Our methodology
Guides for executives, IT and data owners. Understand visible risks, then define your Private AI scope together.
RAGBOX Private AI Control Framework
This is RAGBOX planning guidance, not an external certification standard. Each layer needs an owner, evidence and tests.
AI readiness assessment
Equal question weights: implemented 100%, partial 50%, not yet 0%. Bands: 0–30 critical, 31–60 risk, 61–80 developing, 81–100 ready.
An initial self-assessment, not a security certification or compliance audit
- Uncontrolled AI — Shadow AI is AI use outside organizational approval or visibility. Risk depends on data, tools, accounts and contracts. It does not mean every public AI service is unsafe.
- AI policy — AI records should identify who did what, with which data and model, when, and who may review it. Balance useful evidence against sensitive information in logs.
- Managed AI — RBAC assigns permissions by role, linked to workspaces, sources and agents. Hiding buttons is not access enforcement.
- Private knowledge AI — Organize knowledge approved for AI with source, version and owner. Internal documents are not automatically accessible to every employee.
- Private agentic AI — An AI agent uses a model to select steps and tools toward a goal. Action permissions matter beyond document access: a model proposing an action does not authorize the user to perform it.
Putting it into practice
- Select permitted documents
- Assign data owners
- Prepare reference questions and answers
- Test denied access and deletion
- Measure quality, speed and cost before scaling
References
Public sources explain principles; they do not certify or endorse RAGBOX.
- NIST AI Risk Management Framework
- Microsoft: Retrieval-augmented generation
- OWASP: RAG Security Cheat Sheet
- OWASP: Prompt Injection Prevention
Expert review is required before operational use. This is not case-specific legal or tax advice.