+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● B2B offer — Knowledge & unified search

Company knowledge: one search, all your sources

The information exists: it is spread across the intranet, the file stores, the business tools and the team spaces in Microsoft Teams and Slack. Your agent offers a single search across the lot — queried from Microsoft Teams, Slack or email — strictly respecting each employee's access rights, and cites for every answer the source and the original location. Hosted in France: all of your internal content stays with you.

Hosted in France Internal content protected GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
Company knowledge · hosted in France
Who has worked on this kind of case before, and where are the deliverables?
Four sources concerned: one project space, two file folders and an intranet page.
For each: the exact location and the date last changed.
These results correspond to the spaces you have access to.
🔗 Sourced · internal sources, within your access rights
There must be other documents elsewhere.
I only look at the spaces your rights allow: the others are no more accessible to me than to you.
Widening your access rests with the administrators of each space — the agent never opens an access itself.
✎ Support · access rights unchanged
Local inference · no data outside the EU
Sources hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
Your teams decideThe agent prepares, never rules
✦ In brief

A Blue Lemon Agent knowledge management agent unifies search across all your internal sources — intranet, file stores, business tools — while respecting each employee's access rights and citing the original location of every result. It never opens an access itself. It runs on local inference or is hosted in France: your internal content stays with you, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.

100%
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
6
search uses ready to deploy
0
decision taken without human approval

These figures describe our offer, not results measured at a client. How large the gain is on your number of sources connected and users is confirmed by a pilot.

The context

What does an AI agent bring to your company's knowledge?

What the company already knows is its most profitable asset — provided an employee can find it from a single place.

! The issue

A company's knowledge is complete but scattered: each tool holds part of the answer. A unified search brings those parts together, provided it respects the access rights of whoever is asking. The agent applies each employee's exact scope and cites the original location of every result.

Our answer

Every employee questions all the sources they are entitled to, from a single point of entry, and gets back to the original location in one click. Access rights stay managed by the administrators of each space: the agent never widens them. Local inference or an isolated resource hosted in France: all of your internal content does not leave the company.

The decisive point

All of your internal content: sovereignty & compliance

A unified search touches the company's entire body of information: respecting access rights is the central guarantee. Here is how it is upheld.

Local inference

The agent can run on a machine belonging to your organisation: no internal content leaves the network.

Hosting in France

Otherwise, a dedicated and isolated resource hosted in France, under French law — your scattered information sources: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

For all of your internal content, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.

Isolated resource

No pooling: an environment strictly dedicated to your company and its workspaces.

Each person's rights, applied to the letter

An employee sees only what their rights already allow; encryption, role-based access and logging of every search.

AI Act: governed deployment

The agent is strictly in support; no access is opened and no content is changed automatically; traceability and human oversight from end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For executive spaces, employment data and confidential projects, SecNumCloud and reinforced hosting are options depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Ventaline — design office and manufacturer of ventilation systems for commercial buildings

Sector
Design, manufacture and maintenance of ventilation systems for commercial buildings — in-house design office and after-sales service
Headcount
240 staff, including 38 in the design office, 26 in after-sales, 12 in purchasing and 9 in quality; 186 people hold an account on at least one of the connected sources
Market served
Commercial property owners, social landlords and hospitals — 410 sites delivered over ten years, 190 of them still under warranty or under a maintenance contract
Volume
1.9 million files on the servers, 12 years of intranet, 74,000 team discussion threads — and 2,900 information searches a month, all logged
Tools in place
Intranet, two file repositories, the design office's document management system, the after-sales ticketing tool and the team messaging platform — the agent plugs into them read-only, nothing is replaced and nothing is migrated
Who decides
The head of information systems settles the list of connected sources; the administrators of each space remain the only people who can open access; the design office director designates what counts as the reference version
Room for improvement
60 % of the time spent on a search goes into querying the sources one after another; tracing where a document came from takes another 30 %; and 35 % of searches end with a question put to a colleague — a successful search takes 16 minutes on average

Ventaline is not short of information: it has twelve years of it, spread across six tools that do not talk to each other. What the company already knows is its most profitable asset, provided a member of staff can find it from a single place — and without seeing one byte more than their rights already allow. The agent runs on local inference on a machine at Ventaline and reads the six sources without ever writing to them. The exchanges below span a quarter, from the initial indexing to the review.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

Company knowledge · hosted in France
I indexed your six sources over the weekend — 1.9 million files, twelve years of intranet, 74,000 discussion threads — and I have pulled out a figure your access logs were carrying without anyone ever reading it.
Indexing means reading the content of every document so it can then be found by what it says, and not by the file name or the folder it sits in. Nothing is copied, nothing is moved, nothing is renamed: your current paths work exactly as they did yesterday.
The gap I measured, and it is the one that decides the gain: out of your 2,900 searches this month, 1,276 were re-run word for word on a second source in under ten minutes44 %. A search re-run identically elsewhere is a search that did not succeed the first time. Your staff search well: they search six times.
What that costs, across three items you already measure:
· Querying the sources one after another: 60 % of the time spent on a search.
· Tracing where the document found came from, and whether it governs: another 30 %.
· 35 % of searches end with a question put to a colleague — the most expensive item of all, because it is paid twice: by the person searching and by the person interrupted.
What I am putting in place: a single point of entry across the six sources, read-only, where every answer arrives with its exact location and its last-modified date. A successful search goes from 16 minutes to 5.
The next step, and it is the first thing to settle: the map of the six sources is drawn up, with for each one the number of spaces and the number of people entitled to them today. Hand it to your head of information systems: she settles the connection order, and I start with the sources she names. map-of-the-six-sources_what-is-indexed.pdf1.9 M files, 6 sources, 0 content copied
⛓ Sourced · access logs of the six sources over 30 days, inventory of spaces and their rights
The set includes the HR space and the executive space. A workshop supervisor must not stumble onto a salary table because someone plugged in a search engine.
He will not stumble onto it, and not because I decided so: it is your rights that answer, not mine.
The access perimeter is the exact list of spaces a person can already open with their account. I have no other one: I query the six sources ON BEHALF of whoever asks the question.
The proof runs on three accounts, same question — “what is the year-end bonus policy?”:
· The workshop supervisor receives the intranet note open to everyone, dated. Nothing else exists for him.
· The head of human resources also receives the two internal notes from the HR space and the company agreement.
· The managing director also receives the budget framing note from the executive space.
Three answers to the same question: each person sees what they already saw, and now they find it.
The three guarantees that hold this sealing, and you can have them written into the contract:
· Opening an access stays with the administrator of each space, and with them alone — it is a technical power I do not have, not an instruction I comply with.
· An extract stays inside the perimeter of whoever is asking, summaries included. The summary of a confidential document is a confidential document.
· When the answer sits in a closed space, you get the path: “a document answers your question in the HR space; its owner is the head of human resources.” Ten seconds, instead of three follow-ups and an answer the next day.
What I propose: that your head of information systems reviews the 41 spaces and 186 accounts before go-live. Out of the 41, 7 carry rights broader than your internal policy provides for, and unified search is what finally puts them side by side. The list of seven is ready, proposed tightening and review date included: a benefit you had not asked for, and it lands before go-live. access-perimeters_41-spaces-186-accounts.pdf3 accounts, one question, three answers
⛓ Sourced · account directory, declared rights of the 41 spaces, internal authorisation policy
All of this assumes you read our drawings, our contracts and our internal exchanges. Where exactly do they end up?
They stay with you. I run on local inference on a Ventaline machine, and your six sources are copied nowhere.
Local inference means the model computes on your machine: the text of a drawing or a contract crosses no outside network to be processed. If you would rather not administer a machine, the other route is an isolated resource hosted in France, dedicated to your company alone — no sharing.
What that lets you write in a tender file:
· Your content trains no model, neither ours nor a third party's. What I learn from Ventaline serves Ventaline.
· I read your six sources and stop there: the technical account I read through has no write permission — sturdier than a promise, and your administrator checks it in three clicks.
· Encryption in transit and at rest, and role-based accessrights follow the job: an after-sales technician opens site files, not distribution contracts.
· Hosting in France, under French law, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
· A complete log: who searched for what, when, and what the system returned.
The figure that makes this commercial rather than technical: of your 190 sites still under contract, 34 belong to healthcare establishments or public bodies whose specifications already require hosting in France. The last tender you answered made it a scored criterion — and you ticked “under review”.
What I propose: that I keep up to date the technical sheet your clients ask for at renewal — hosting, subcontractors, retention periods, who accesses what. It costs you three days a year to reconstruct; it will be permanently current, and you will tick “yes” at the next tender. technical-framework_where-your-content-lives.pdfLocal inference, read-only, processing in the EU targeted
✎ Framework · deployment architecture, rights of the technical read account, specifications of the 34 contracts concerned
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

One agent, all your information sources. All these uses work in support, subject to your approval.

Included in your agent The 5 capabilities essential to this promise are included, at no extra cost.
From 708 € excl. VAT / month

Unified search

Questions the intranet, the file stores and the business tools all at once.

Access rights respected

Strictly applies each employee's scope, without ever widening it.

Original location cited

Refers back to the exact source and its date last changed.

Business document management

For a large, versioned body of business documents, a dedicated agent takes it on.

Internal FAQ

For employees' everyday questions, a dedicated intranet agent takes over.

Controls and safeguards These 4 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Explicit handling of questions with no answer and of conflicting sources Inherited access rights, versions and freshness of the corpus
What the agent must be connected to This connection is required for the agent to work. It concerns your information system and is scoped during the audit.
Measurement of accuracy, coverage and time saved

Need to go further?

These agents handle a different business process, with their own owner and their own price. They are added to this one.

Does your need fall outside this?

In 15 minutes we identify the most relevant agent — without oversizing the project.

Book the free audit Build your agent
The gain

How much time does a company spend looking for what it already knows?

By unifying the search, the effort shifts towards using the information found. How large the gain is depends on your volume and remains to be confirmed by a pilot.

Searching source by source
Today · done by hand
Unified search
Identifying the original location
Today · done by hand
Location cited
Asking a colleague to find a document
Today · done by hand
Answered without help
Indicative figures, not contractual, to be confirmed by a pilot on your number of sources connected and users. The agent never opens an access: widening an employee's scope rests with the administrators of each space.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One package, one agent

A knowledge management agent (multi-source, rights, traceability), installed and operated for you.

Agility

Setup + controlled subscription

8,105 € excl. VAT setup
then 708 € excl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

1,158 € excl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

11,780 € excl. VAT setup
then 905 € excl. VAT/month · + hardware from 2,491 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices exclude VAT.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter to your body of information

Your internal content stays with youLocal inference or an isolated resource hosted in France; no content entrusted to a third party, no data used to train a model.
Data in France, under French lawAll of your internal content: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
Your teams keep the decisionThe agent produces a unified search across all your sources, which can be checked and altered; no approval is automated.
Human oversight & traceabilityOn your number of sources connected and users: systematic logging and tracking, in line with the AI Act.
Frequently asked questions

Your questions, our answers

Can an employee see more than usual?
No. The agent applies the existing access rights exactly: it shows nothing that is not already accessible to the person asking.
What sources can it connect to?
Intranet, file stores, business tools and common workspaces. The list is settled with you at the design stage.
Are the results traceable?
Yes: every result states the source, the exact location and the date last changed, and every search is logged.
Does the agent change documents?
No. It works read-only on the sources connected.
Do we have to learn a new tool to use it?
No. Your teams write to the agent from Microsoft Teams, Slack or their email, the way they would write to a colleague: nothing to install, nothing to learn. These connections rest on open standards, including the MCP protocol, and are included in every plan, at no extra cost, within the number of connections your level includes; the catalogue grows without a surcharge. You supervise the agent from a web dashboard.
Is our content protected?
Yes. The agent is hosted in France, on local inference or an isolated resource, with the deployment objective of processing and access operated within the European Union and an architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity. Your content is not used to train a third-party model.
How long does it take to deploy this agent?
A few months as a rule, depending on the number of sources to connect and how fine-grained your access rights are, after a free audit then phases of design, integration and testing.
Let's talk

Let's size up the potential in your company knowledge

15 minutes to frame your sources and your access rights — hosted in France, supervised, with no commitment.