steadier for it. Kanata’s operation manual explains that AI chat, AI summarisation and e-learning can all be handled within a single business-support platform, and that users, data and apps can be organised on a per-project basis.

  • email drafts
  • meeting-minute summaries
  • first drafts of internal materials
  • brainstorming
  • proofreading text

When you bring generative AI into the organisation, designing “where do I ask when I’m unsure” matters every bit as much as “which tool we adopt”. The AI Business Operators’ Guidelines touches on the scope of AI use, appropriate and inappropriate ways of using it, the provision of information about capabilities and limitations, the documentation of relevant information, and the securing of AI literacy. An internal FAQ and enquiry desk are, in effect, the practical mechanism for translating that thinking into day-to-day operation. For an authoritative English-language framework, see the NIST AI Risk Management Framework.

The basic items your internal FAQ should cover

The basic items your internal FAQ should cover

An internal FAQ is not merely a collection of questions. It is the shared rulebook that keeps judgements on the ground consistent.

There is no need to produce a flawless FAQ from the outset. Even so, sorting out at least the following items before generative AI use begins makes it considerably easier to keep enquiry-related confusion in check.

The range of tasks AI may be used for

The first thing you need is a clear view of “which tasks generative AI may be used for”.

Example classification of tasks for generative AI use
Category Details
Tasks well suited to AI Draft emails, summaries of minutes, first drafts of internal materials, idea generation, proofreading text
Tasks to be used with conditions Customer-facing proposals, first-pass checks of contracts, summaries of internal regulations, drafting recruitment communications
Tasks to avoid Personal data, sensitive information, undisclosed financial information, final decisions involving legal judgement, settling personnel evaluations

The key here is to separate “work that may be entrusted to AI” from “judgements for which a person takes responsibility”. Generative AI lends itself readily to drafting, summarising, marshalling the points at issue and producing comparison tables, while fact-checking, final decisions and external accountability remain firmly with people.

If you are using a tool such as Kanata that lets you carve up access by project and permission, it pays to settle “which task it is for” and “who checks it” before you get drawn in by how convenient the features are; operation tends to be steadier for it. Kanata’s operation manual explains that AI chat, AI summarisation and e-learning can all be handled within a single business-support platform, and that users, data and apps can be organised on a per-project basis.

Information you may and may not enter

A particularly common question from the front line concerns the data being entered.

“May I let the AI read this document?”
“Is it all right to include a customer’s name?”
“Can I tidy up an employee’s appraisal comments with AI?”

Field these questions one by one every time and your enquiry handling soon comes to rest on particular individuals. In the FAQ, set out how each type of information is to be treated.

By way of illustration, a classification along these lines:

Example classification of information entered into generative AI
Type of information Treatment
Public information May be entered
General internal materials May be entered within a managed internal environment with access controls
Customer information Judge after checking contracts, NDAs and internal rules
Personal data As a rule, do not enter. Where necessary, apply masking or confirm the purpose of use
Sensitive information Best treated as prohibited from entry
Undisclosed financial, M&A or personnel-reassignment information Best prohibited from entry, or made subject to mandatory approval by a specialist department

The Personal Information Protection Commission’s advisory emphasises that, when using generative-AI services, the proper handling of personal data and due regard for privacy are important. Your internal FAQ likewise needs to spell out the conditions for entering personal data, the information that must not be entered, and the method of masking. For authoritative English-language guidance on handling personal data in AI, see the UK ICO guidance on AI and data protection.

Rules for checking AI output

Because generative AI replies in natural, fluent prose, the output can look ready to use as it stands. It may, however, contain mistaken information, out-of-date information, or wording at odds with internal rules.

It is worth building checking rules of the following sort into the FAQ:

  • Any text going outside the company must be checked by a person
  • Figures, dates, proper nouns and quotations are to be reconciled against the original source
  • Anything touching contracts, the law, employment matters or security is to be confirmed with the specialist department
  • Do not treat an AI’s answer as the final decision
  • Do not justify something by saying “the AI produced it, so it must be right”

When AI is used in the course of work, it is important to be in a position to verify that the output is sound.NIST’s risk-management document for generative AI sets out a framework to help an organisation understand and manage the risks that come with using generative AI.

Who to contact when something goes wrong

Roll generative AI out across the whole company and operational hiccups will arise as well.

Enquiries of this kind, for instance:

  • Can’t log in
  • Lacks permission, so the feature in question isn’t shown
  • Can’t upload a file
  • No answer comes back from the AI
  • The answer differs from what was expected
  • Accidentally entered confidential information

Treat all of these the same way and your response will lag. In the FAQ, set out separate contacts for each type of trouble.

In particular, where confidential or personal data has been entered by mistake, you need to spell out a route — distinct from ordinary how-to enquiries — for reporting it straight away to the information-security team or a line manager.

The enquiry desk: one way in, with judgement routed separately

The enquiry desk: one way in, with judgement routed separately

The important thing when designing a generative-AI enquiry desk is to keep the way in and the place where judgement happens separate.

From a user’s point of view, working out “should I ask IT, legal, or DX about this?” is genuinely hard. For that reason, make the first point of entry as single a channel as you can.

Behind the scenes, on the other hand, classify how things are handled.

Examples of generative-AI enquiry content and escalation routes
Enquiry content First-line response Escalation route
Login, permissions, screen display Support desk / IT IT administrator
Whether information may be entered First-line desk Security
External submission of customer documents First-line desk Department concerned / legal / PR
Contracts, copyright, terms of use First-line desk Legal
Personnel evaluation / employment information First-line desk HR
Suspected mis-entry or data leak First-line desk Security / line manager
Use for externally submitted materials First-line desk Department concerned / legal / PR

With a single way in, people on the ground can ask without hesitation. By splitting up where the judgement is made behind the scenes, the specialist departments only have to look at the cases that genuinely need them.

There are several ways to take in enquiries — a form, chat, email, a ticketing tool. Whichever you use, what matters is keeping a record of the enquiry, who handled it, the date of the reply and the grounds for the judgement, in a form you can check afterwards.

Information to confirm during first-line triage

Information to confirm during first-line triage

It also steadies your handling to decide, in advance, what the person taking an enquiry should check first.

On an enquiry form or chat desk, it is worth asking for the following items:

  • Department
  • The AI tool or feature being used
  • What they were trying to do
  • The type of information they intend to enter
  • What they plan to use the output for
  • Whether it is for internal use or external submission
  • A screen capture, if an error appeared
  • Date and time it occurred
  • Urgency

That said, it is just as important not to demand too much detail up front. Ask for too many fields and people will simply avoid making the enquiry at all.

A realistic approach is to start with the bare minimum and only ask for more where a judgement actually requires it.

For instance, you might pare the mandatory intake fields down to roughly five — “department”, “purpose of use”, “information to be entered”, “internal use or external submission”, and “what the difficulty is” — and leave the detailed follow-up to the first-line responder.

Prepare escalation scenarios

Prepare escalation scenarios

With generative-AI enquiries, you need to separate “questions the first-line desk may answer” from “questions that should be passed to a specialist department”.

The following are illustrative examples for when you draw up internal rules. In practice, do adjust them to your own organisational structure, security policy and contractual terms.

Cases to pass to IT

  • Can’t log in
  • No account has been issued
  • Insufficient permissions
  • Can’t upload files
  • The feature in question isn’t displayed
  • A system fault is suspected

With a tool such as Kanata, where the scope of use can be divided by project and permission, it is important to tell apart “the feature does not exist” from “it isn’t shown because the permission is missing”. Kanata’s operation manual likewise explains that permissions are set per member and that what one can do varies with those permissions.

Cases to pass to Security

  • Unsure whether personal data may be entered
  • May have entered confidential information
  • Wishes to have AI handle customer information
  • Wants to check whether integration with an external service is permitted
  • A data leak is suspected

In this territory, it is important that the first-line desk does not make the call on its own. A query that comes in after something has already been entered is closer to incident response, so it is handled separately from an ordinary FAQ answer.

Cases to pass to Legal

  • Wishes to summarise a contract with AI
  • Wants to check the terms of use
  • Wishes to handle text or images involving copyright
  • Wants to use AI output in a document submitted to a customer
  • Wishes to check the scope of liability or disclaimer wording

AI is not the final arbiter of contracts or the law. Draw a clear line in the FAQ around the areas that need a legal check.

Cases to pass to HR

  • Wishes to enter information on a job candidate
  • Wants to tidy up personnel-evaluation comments with AI
  • Wishes to summarise the content of an employee’s consultation with AI
  • Wants to handle matters involving employment, leave of absence or health information

In the HR domain, personal and sensitive information is more likely to be involved. Even where you would like to use AI to make work more efficient, you need a rule that things are checked before entry.

An example internal-FAQ template

An example internal-FAQ template

Here we offer an example of the FAQ worth having ready before rollout. Do adjust the answers to suit your own organisation’s rules.

Q. What information may I enter into generative AI?

A. Public information, and general business information that has been cleared for internal sharing, may be used in line with internal rules. However, personal data, sensitive information, undisclosed financial information, personnel reassignments, M&A information, contractual terms with customers and the like should be prohibited from entry or made subject to prior approval. If you are unsure, check with the enquiry desk before entering anything.

Q. May I include customer names or personal names?

A. As a rule, mask customer names and personal names. For instance, replace a customer name with “Manufacturer A”, a personal name with “Contact B”, and a figure with “in the tens of millions of yen”. There may also be contractual restrictions on the external use of customer information, so NDAs and contractual terms need checking.

Q. May I send text the AI has produced straight out of the company?

A. Avoid sending it as it stands. Text going outside the company should be checked by the person responsible and, where necessary, signed off by a line manager, legal or PR. Figures, dates, proper nouns, quotations and contractual terms must be reconciled against the original source.

Q. May I let the AI read contracts or internal regulations?

A. Contracts and internal regulations can be highly confidential. Judge only after checking the AI environment in use, the permission settings and any contractual restrictions. Even when handled in an internal-only environment or an access-restricted project, the final legal judgement must rest with a member of the legal team.

Q. If the AI’s answer turns out to be wrong, who is responsible?

A. Where AI output is used in the course of work, the final responsibility for checking lies with the user or the approver. Use AI as an aid for drafting and marshalling the points at issue, and run it on the understanding that the final decision is made by a person.

Q. What should I do when I have a question the FAQ doesn’t cover?

A. Take it to the enquiry desk. Depending on the content, the desk will check with IT, DX, security, legal, HR and so on. Common questions are folded back into the FAQ in due course.

An FAQ isn’t finished once published — grow it from the enquiries

An FAQ isn’t finished once published — grow it from the enquiries

There is no need to demand too much polish of an internal FAQ from the outset. Better, in fact, to build it on the understanding that you will update it from the enquiries that come in after rollout.

For the first 30 days after going live, it is worth reviewing the enquiries with the following in mind:

  • Which departments the enquiries come from most
  • Which categories of question are most common
  • Which questions could have been resolved simply by reading the FAQ
  • Which items are in the FAQ but aren’t getting through
  • Which areas are taking a long time to decide
  • Which questions have vague escalation routes

Where figures are involved, always make the assumptions explicit.

By way of an illustrative example: “Over the first 30 days after rollout, classifying 60 enquiries gave 20 on whether data could be entered, 15 on whether something could be used externally, and 10 on operational trouble.” In that case, the priorities for updating the FAQ become whether data may be entered and whether something may be used externally.

While you have no track record to draw on, there is no need to force out a numerical claim about the benefits. The realistic approach is to classify the enquiries first and feed the most frequently asked items back into the FAQ.

What to sort out if you are using Kanata

An internal FAQ and the machinery for handling enquiries are not something a single tool can deliver on its own. There are several options — a form, chat, a ticketing tool, an internal portal, a knowledge base.

Among them, if you are using Kanata, you can put features such as AI chat, AI summarisation, e-learning and the project library to work in organising internal knowledge and in training. The operation manual explains that AI settings, prompts and training data can be stored in a project library and referred to from the chat and summarisation apps within the project.

For instance, uses of the following kind come to mind:

  • Organising the FAQ and internal regulations as training data
  • Registering frequently used response approaches in a prompt library
  • Splitting projects by department and managing permissions
  • Setting up an AI chat for handling enquiries
  • Distributing training videos and explanatory materials as e-learning

That said, whichever tool you use — Kanata included — it cannot automatically settle the responsibility for enquiries or the rules for judgement themselves. Which information to register, who updates it and which answer counts as official are matters the organisation has to decide.

In summary: surface concerns about generative AI through enquiry design

In summary: surface concerns about generative AI through enquiry design

Roll generative AI out across the whole company and questions from the front line are a certainty.

Those questions are not confined to how the tool works. Many of them require judgement spanning several departments — which information may be entered, who is accountable for checking the output, whether something may be used externally, whom to notify when things go wrong.

That is precisely why it is important to put the following four things in place before rollout:

  • An internal FAQ
  • An enquiry desk
  • First-line triage
  • Escalation scenarios

The aim should not be to reduce enquiries to zero. It is to create a state in which people on the ground, when a worry strikes, can ask without hesitation — and then to reflect the enquiries that come in back into the FAQ and the rules, growing the operation little by little.

Generative AI adoption does not take root simply by handing out the tool. Only once you have a setup that picks up concerns on the ground, keeps judgements consistent and connects people to the specialist departments when needed do you start to approach an environment people can use with confidence.

Q&A: internal FAQ and enquiry desk before adopting generative AI

Before adopting generative AI, what should I decide first?

The first thing to settle is “who may use which information, for which tasks”. Beyond choosing a tool, you need to sort out, as a set, the scope of use, the information barred from entry, who is accountable for checking, and where to direct enquiries.

Is it enough for the enquiry desk to be IT alone?

Cases that IT can wrap up on its own are limited. IT will be at the centre of login and permissions, but personal data needs security, personnel information needs HR, and contracts and copyright need legal. The realistic design is to have a single way in and connect through to the specialist departments behind the scenes.

How fully built-out should an internal FAQ be before publishing?

There is no need to be exhaustive from the start. Before rollout, have the bare minimum ready — the range of tasks AI may be used for, the information that may be entered, the rules for checking AI output, and who to contact when something goes wrong — and update it from the enquiries that come in afterwards.

May I put AI’s answers straight out of the company?

Better not to. Text going outside the company needs a person to check the content and to reconcile figures, dates, proper nouns, quotations and contractual terms against the original source. Some documents also need a check from legal, PR or a line manager.

Does using Kanata mean enquiry handling can be automated?

Kanata can help by organising the FAQ and internal regulations as training data and by reusing prompts and knowledge. The responsibility for enquiries, the final judgement and the escalation criteria, however, have to be designed by the organisation. The tool is a means of supporting operation; it is no substitute for designing the rules themselves.

Share this article