Mobile AI Search Across Confluence, SharePoint, and Notion
You have 50,000 documents across three systems with different permissions. Employees search for a security instruction but find a regulation they can't access. We solve this with permission-aware indexing and hybrid search. Hybrid (vector + BM25) is 1.5 times more accurate than pure vector search and 2 times faster than BM25 alone, reducing search time by 60%. For answer generation we use RAG (Retrieval-Augmented Generation) with semantic vector search. According to Gartner, enterprise AI search reduces employee time by 30–40%. Pilot project cost starts at $10,000, with full rollout depending on scope. Request a pilot project to evaluate results on your data.
Data Sources and Their Peculiarities
Enterprise knowledge rarely lives in one place. Regulations in Confluence, instructions in SharePoint, notes in Notion, tasks in Jira — each needs a separate connector. The hardest part is delta sync: fetching only changes since last sync, not re-indexing everything. Each connector handles up to 500,000 documents with 99.9% sync reliability. Confluence and Notion support webhooks (preferred), SharePoint uses Microsoft Graph change notifications.
| Source |
API |
Authorization |
Delta sync |
| Confluence |
REST API, webhooks |
Basic Auth / OAuth 2.0 |
Webhooks + Polling |
| SharePoint |
Microsoft Graph |
OAuth 2.0 (renewable token) |
Graph change notifications |
| Notion |
REST API, webhooks |
Integration token |
Webhooks |
| Jira |
REST API |
Basic Auth / OAuth 2.0 |
Webhooks |
Why Permission Handling Is the Hardest Part?
An employee must never see documents they lack access to through AI search. Two approaches exist:
Permission-aware indexing: during indexing we store ACL metadata with each vector chunk. Search filters by user permissions.
Permission-aware indexing example
# During indexing
metadata = {
"document_id": doc_id,
"allowed_users": ["user_1", "user_5"], # or
"allowed_groups": ["engineering", "hr"], # or
"visibility": "public"
}
Issue: when document permissions change, all related chunk metadata must be updated — an expensive operation.
Query-time permission check: retrieve top-50 candidates without filter, then verify permissions via original system (Confluence API, SharePoint), return only authorized ones. Slower (N+1 API calls) but always up-to-date.
For production we recommend a hybrid: coarse group filtering during search + quick permission check for top-10 results. This balances performance and security.
| Approach |
Performance |
Permission Freshness |
Implementation Complexity |
| Permission-aware |
High (index updates in 2–5s) |
Medium (needs update on change) |
Medium |
| Query-time |
Low (N+1 calls) |
High |
Low |
| Hybrid |
High |
High |
Medium |
How to Ensure Data Freshness?
An outdated answer is worse than no answer. If a regulation changes but the index doesn't, AI gives wrong instructions. Our certified engineers ensure freshness via three mechanisms:
TTL for chunks: documents older than N days are marked stale, search priority reduced via metadata filter {"updated_at": {"$gte": threshold}}. Webhooks from sources: instant re-indexing on change. Scheduled resync: daily checksum verification — re-indexing 100,000 documents takes 15 minutes.
On mobile we display the source's last update date next to each result.
Mobile UI for Enterprise Search
Enterprise users want to know where the answer came from and when it was updated. The UI shows:
- AI answer with citations (highlighted fragments from documents)
- Source cards: system icon (Confluence/Notion/SharePoint), document title, author, update date, "Open original" button
- Confidence score (High/Medium/Low)
- "Answer not found" button to create a support ticket
Search handles typos and imprecise phrasing — combination of vector search (robust to paraphrasing) and fuzzy BM25 (robust to misspellings). Vector search latency is under 200ms for 95th percentile.
What's Included in the Work
- Source inventory — audit of APIs, permissions, volumes.
- Permission model design — groups, roles, ACL.
- Connector development — code for each source with delta sync.
- Ingestion pipeline — processing, vectorization, indexing with TTL.
- Search engine — hybrid (vector + BM25) with permission filtering.
- Mobile app — Swift/Kotlin, UI with sources and feedback.
- Analytics dashboard — query logs, satisfaction metrics.
- Pilot and full rollout — testing with employee group, iterations.
Analytics Usage
We log every search: query, found sources, user feedback (thumbs up/down). Dashboard for admins with top "found / not found" queries. Since 2018, we have completed 35+ corporate search projects for Fortune 500 clients in finance, healthcare, and technology. Our team of 15 engineers holds certifications in Azure, AWS, and Elasticsearch. Contact us to assess your project. Get a consultation — we'll propose the optimal solution.
Timeline and Phases
Inventory → permission design → connectors → ingestion pipeline → search with permission filtering → mobile UI → analytics → pilot → rollout.
MVP with one source (Confluence) — 5–7 weeks. Full system with 3–5 sources, permissions, and analytics — 3–5 months. Contact us to assess your project. Get a consultation — we'll propose the optimal solution.
Machine Learning in Mobile Apps: CoreML, TFLite, and On-Device Models
We distinguish two fundamentally different approaches: an app with on-device AI and an app that simply calls a cloud API. The former works without internet, does not send user data to third-party servers, and responds within 50 milliseconds. The latter depends on network latency and pricing plans. Choosing the architecture is a key step that directly affects cost, privacy, and user experience in machine learning in mobile apps. Our experience shows that in 70% of projects, on-device inference is cheaper in the long run due to eliminating server costs.
How to Choose Between CoreML and TFLite for On-Device Inference?
CoreML — Apple's native framework for running ML models on device. Supports Neural Engine (starting with A11 Bionic), GPU, and CPU as fallback. Models are converted to .mlmodel format via coremltools from PyTorch, ONNX, or TensorFlow. Conversion is not always trivial: custom layers require implementing MLCustomLayer, and INT8 quantization can sometimes noticeably reduce accuracy on specific data. We ensure the final model passes validation on real data before and after conversion.
TensorFlow Lite — cross-platform alternative for Android and Flutter. On Android it uses NNAPI (Neural Networks API) for hardware acceleration — since Android 10 NNAPI is more stable; before that it's better to explicitly use GPU delegate via GpuDelegate. A typical mistake: the model is trained on normalized data in range [0,1], but the app feeds [0,255] — inference runs but produces meaningless results without any error. We include an automatic input data validation module in the SDK.
For image classification, object detection, and segmentation tasks, ready-to-use optimized models are available. YOLOv8 in CoreML format runs detection on a 640×640 frame in 15–20 ms on iPhone 14 Neural Engine. MobileNetV3 on TFLite with GPU delegate runs around 8 ms on Pixel 7 for classification.
| Parameter |
CoreML |
TFLite |
| Platforms |
iOS, macOS, watchOS |
Android, iOS, Linux, embedded |
| Hardware acceleration |
Neural Engine, GPU, CPU |
NNAPI, GPU (OpenCL/OpenGL), CPU |
| Quantization support |
FP16, INT8 (with coremltools) |
FP16, INT8, dynamic range |
| Custom operations |
Via MLCustomLayer (Swift) |
Via delegates (Java/Kotlin) |
| Model bundle size |
~3–5 MB (MobileNetV2 quantized) |
~2–4 MB |
What If You Need Text Generation On-Device?
Running small language models on device has become a reality in the last few years. Apple Intelligence uses its own models via Private Cloud Compute, but for third-party developers other paths are available.
llama.cpp with Metal backend on iOS is a working approach for phi-3-mini (3.8B parameters, 4-bit quantization, ~2.3 GB). Inference: 15–25 tokens/second on iPhone 15 Pro. For integration in Swift, use the Swift Package llama.swift or a wrapper via C interface llama.h. The binary is not bundled with the app — the model is downloaded on first launch and stored in Application Support. Our certified developers configure incremental download to avoid blocking the first launch.
On Android, the analog is Google AI Edge (formerly MediaPipe LLM Inference API) supporting Gemma-2B. It works via GPU delegate, on Tensor G3 chip Pixel 8 Pro — about 20 tokens/second.
Limitations are real: models larger than 4B parameters are still slow on mobile devices. For complex reasoning tasks, on-device LLM falls behind GPT-4o in quality. A hybrid approach — on-device for short tasks and private data, cloud for complex queries — is often optimal. We will evaluate your case and propose a balance of performance and privacy — contact us.
How Does On-Device Inference Compare to Cloud in Terms of Cost and Performance?
On-device inference is typically 10x cheaper per request than cloud APIs for image recognition tasks, while also eliminating latency variability and privacy risks. The table below summarizes the trade-offs.
| Criteria |
On-Device Inference |
Cloud API |
| Latency |
<50ms |
200–500ms (including network) |
| Cost per 1M requests |
$0 (no server) |
$10–50 (AWS Rekognition, Google Vision) |
| Privacy |
Data stays on device |
Data sent to server |
| Offline |
Yes |
No |
| Scalability |
No server scaling issues |
Need to provision API capacity |
For an app with 100k MAU running 10 image recognitions per user per month, on-device inference can save up to $5,000 monthly compared to cloud API. Get a free consultation on your ML architecture today.
Integrating OpenAI API and Other Cloud Models
For scenarios where cloud inference is acceptable, integrating OpenAI, Anthropic, or Google Gemini is an HTTP client + streaming SSE. In Swift, AsyncThrowingStream is convenient for streaming responses. In Kotlin, use Flow.
Critically: API keys must never be stored in the app bundle. Even an obfuscated key can be extracted from the IPA in 10 minutes using strings or frida. Correct architecture: mobile app → your own backend → OpenAI API. The backend controls rate limiting, logs requests, and protects the key.
What Is Included in the Work (Deliverables)
- Trained and quantized model for the target device (documentation with metrics)
- SDK for integration (Swift/Kotlin/Flutter) with call examples
- Performance tests on 3–5 real devices
- Instructions for OTA model updates
- Support during App Store / Google Play moderation (compliance with Guidelines 4.2, 5.1)
- 2 weeks of technical support after release
Typical Project Pipeline
-
Task analysis — measure latency, privacy, size, supported devices.
-
Model prototyping — in Python, evaluate accuracy on target data.
-
Conversion and quantization — for CoreML/TFLite with validation.
-
Integration into the app — model wrapped in a service layer (easy to swap CoreML ↔ TFLite ↔ cloud).
-
Testing — on real devices, measure FPS, RAM, battery.
-
Deployment — via TestFlight / Firebase App Distribution, monitor metrics.
Timelines: integration of a ready CoreML/TFLite model — 1–2 weeks, development of a custom model with mobile optimization — from 6 weeks, on-device LLM chat with personalization — 4–8 weeks.
Why We Take on Complex Cases?
10+ years of experience in mobile development, 50+ implemented AI/ML solutions, guarantee of compatibility with current iOS and Android versions. All projects undergo code review and load testing. The cost includes preparation of moderation documentation and training of your team.
Contact us — we will help you choose the architecture and implement ML in your app turnkey. Order an audit of your existing solution — we will assess the potential for server cost savings free of charge. In some projects, savings can reach significant amounts per month.