Project-aware access
Separate identities, folders, retrieval indexes, memory, tools, credentials, and retention by project or team where the platform allows. Test isolation with denied-access cases.
AI Impact Maine is based in Portland and supports Brunswick, Bath, and Midcoast Maine remotely and onsite by arrangement. We help engineering, maritime-related, contracting, professional, nonprofit, and educational organizations evaluate private assistants and governed agents for technical documents, project knowledge, document review, and multi-step work.
An internal knowledge or document-review agent can help find approved specifications, procedures, project notes, research, and correspondence. The hard work is not merely connecting a folder: it is distinguishing current from superseded material, preserving citations, separating projects, respecting contractual or organizational access, and ensuring a qualified person reviews important conclusions.
Separate identities, folders, retrieval indexes, memory, tools, credentials, and retention by project or team where the platform allows. Test isolation with denied-access cases.
Prefer responses that point to approved sources and revision status. Define what happens when documents conflict, lack context, or fall outside the agent’s approved knowledge base.
Agents may accelerate search and review, but they do not replace accountable engineering, contractual, academic, safety, or professional decisions.
A local or self-hosted agent harness may run on client-controlled hardware, with local models, private cloud, or a hybrid design. Planning covers model endpoints, storage, agent memory, retrieval indexes, backups, updates, capacity, reliability, integrations, and operating ownership.
Cloud models may also be used through Azure OpenAI, Claude through Amazon Bedrock, or direct OpenAI or Anthropic commercial APIs when their data flows, agreements, and controls fit the project.
A locally installed agent does not automatically mean all data remains local. Data can still leave the environment when cloud models, external APIs, websites, messaging systems, or third-party tools are enabled.
A data-flow review follows each connection, transmitted field, credential, storage location, log, support path, backup, and retention responsibility rather than relying on a “local” label.
Select a bounded internal knowledge, document-processing, research, administrative, customer inquiry, website, or business-system workflow. Define approved models, data, tools, users, human-reviewed actions, least privilege, logs, controlled tests, fallback, rollback, and shutdown. Not every workflow should become an agent.
Explore secure deploymentInventory agents and sub-agents, assign owners, review files, folders, applications, tools, credentials, network destinations, human approvals, and logging, identify shadow agents, and document remediation and emergency controls. Security tooling is used only when technically suitable.
Explore agent securityReview supported records for selected sessions, commands, tools, files, destinations, permissions, and configurations. When evidence allows, produce a redacted incident timeline, findings, remediation actions, and confidence and coverage limitations. Complete reconstruction is not promised.
Explore activity auditsDefine owners and relationships for agents and sub-agents, handoff boundaries, shared memory, tools, credentials, escalation, human approval, failed-task handling, emergency shutdown, and change and version management.
Explore governance reviewsSupport can include scheduled health checks, configuration and version review, dependency review, backup verification, permission review, failed-task investigation, usage and reliability reporting, documentation updates, staff assistance, and quarterly governance review.
The agreement defines frequency, supported endpoints and agents, integrations, available logs, and response expectations. Coverage depends on those integrations and records and is not marketed as 24/7 monitoring.
Name project owners, approved repositories, document status, users, tools, actions, and the decisions that remain human.
Map identities, permissions, models, storage, retrieval, memory, credentials, destinations, logs, backups, and vendor responsibilities.
Evaluate representative documents, citations, revision conflicts, project isolation, tool restrictions, approval, failure, rollback, and shutdown.
Deliver inventory, ownership and relationship maps, configuration notes, evidence, limitations, prioritized remediation, runbooks, and staff guidance.
They can search and summarize approved repositories when document formats, access controls, indexing, citations, revision status, and quality checks are suitable. A subject-matter expert should review consequential conclusions.
Yes, where the platform supports separation. Project identities, data stores, retrieval indexes, tools, credentials, retention, and logs should be isolated and tested rather than separated only by instructions.
It defines who owns each agent, how agents and sub-agents hand work to one another, what memory and tools they share, when people approve actions, how failures escalate, and how the system is changed or stopped.
It may, if the selected models, storage, tools, integrations, support paths, and operating practices remain client-controlled. Any enabled cloud service or external connection must be assessed separately.
The review inventories destinations, APIs, authentication, transmitted fields, permissions, encryption, logging, vendor responsibility, failure behavior, and whether each connection is necessary for the approved purpose.
Bring one document set or project workflow and the people responsible for it. We can scope a deployment, security assessment, audit, governance review, or scheduled support engagement.