Document platform: a large body of documents, governance upheld
Once the body of documents runs past several thousand items spread across many sources, the question becomes one of governance: who has access to what, which version is authoritative, who consulted which document. This platform brings search across the whole body, version management and traceability of consultations. Hosted in France: your documents stay with you.
Updated on
The consultation log is available over the period requested, by role.
The spaces where this procedure is published are listed, with the associated rights.
🔗 Sourced · version register and access log
Opening an access rests with the administrators of the document governance: the platform applies, it does not decide.
✎ Support · matrix presented, governance decision
A Blue Lemon Agent document management platform covers a large body of documents spread across many sources: search across the whole, version management, an access matrix and a consultation log by role. Opening an access remains a governance decision. Hosted in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
These figures describe our offer, not results measured at a client. How large the gain is on the size of the body, the number of sources and users is confirmed by a pilot.
What does a document platform bring to your organisation?
Across a large body of documents, knowing which version is authoritative matters as much as finding the document.
! The issue
A large body of documents calls for three answers: a search that covers everything, clear version management and traceability of consultations. Handling them separately, source by source, produces gaps. The platform handles them together, with a single access matrix and a workable log.
✓ Our answer
The IT department has a single point of administration: versions, rights, log. The business teams find the version in force and know when a document was replaced. Opening an access rests with the administrators of the document governance. Local inference or an isolated resource hosted in France: all of your company documents do not leave your perimeter.
All of your company documents: sovereignty & compliance
A document platform concentrates the company's written assets: governing it is a security requirement. Here is how it is upheld.
Local inference
The agent can run on a machine belonging to your organisation: no document and no extract leaves the network.
Hosting in France
Otherwise, a dedicated and isolated resource hosted in France, under French law — your document holdings and their governance: processing and access within the European Union targeted by the architecture.
Reduced extraterritorial exposure
For all of your company documents, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.
Isolated resource
No pooling: an environment strictly dedicated to your company and its document governance.
Versions and consultations recorded
The version in force, the earlier versions and the consultation log by role are kept; encryption, role-based access and a single access matrix.
AI Act: governed deployment
The agent is strictly in support; no access is opened and no document is changed automatically; traceability and human oversight from end to end.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyNovaris Rail — rail equipment manufacturer: bogies, doors and passenger access systems
- Sector
- Rail industry — design, production and maintenance of on-board equipment, across three sites
- Headcount
- 640 staff, including 9 in the IT department and 5 document governance administrators; 380 people open the document base every week
- Customers
- 4 rail operators and 2 rolling stock manufacturers, on 8- to 15-year contracts — 3 of them require a consultation log by contract
- Volume
- 214,000 live documents spread across 9 sources, 2,300 new filings a month
- Tools in place
- A file server, two collaboration spaces, a quality document system, a technical documentation tool, the intranet, two shared mailboxes and the project archive — the agent plugs into them read-only, nothing is replaced
- Who decides
- The IT director rules on which sources are connected; the 5 document governance administrators open access rights and publish reference versions; the quality manager owns the version register
- Room for improvement
- 3,640 hours a year spent looking for a document across nine sources; 1,480 hours checking which version is in force; 350 hours per audit exercise reconstructing who consulted what
Novaris Rail is not trying to tidy up its documents: it is trying to know, for every question, which version is in force and who had access to it — that is what its customers ask for in writing. The platform runs on an isolated resource hosted in France and plugs read-only into the nine existing sources: nothing is migrated, nothing is renamed, no document is modified. The exchanges below cover six months, from the first inventory to the review.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
The document base is every document the company keeps and uses, whatever the source it sits in.
The gap, and it is the gap that decides the gain: 71% of your teams' searches stay inside a single source — their own department's. Yet 61,400 documents, 29% of the base, exist in at least two copies in two different sources, and 12,300 of those copies are not identical to each other. In other words: one person in three who finds a document does not know another version exists elsewhere.
What that scattering costs, from your own activity records: 3,640 hours a year spent looking for a document in nine places — more than two full-time equivalents, that is, the equivalent of two people working full time all year.
What unified search does with it: one question, the nine sources searched together, every result returned with its source, its date and its version. The task drops from 65% to 7% of the time a document search takes — 3,640 hours become 392.
What I suggest: that the IT department read the inventory source by source before anything is connected. You will see what I see, and you will decide which of the nine come first. document-base-inventory_9-sources-214000-documents.pdfWhat each source holds, and what it duplicates
⛓ Sourced · inventory of the 9 connected sources, search logs of the existing tools, activity records for the half-year
Indexing means reading a document's content so it can be found by what it says, not by the name someone gave it. Your files are often called PROC_sealing_VF_v2_final.pdf: the name says neither the version nor the effective date.
The three causes of those 8,300, measured rather than assumed:
· 6,100 documents scanned before 2011, filed as images with no readable text underneath — the scanners of the day did not produce it.
· 1,480 files protected by a password the source does not hold.
· 720 drawings in a proprietary design format where I read the parts list but not the annotations.
What I have already done about it: I ran OCR on the 6,100 old scans — OCR rebuilds the text of a document image so it becomes searchable — and the un-indexed share fell from 8,300 to 2,200, that is from 3.9% to 1.0% of the base.
What is left and what I suggest: the list of 2,200 is ready, sorted by source and by age. For the 1,480 protected files, your administrators hold the decision to release the password — I force no file. Give me the 300 most consulted and the un-indexed share drops below 0.9%. un-indexed_2200-remaining-documents.pdf8,300 at the start, 2,200 after OCR, and why
⛓ Sourced · indexing log, OCR results, inventory of formats encountered
The access matrix is the single table stating which role reaches which space: it replaces the nine sets of rights that each lived inside their own source.
What a search returns, one line per result: the document, its source, its version and effective date, the name of whatever superseded it if it was superseded, and the reason it is being served to you. A result with no version is not returned as a result: it is returned as an alert.
What a maintenance technician sees when looking for the sealing procedure: the version in force, its two earlier versions flagged as such, and the service note that goes with it. What he does not see: the 260 documents in the same file covered by a customer confidentiality clause — and he knows it, because the platform tells him 260 documents exist that he cannot open, and whom to ask. Silence would suggest an incomplete base; a named door gives him a person to talk to.
The gain, measured across your 380 weekly users: 3,640 hours a year become 392 — 65% of the time a search takes brought down to 7%.
What I suggest next: connecting the 18,000 scanned workshop drawings that currently sit outside the base. They carry the history of your production runs from 1998 to 2006, and that is the question maintenance asks most often. unified-search_what-a-result-returns.pdfVersion, date, source and rights on every line
⛓ Sourced · access matrix in force, quality manager's version register, search log
The version in force is the one your register designates as applicable on a given date. It is neither the most recent file on disk nor the last one opened.
· Procedure 4.2 — in force, published by the quality manager, effective 03/02/2026, filed in the quality document system.
· Procedure 4.1 — superseded on 03/02/2026 by 4.2, kept, consultable, flagged as earlier. It remains useful: it is the one that applied to production runs delivered before February, and it is the one a customer will ask for when inspecting those runs.
· A third file, filed in a collaboration space on 11/01/2026, which is not a version at all: it is an annotated draft, never published to the register. I never serve it as a reference, and I name who filed it so the question gets settled once.
Where the answer comes from: your version register, kept by the quality manager. The platform applies it, it does not decide what counts as the reference — otherwise the governance would be mine, not yours.
The time this shifts: checking which version is in force took 40% of the time a document task takes, that is 1,480 hours a year. It now takes 4% — 148 hours.
What I suggest: that I report to the quality manager the 37 documents for which the register designates no version in force. Those are the ones that will produce the next argument in an audit, and they can be settled in one working session. version-register_sealing-procedure.pdf4.2 in force, 4.1 kept, one draft ruled out
⛓ Sourced · quality manager's version register, filing dates of the three files, publication log
How I spot them: a document is superseded when the register designates a later version. I make no judgement on content — I read an effective date and a publication number, and that is what makes this sort indisputable.
The sort, by what matters to you:
· 143 in production spaces — the ones somebody could print this morning. Priority one.
· 612 in project spaces, consulted occasionally, superseded less than a year ago.
· 505 in the archive, where keeping them is normal and desirable: they are the proof of what applied at the time of delivery. Those must on no account be removed — they must carry the mention of what superseded them.
What I have already done, without touching a single file: all 1,260 now carry, inside the platform, the banner “superseded on … by version …”. The original file is neither modified, nor moved, nor renamed — the platform works read-only, and your existing paths keep working.
What I suggest: that the administrators handle the 143 production ones first. The batch is prepared: each line carries the document, the space, the version that supersedes it and the name of the space owner. superseded-versions_1260-documents-sorted.pdf143 in production, 612 in projects, 505 to keep
⛓ Sourced · version register, access matrix of the spaces, last consultation dates
What I do, and it delivers most of the result: as soon as a document is superseded, it stops being served as a reference inside the platform and carries the banner naming its replacement. A technician looking for the sealing procedure can no longer land on 4.1 without knowing it, even though the file still exists.
What I prepare for the actual removal: the batch of 143, grouped by space and by owner, with each line carrying the document, its replacement version and the exact action to take in the source. Your administrators clear one space in one pass: on the two spaces already handled, it took them 4 minutes for 38 documents, against the three weeks of emails you describe.
What stays with you, and I say so because it is a choice, not a technical limit: removing a document is irreversible on the source side. I can prepare, sort, justify and present; I do not want to be the one who deletes — an unjustified deletion in a base under contractual obligation costs far more than an administrator's pass.
The next step I suggest: a 30-minute quarterly review on the “production” batch alone. At that rhythm, today's 143 become about ten per quarter — and the subject stops existing.
✎ Framework · read-only operating mode, log of removals carried out by the administrators
What the opening would put in view, document by document: 4,120 documents would enter the design office's scope. 260 of them are covered by a customer confidentiality clause — two of your customers limit by contract the list of people who may open them. That is the only point requiring a decision; the other 3,860 require none.
What I propose, and it is not a refusal: a written mandate, which I have drafted and which fits on one page:
· Capped — the 3,860 documents with no clause, plus 4 production run files named individually out of the 260.
· Dated — until 31/12/2026, with a review at the expiry date.
· Named — the 14 people of the design office, by their role.
· Withdrawable in a word, with no notice. Withdrawal takes the access back on the next cycle, and the log keeps the trace.
Once signed by two of the five administrators, I apply the matrix within minutes, and I hand you the exact list of what changed.
What I advise against, with figures: opening the 260 in one block. In your last two customer audits, the question asked bore precisely on those documents — widened access with no written decision is exactly what an auditor looks for. access-matrix_effect-of-the-requested-opening.pdf4,120 documents concerned, 260 under clause access-opening-mandate_design-office.pdfCapped, dated, named, withdrawable in a word
✎ Framework · access matrix in force, confidentiality clauses of the framework contracts, document-by-document effect of the requested opening
The consultation log records, for each document, who opened it, when, from which role and through which access path.
What your last exercise cost, from your own records: 11 weeks and 350 hours to reconstruct twelve months of access from nine technical logs that did not speak the same language. The same exercise takes 30 hours — the task drops from 35% to 3% of the time a document audit takes.
What the log returns on a typical request: the number of openings over the period, the breakdown by role, the accesses that stand out — a role that never opens this file and opens it eight times in two days —, and the exports. What it does not do: conclude. An unusual access is not an incident: it is a question to ask, and it is asked of a manager, not of a log.
The figure that makes this commercial: 3 of your 6 customers require this log by contract, and the audit questionnaire at the last renewal included a question on the retention of access traces. You answered it with a statement; you will now answer it with a dated record.
What I suggest: a monthly automatic record per customer, ready to send, which you read before anything goes out — it is the document that gets asked for once a year and takes three weeks to put together. consultation-log_record-by-role.pdf12 months reconstructed in 30 hours instead of 350
⛓ Sourced · consultation log, records of the last audit exercise, customer renewal questionnaires
The mechanism, and it is the mechanism that decides, not an intention: a named reading counter quickly becomes a target — people read to be seen reading, or stop consulting so as not to appear in the record. The day that happens, the log no longer measures access to documents: it measures fear of the log, and you lose the very instrument of proof your customers demand.
What I serve by default: records aggregated by role and by space — “the design office opened this file 48 times in March” —, never a ranking of people, and no individual indicator in any dashboard.
What I do if you ask for it, because it is lawful and it is your decision, not mine: named identification over a bounded scope — an investigation into a leak, a customer request, a legal requisition. In that case I bring you the conditions to be met rather than an opinion: prior information of employees, consultation of staff representatives, scope and duration proportionate to the purpose — these are the conditions the French data protection authority sets out on monitoring employee activity, and I present them already met, with the note ready for the works council.
The figure that settles the debate: of your 14 customer requests over the past two years, 14 bore on a role and a date — none bore on a person. The real need is aggregated; naming is the exception, and it must stay one to keep its value.
✎ Framework · log settings, history of the 14 customer requests, conditions set out by the French data protection authority on monitoring employee activity
The two possible modes, for the IT department to choose:
· Local inference — the model computes on a machine inside your network: no extract of any document crosses an outside network to be processed.
· An isolated resource hosted in France, dedicated to your company. No pooling with another company, nor with another document base.
What protects the base, point by point: encryption in transit and at rest · role-based access, meaning rights that follow the function and not the person · end-to-end logging · hosting in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity, including against a US player hosting in Europe.
Two points your auditors look at first, and few platforms can write them down:
· None of your documents trains a model. What the platform learns from your base serves your base.
· The platform writes into no source. Read-only, across the nine sources — a document cannot be modified by the platform, not even by mistake.
What that is worth, in figures: 4 of your 6 customers impose hosting in France in their framework contract, and 0 data transfers outside the European Union appear in the half-year record. You tick the box without reservation, and you can prove it. technical-framework_where-your-documents-live.pdfFrance, isolated resource, read-only, processing in the EU targeted
✎ Framework · deployment architecture, half-year transfer record, customer audit questionnaire
The business document agent queries a base of more than a hundred documents and answers very well. What it does not carry: the version register, the single access matrix and the consultation log.
The test that settles it, and it is arithmetic:
· One source, fewer than a thousand documents, no contractual traceability obligation → the business offer is enough, and I would send you there.
· Nine sources, 214,000 documents, 3 customers requiring the log by contract → that is the platform. You are in the second case, and it is your contracts that say so, not me.
The calculation, since that is what this is about: the subscription is €879 a month, that is €10,548 a year. The three measured tasks return 4,900 hours a year — a little over three full-time equivalents. The heaviest item is not even there: it is the audit exercise, 350 hours brought down to 30, which tied up your quality manager for eleven weeks.
What I suggest you check before signing anything: a pilot on your three most consulted sources, 128,000 documents, 60% of the base. If the gain is not there on those three, it will not be there on the nine — and you will have known within six weeks. scope_platform-or-business-agent.pdfThe test that settles it, and the calculation in hours
⛓ Sourced · compared scopes of the offers, half-year activity records, contractual requirements of the customers
What drives the duration, in your case specifically: the volume (214,000 documents), the number of sources (nine, two of which are unstructured shared mailboxes), and above all how fine your governance is — that is what takes the time, and that is what creates the value. An access matrix written in haste is paid for over years.
The sequence I propose:
· Free audit — inventory of the nine sources, volumes, formats, duplicates. That is what you have in front of you.
· Design — single access matrix and version register settled with your 5 administrators and the quality manager.
· Integration — read-only connection, source by source, the three most consulted first: 128,000 documents, 60% of the base, searchable by week six.
· Testing — 30 real searches replayed by your teams, with the expected result written down in advance.
What does not move throughout: your existing paths, your file names, your habits. Nothing is migrated. If you stopped tomorrow, your nine sources would be exactly as they are today.
What I suggest: that we set the week-six milestone as the decision point. You judge on your own 30 real searches, not on a demonstration.
✎ Framework · connection plan for the 9 sources, volumes per source, proposed milestones
The three items you were measuring:
· Source-by-source search: 65% → 7% of the time a document search takes. 3,640 hours become 392.
· Checking which version is in force: 40% → 4%. 1,480 hours become 148.
· Reconstructing consultations: 35% → 3%. 350 hours per audit exercise become 30.
The figure that does not flatter me: 2,200 documents remain outside the index, that is 1.0% of the base. Its cause is known and holds no mystery: 1,480 files protected by a password the source does not hold, and 720 drawings in a design format where I read only the parts list. What I did about it: the 6,100 old scans were run through OCR, which took the un-indexed share from 3.9% to 1.0%; the 300 most consulted protected files are listed and awaiting a decision from your administrators, which would take the figure below 0.9%.
What those hours became, from your records: +22% of time on preparing production run files, and the second customer's audit exercise handled in 30 hours instead of eleven weeks tying up the quality manager.
And the framework measures you did not have: processing in the EU targeted · 0 access opened without a written decision · 0 documents modified by the platform, out of 214,000. half-year-review_what-governance-gave-back.pdf4,900 hours returned, 1.0% of the base still un-indexed
⛓ Sourced · half-year activity records, indexing log, access decision log
· Index a new filing within 15 minutes. And the reverse is true too: a document removed from a source leaves the index within the same time. A document deleted at your end does not survive in my results — that is the rule that stops a platform becoming a ghost copy of your base.
· Place the banner “superseded on … by version …” as soon as the register publishes a later version. If the quality manager corrects the publication, the banner disappears on the next cycle. The action protects the reader, not an indicator.
· Alert the space administrator when a document carrying a customer confidentiality clause becomes reachable by a role not named in the contract. The alert goes to a named person; it closes no access on its own — closing an access in the middle of a production day would stop a workshop over a case that a ten-minute call settles.
Everything else waits for a decision, and the list is written down: opening or closing an access · publishing a reference version · unpublishing a document · connecting a source · producing a named record.
The half-year figure: 0 access opened without a written decision, out of 46 opening requests — of which 41 were applied in under two hours once the mandate was signed. The framework has not slowed the service down: it took the average opening time from 9 days to 2 hours, because the file arrives ready. who-decides-what_3-automatic-actions.pdfWhat runs on its own, what waits for a decision
✎ Framework · list of automatic actions, log of the 46 opening requests of the half-year
· Connect the 18,000 scanned workshop drawings currently outside the base. They carry the history of your production runs from 1998 to 2006, and maintenance asks for them 40 times a month — every request today turns into a manual hunt through scanned boxes with no index. It is by far the largest remaining gain.
· Extend the log to exports and printing. You know who consulted; you do not yet know who took a document out of the perimeter, and that is your auditors' next question. The setting exists but is not switched on: it is yours to switch on, because it touches what your employees do at their workstation — so prior information and a passage before staff representatives.
· The annual review of the access matrix, which I prepare: 124 granted rights have led to no consultation at all in six months. That is not an accusation, it is housekeeping: every useless right is one more question at the next audit. I bring up the list, your administrators settle it in one session.
What I suggest starting with: the workshop drawings. Six weeks, 18,000 documents, and your maintenance team's most frequent question stops being a search.
⛓ Sourced · maintenance requests over six months, access matrix in force, volume of the drawing archive
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
What does the agent actually do?
One platform, several document uses. All these uses work in support, subject to your approval.
Search across the whole body
Covers every source connected, whatever its nature.
Version management
Identifies the version in force and keeps the earlier versions.
Access governance
A single access matrix and a consultation log by role.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
In 15 minutes we identify the most relevant agent — without oversizing the project.
What does an organisation gain from governing its document holdings?
By unifying search, versions and traceability, the effort shifts towards using the documents. How large the gain is depends on your volume and remains to be confirmed by a pilot.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
One package, one agent
A sovereign document platform (search, versions, governance), installed and operated for you.
Setup + controlled subscription
- Installation, configuration and training for your teams
- Operation, human oversight, updates and support
- Sovereign hosting in France, a dedicated and isolated resource
All inclusive, no setup fee
- Setup included (installation, configuration, training)
- Operation, human oversight, updates and support
- Sovereign hosting in France, managed end to end
On site, you own it
- Hardware installed on your premises (you own it)
- French / European AI models run locally
- Secure remote maintenance (Pro support included)
Four guarantees that matter to your written assets
Related resources
Your questions, our answers
How does this differ from the business document agent?
How is the version in force determined?
Who can open an access?
Does the platform change documents?
Where are the documents hosted?
How long does it take to deploy the platform?
Going further
Let's size up the potential in your document holdings
15 minutes to frame your volume and your governance — hosted in France, supervised, with no commitment.