Skip to main content

    Private & Secure AI

    Building an internal AI knowledge system with SharePoint and Outlook

    8 min readUpdated August 2026

    The short answer

    An internal AI knowledge system over SharePoint and Outlook typically costs £12,000 to £30,000 to build and £250 to £900 a month to run. It indexes your document libraries, intranet pages and — where appropriate — shared mailboxes, then answers staff questions in plain English with citations, respecting each person's existing Microsoft 365 permissions. Most deployments take eight to twelve weeks, and the hardest part is content quality, not technology.

    Indicative price ranges

    Single library

    £6,000 – £12,000

    One SharePoint site or document library indexed, chat interface, citations, basic admin. A strong proof of value.

    Full tenant

    £12,000 – £30,000

    Multiple sites, shared mailboxes, permission-aware retrieval via Microsoft Graph, Teams integration, analytics on what staff actually ask.

    Knowledge + action

    £30,000 – £60,000

    The assistant also drafts replies, files documents, raises tickets and updates the CRM — with approval steps on every write.

    These are indicative UK ranges based on projects we have actually delivered. Scope drives the number, not the sales conversation — we quote a fixed price after a scoping session, and we will tell you if an off-the-shelf tool is the cheaper answer.

    Typical timescales

    1. 1–2 weeks

      Content audit

      Which libraries are authoritative, which are graveyards, and what must be excluded outright.

    2. 2–3 weeks

      Graph integration and indexing

      Connecting via Microsoft Graph, mapping permissions, building the index.

    3. 3–5 weeks

      Assistant build

      Teams and web interfaces, citations, refusal handling, admin console.

    4. 2–4 weeks

      Pilot and rollout

      One department first, tuned on their real questions, then wider.

    Who this suits

    • Organisations already standardised on Microsoft 365 with content in SharePoint rather than personal drives.
    • Teams where onboarding is slow because knowledge lives in people's heads and old email threads.
    • Businesses with heavy policy, contract or specification documentation that staff must search daily.
    • Support and operations teams answering the same internal questions repeatedly.

    Who it does not suit

    • Businesses whose documents live on a local file server nobody has tidied since 2019 — fix the content first, or budget for that work.
    • Organisations with fewer than about fifteen staff; the time saved rarely covers the build.
    • Teams unwilling to nominate content owners. Stale sources produce confidently wrong answers.
    • Anyone hoping to index mailboxes wholesale without a privacy assessment. That needs care and consultation.

    What actually drives the cost

    Content hygiene

    Duplicated policies with three versions in circulation are the single biggest cost multiplier. The AI will surface all three.

    Permission complexity

    Clean group-based permissions are cheap to mirror. Thousands of item-level exceptions are not.

    Mailbox scope

    Shared, role-based mailboxes are reasonable to index. Personal mailboxes raise privacy questions that need answering before any technical work.

    Interface count

    Teams, web and mobile each need their own build and testing.

    Why Microsoft's own search disappoints

    SharePoint search matches keywords. Staff ask questions. "What is our subcontractor insurance requirement on public-sector jobs?" returns forty documents containing the word insurance, and the person gives up and asks a colleague — which is the hidden cost you are actually trying to remove.

    A retrieval-based assistant reads the relevant passages and answers the question, then links the exact document and section so the answer can be checked. That difference — question in, cited answer out — is the whole point.

    How the permission model works

    The system authenticates each user against Microsoft Entra ID and retrieves only content that user is already entitled to open, using Microsoft Graph. Two people can ask the same question and correctly receive different answers, because HR sees the HR library and the site team does not. Any implementation that skips this and indexes everything into one open pool is a data breach waiting for its moment.

    The content problem nobody warns you about

    Roughly 60% of the effort in these projects is content, not code. Typical findings in a first audit:

    • Three versions of the same policy, none marked current.
    • Critical processes documented only in an email chain from 2022.
    • Templates in a folder called "old" that people still use daily.
    • Authoritative material sitting in someone's OneDrive rather than a team site.

    We handle this by scoping tightly: index the libraries that are genuinely authoritative, exclude the rest, and expand only as content is cleaned. A narrow assistant that is always right builds trust. A broad one that is sometimes wrong gets abandoned in a fortnight.

    What to measure

    Track time-to-find, the proportion of questions answered without escalation, and — most usefully — the questions the assistant could not answer. That last list is a free, continuously updated map of the documentation gaps in your business.

    If confidentiality is your main concern, read can a company use AI without sharing confidential information. For budgeting, see private business AI system costs.

    Common questions

    Is this the same as Microsoft 365 Copilot?

    It overlaps. Copilot is excellent for drafting inside Office apps and is priced per user per month. A bespoke retrieval system gives you control over exactly which sources are authoritative, how refusals work, what is logged, and how answers are presented — and it has no per-seat fee. Plenty of clients run both.

    Can it index Outlook mailboxes?

    Shared and role-based mailboxes, yes, and they are often the richest source of institutional knowledge. Personal mailboxes need a privacy assessment and staff consultation before you go near them.

    What if a document is out of date?

    The assistant will quote it, because it faithfully reflects your content. That is why every deployment includes named content owners and a review cycle — the system exposes documentation debt rather than hiding it.

    How long before staff actually use it?

    Adoption is fastest when it lives inside Teams where people already work, and when the first pilot group is chosen for high question volume. Most pilots reach regular daily use within three to four weeks.

    Get Started

    Ready to own your
    digital infrastructure

    Book a free infrastructure audit. We'll map your current systems, identify gaps, and show you exactly how a connected digital platform can transform your business.

    Response within 24 hoursNo obligation, no pressureFree infrastructure audit included