The Client is a European bank with approximately 8,000 employees operating across multiple countries, spanning retail banking, corporate banking, risk management, and shared service functions. Over a decade of mergers, country expansions, and tooling migrations, it has accumulated a federated knowledge landscape in which internal information is fragmented across Confluence, Jira, SharePoint, Google Drive, ServiceNow, HR systems, compliance repositories, delivery playbooks, and a legacy client-ownership application. Authoritative content for a single business process is routinely scattered across three or more systems — and the business cost of that fragmentation is measurable in lost productivity, slow onboarding, inconsistent answers, repeated support tickets, and operational risk from employees acting on outdated documents.
To address this, the Client has implemented an internal AI assistant, referred to throughout as "the Assistant," built on Google Cloud Gemini Enterprise Plus. The Assistant provides a single, permission-aware, citation-grounded entry point for all internal knowledge and process questions. It answers in natural language, cites every source, respects source-system permissions, and — where governance allows — executes controlled workflow actions such as drafting ServiceNow requests. Employees no longer need to know where information lives; they ask one assistant and receive a grounded, permissioned answer with citations, ownership, validity date, and country applicability surfaced in every response.
The platform decision is treated as final. Gemini Enterprise was selected because it combines enterprise search, retrieval-augmented generation, permissions-aware retrieval, native connectors for the bank's existing SaaS landscape, configurable agents, observability, and regulated-industry security controls in a single product. The result is a trusted answer layer that reduces time spent searching, accelerates onboarding, deflects repetitive support requests, strengthens the compliance posture, and keeps every prompt, response, citation, and action fully auditable.
The Client operates a federated knowledge environment that has grown organically over a decade of mergers, country expansions, and tooling migrations. Authoritative content for any single business process is frequently spread across three or more systems: a question as ordinary as "How do I request vacation?" can require consulting the global HR policy in SharePoint, a country-specific addendum in a Google Drive folder, the ServiceNow request form, the approval workflow definition, and in some markets a local works-council agreement archived in Confluence. Prior attempts to fix this through static intranet portals, content-management consolidation, and keyword search have not delivered durable improvement — because the root cause is not a shortage of content, but the absence of a permission-aware, role-aware, citation-grounded answer layer that can reason across systems.
Employees spend a measurable share of their working time searching for, validating, and reconciling internal information. The Client's own operations surveys indicate that knowledge workers lose between four and six hours per week to internal search and clarification — time that produces no output and steadily erodes capacity across an 8,000-person workforce. The same problem falls hardest on new hires, who need multi-week ramp time simply to learn where information lives. That drag is most costly in exactly the roles where the bank competes hardest on talent, such as corporate banking relationship managers and senior risk analysts, where slow time-to-productivity translates directly into lost commercial ground.
In a regulated banking environment, fragmentation is not only inefficient — it is dangerous. Employees routinely act on outdated templates, deprecated policies, or country-mismatched procedures because nothing signals which version is current or where it applies. When a policy has an owner, a validity date, and a country scope that the employee cannot see, the wrong document looks identical to the right one. Acting on stale or misapplied guidance carries audit, regulatory, and reputational consequences, and the risk compounds quietly: every unverified answer is a potential control failure waiting to surface in review.
The Client's Assistant is delivered as a unified, employee-facing service available through five access channels — the Gemini Enterprise web app, an embedded intranet widget, a Google Chat bot, a mobile-optimised browser experience, and a Google Workspace add-on — all sharing the same backend, identity context, and governance controls. It accepts natural-language questions and returns a structured, grounded answer with a fixed anatomy: a direct answer, a step-by-step procedure where relevant, citations to every source document, policy metadata such as owner, last review date, validity status, and country applicability, and a recommended next action. The Assistant never returns a bare hyperlink — every response is grounded, every claim is cited, and every source surfaces its provenance.
Two design decisions separate this from a generic AI demo. The first is strict permission inheritance: the Assistant integrates end-to-end with the bank's identity infrastructure, anchored in Microsoft Entra ID and federated to Google Cloud through Workforce Identity Federation, inheriting each user's group membership, country, department, and role at every session start. If a user cannot open a source document in its native system, the Assistant cannot retrieve, cite, or use that document in answer generation — a rule applied uniformly across all connectors, with no permissive fallback.
The second is knowledge normalisation. Every indexed document is enriched with a fixed metadata schema — source, owner, business domain, country, role, confidentiality level, validity date, review date, policy type, and more — applied uniformly across all source systems. This metadata drives filtering, retrieval boosting, answer ranking, and lifecycle management, so a country-specific policy outranks a generic global one and an expired policy is excluded entirely. Documents lacking a named owner, a validity date, or a confidentiality classification are held out of the index at ingestion until remediated.
Inside Gemini Enterprise, a main Employee Knowledge Assistant acts as the router and delegates to four specialised agents when intent is unambiguous. An Onboarding Agent generates a personalised first-week plan from the joiner's role, country, department, and start date; an HR Policy Agent handles leave, benefits, and mobility with strict country-aware filtering; and a Delivery Management Agent serves project managers with templates and governance material, enforcing a "latest approved template" rule.
A Service Request Agent bridges knowledge to action. It identifies the correct ServiceNow request type for an employee's intent, prepares a draft with pre-filled fields, asks the employee to confirm any missing justification, and submits only after explicit user confirmation — never auto-submitting under any circumstances. Underpinning all of this is a non-negotiable security layer: a VPC Service Controls perimeter, CMEK encryption via Cloud KMS, TLS 1.3 in transit, Model Armor on every agent, seven-year audit logging streamed to the bank's SIEM, and full EU data residency for all data, models, and logs.
The programme is governed by a fixed set of committed targets, baselined during the pilot and tracked monthly once the Assistant reaches full rollout. Success is defined not by activity but by measurable movement in productivity, support load, answer quality, and compliance posture — and any deviation from target trajectory triggers a governance review rather than being quietly absorbed.
Productivity, Support, and Onboarding Gains
Answer Quality and Compliance Assurance
The Assistant turns the Client's internal knowledge from a passive, fragmented document archive into an active, permission-aware, citation-grounded employee service layer. Employees no longer need to know where information lives; they ask one trusted assistant, receive a grounded answer with named sources, owners, and validity dates, and move directly to the next action. What was once four to six lost hours a week and a source of quiet compliance risk becomes a single, auditable point of entry to the organisation's knowledge.
The architecture, agent design, governance model, security posture, KPIs, and rollout sequence set out in this use case are committed decisions, not options under evaluation. The platform is Gemini Enterprise Plus, the deployment region is the European Union, the operating model is permanent, and the security controls are non-negotiable. Delivery proceeds through four sequential phases over nine months — from discovery and data readiness, through a 1,000-user MVP and the activation of agentic workflows, to full enterprise rollout across all 8,000 employees — each with a defined exit gate and go/no-go review.
The value extends beyond the Assistant itself. Once live, the same architecture, governance, and security envelope becomes a reusable foundation for the Client's broader AI operating model, with the next wave of services — contact-centre assistance, relationship-manager copilots, risk-officer research, and developer productivity — built on top of the established permission model, connector fabric, and audit framework without re-architecting from scratch. The Assistant is not a standalone tool but the first, trust-building instance of a durable enterprise AI platform.