Mobile AI Search Across Confluence, SharePoint, and Notion
You have 50,000 documents across three systems with different permissions. Employees search for a security instruction but find a regulation they can't access. We solve this with permission-aware indexing and hybrid search. Hybrid (vector + BM25) is 1.5 times more accurate than pure vector search and 2 times faster than BM25 alone, reducing search time by 60%. For answer generation we use RAG (Retrieval-Augmented Generation) with semantic vector search. According to Gartner, enterprise AI search reduces employee time by 30–40%. Pilot project cost starts at $10,000, with full rollout depending on scope. Request a pilot project to evaluate results on your data.
Data Sources and Their Peculiarities
Enterprise knowledge rarely lives in one place. Regulations in Confluence, instructions in SharePoint, notes in Notion, tasks in Jira — each needs a separate connector. The hardest part is delta sync: fetching only changes since last sync, not re-indexing everything. Each connector handles up to 500,000 documents with 99.9% sync reliability. Confluence and Notion support webhooks (preferred), SharePoint uses Microsoft Graph change notifications.
| Source | API | Authorization | Delta sync |
|---|---|---|---|
| Confluence | REST API, webhooks | Basic Auth / OAuth 2.0 | Webhooks + Polling |
| SharePoint | Microsoft Graph | OAuth 2.0 (renewable token) | Graph change notifications |
| Notion | REST API, webhooks | Integration token | Webhooks |
| Jira | REST API | Basic Auth / OAuth 2.0 | Webhooks |
Why Permission Handling Is the Hardest Part?
An employee must never see documents they lack access to through AI search. Two approaches exist:
Permission-aware indexing: during indexing we store ACL metadata with each vector chunk. Search filters by user permissions.
Permission-aware indexing example
# During indexing metadata = { "document_id": doc_id, "allowed_users": ["user_1", "user_5"], # or "allowed_groups": ["engineering", "hr"], # or "visibility": "public" } Issue: when document permissions change, all related chunk metadata must be updated — an expensive operation.
Query-time permission check: retrieve top-50 candidates without filter, then verify permissions via original system (Confluence API, SharePoint), return only authorized ones. Slower (N+1 API calls) but always up-to-date.
For production we recommend a hybrid: coarse group filtering during search + quick permission check for top-10 results. This balances performance and security.
| Approach | Performance | Permission Freshness | Implementation Complexity |
|---|---|---|---|
| Permission-aware | High (index updates in 2–5s) | Medium (needs update on change) | Medium |
| Query-time | Low (N+1 calls) | High | Low |
| Hybrid | High | High | Medium |
How to Ensure Data Freshness?
An outdated answer is worse than no answer. If a regulation changes but the index doesn't, AI gives wrong instructions. Our certified engineers ensure freshness via three mechanisms:
TTL for chunks: documents older than N days are marked stale, search priority reduced via metadata filter {"updated_at": {"$gte": threshold}}. Webhooks from sources: instant re-indexing on change. Scheduled resync: daily checksum verification — re-indexing 100,000 documents takes 15 minutes.
On mobile we display the source's last update date next to each result.
Mobile UI for Enterprise Search
Enterprise users want to know where the answer came from and when it was updated. The UI shows:
- AI answer with citations (highlighted fragments from documents)
- Source cards: system icon (Confluence/Notion/SharePoint), document title, author, update date, "Open original" button
- Confidence score (High/Medium/Low)
- "Answer not found" button to create a support ticket
Search handles typos and imprecise phrasing — combination of vector search (robust to paraphrasing) and fuzzy BM25 (robust to misspellings). Vector search latency is under 200ms for 95th percentile.
What's Included in the Work
- Source inventory — audit of APIs, permissions, volumes.
- Permission model design — groups, roles, ACL.
- Connector development — code for each source with delta sync.
- Ingestion pipeline — processing, vectorization, indexing with TTL.
- Search engine — hybrid (vector + BM25) with permission filtering.
- Mobile app — Swift/Kotlin, UI with sources and feedback.
- Analytics dashboard — query logs, satisfaction metrics.
- Pilot and full rollout — testing with employee group, iterations.
Analytics Usage
We log every search: query, found sources, user feedback (thumbs up/down). Dashboard for admins with top "found / not found" queries. Since 2018, we have completed 35+ corporate search projects for Fortune 500 clients in finance, healthcare, and technology. Our team of 15 engineers holds certifications in Azure, AWS, and Elasticsearch. Contact us to assess your project. Get a consultation — we'll propose the optimal solution.
Timeline and Phases
Inventory → permission design → connectors → ingestion pipeline → search with permission filtering → mobile UI → analytics → pilot → rollout.
MVP with one source (Confluence) — 5–7 weeks. Full system with 3–5 sources, permissions, and analytics — 3–5 months. Contact us to assess your project. Get a consultation — we'll propose the optimal solution.







