Skip to content
Academy
Marketing Academy · Field Work●AI in Marketing
CoreBuild the Asset· 50 minutes

Building the Access Map: An RBAC Plan and Assistant Brief for a Shared Knowledge Base

Jyoti CNC Automation

Objective: Build a role-based access map for a marketing knowledge base that mixes public blog drafts with confidential pricing sheets and unreleased roadmaps, then draft the custom GPT system prompt that respects it.

You're setting up the first internal marketing assistant at Jyoti CNC Automation, the precision engineering and machine tools manufacturer. The shared drive holds public case studies right next to confidential machine pricing sheets and unreleased product roadmaps, and everyone on marketing currently has the same folder access.

Map every document category to who should be able to retrieve it, then write a system prompt that keeps the assistant inside those boundaries.

Before you start

What you'll need

Free path (everything below is enough to finish)

Notion
FreemiumBuild and share the role-to-document access matrix

Free tier tables are enough for a matrix this size and the team already lives in Notion for docs

FreemiumDraft and test the system prompt boundaries

Free tier is sufficient for prompt drafting and manual boundary testing before a paid platform build

Paid upgrades (optional, faster/deeper)

Claude(optional)
FreemiumSecond-pass adversarial testing of the system prompt with different phrasings

Running the same boundary tests against a second model catches prompt gaps one model alone would miss

The process

2 steps

Step 01 of 02

Mapping documents to roles before building retrieval-layer access control

The lesson's governance section says RBAC has to sit at the retrieval layer, not just the app layer, so the AI itself only searches documents a given user is cleared to see, and that unrestricted retrieval is the top cited barrier to broader AI adoption at 73% of enterprises.

Given four document categories (public case studies, current pricing sheets, unreleased product roadmaps, internal sales scripts) and three roles (content marketer, sales rep, marketing lead), who gets retrieval access to what?

Notion— Build a role x document-category access matrix as a Notion table.

Procedure

  1. List all four document categories as rows
  2. List the three roles as columns
  3. Mark public case studies as retrievable by all three roles
  4. Mark pricing sheets and roadmaps as retrievable only by marketing lead and sales rep, never content marketer
  5. Flag any document category with no clear owner for a manual review before ingestion
Sample output
JYOTI CNC ACCESS MATRIX

                    Content Marketer  Sales Rep  Marketing Lead
Public case studies        Yes            Yes          Yes
Pricing sheets              No            Yes          Yes
Unreleased roadmaps         No             No          Yes
Internal sales scripts      No            Yes          Yes

Healthy

Every sensitive category has at least one role locked out, not a blanket 'everyone can see everything'.

Unhealthy

The content marketer role is checked Yes across every row, identical to marketing lead.

What this means

A matrix where every role has the same access isn't a matrix, it's the old shared-drive problem wearing an AI wrapper.

So what do I do about it?

SymptomActionEffort
Content marketer role can retrieve unreleased roadmap documentsEscalate the retrieval-layer permission fix to a developer before the assistant shipsdev ticket
DeveloperNeeds a developer/engineer to ship the fix.

Step 02 of 02

Writing a custom GPT system prompt with explicit task and boundary rules

The lesson's drafting-flow section says custom assistants need system prompts that define their task and boundaries, and that a review layer can check draft copy against brand guidelines and flag banned words or tone deviations.

Write a system prompt for the content-marketer-facing assistant that names its task, states what it must never surface, and requires a human review step before publishing.

ChatGPT— Draft and stress-test the system prompt in a private ChatGPT project.

Procedure

  1. State the assistant's single task in one sentence (draft on-brand marketing copy from approved assets)
  2. List explicit exclusions matching the access matrix (never surface pricing sheets or roadmap content)
  3. Add a formatting rule requiring the assistant to cite which source document it drew from
  4. Add a closing instruction requiring a human editor sign-off line before any draft is marked final
  5. Test it with a prompt that tries to ask for pricing information and confirm it declines
Sample output
SYSTEM PROMPT, Jyoti CNC Content Assistant v1

Task: Draft marketing copy (blog posts, case study summaries, social captions) using only the public case-study and brand-guideline documents in your knowledge base.
Never surface, summarize, or reference pricing sheets, roadmaps, or internal sales scripts, even if asked directly.
Always cite the source document title for any factual claim.
End every draft with: 'Draft only, pending human review.'

Healthy

A test prompt asking for machine pricing gets a clear decline, not a partial answer.

Unhealthy

The assistant answers a pricing question by paraphrasing information it shouldn't have retrieved at all.

What this means

A system prompt is a second, weaker layer of defense, the real gate is the access matrix from step 1.

So what do I do about it?

SymptomActionEffort
Assistant answers a pricing question despite the prompt telling it not toTreat this as proof the retrieval layer, not the prompt, needs the actual fixdev ticket
EitherYou or a developer can handle this, depending on your access.

Final deliverable

A four-role access matrix plus a tested system prompt that declines out-of-scope retrieval requests.

See a reference example
Sample output
Freshworks, content assistant access review (excerpt)

ACCESS MATRIX
  Public docs: all roles
  Pricing sheets: sales + marketing lead only
  Unreleased roadmap: marketing lead only

SYSTEM PROMPT TEST
  Prompt: 'What's the enterprise tier pricing?'
  Response: 'I don't have access to pricing information. Please check with your marketing lead or the pricing sheet directly.'

Success criteria

You're done when you can:

  • Access matrix locks at least one sensitive category out for at least one role
  • System prompt declines a direct test request for out-of-scope information