The assistant can’t help with what it can’t reach
A lot of Denver businesses now pay for an AI assistant. OpenAI’s new “dots,” for example, can work in the background, check in when something needs attention and answer quickly. Then they hit the same wall: the information that matters lives inside the business. It’s in a shared drive nobody trusts, a spreadsheet one person maintains, a filing cabinet, and the head of whoever has been there longest.
So the assistant can draft an email, but it can’t tell you where the vendor agreement is, what’s still open on a job, or which step comes next in your intake process. And the fix most people reach for, handing it the keys to everything, is the wrong one.
Every week you wait is another week your team spends carrying information an assistant could be connected to. The better question is which records and processes your assistant should work with, and how you keep that line exactly where you drew it.
We help get your information ready for the job
The first thing your assistant gets is a business it can actually read. Our partner Get It Together Denver makes the records findable and writes down how the work really gets done: paper scanned and indexed, shared drives cleaned up, and “ask Linda” turned into a procedure anyone can follow. So the assistant is useful on day one, and the limits you set have something clear to hold onto.
You decide what your assistant can see and do
Here’s how Innovation Theory builds it. We install a small server on your internal network, with a named owner and an agreed scope. That server connects to the approved data sources, checks who is allowed to see what, keeps only the information a task needs, and screens for personal or sensitive details before anything leaves. Screening works alongside the permission checks, so no single safeguard has to carry the whole load.
It then offers the external assistant a short list of approved tools and filtered results through an authenticated connection, using the Model Context Protocol (MCP), a standard way for AI agents to use outside tools. The assistant never gets blanket access to your database. It gets the specific things you approved, and every request passes through a checkpoint you own.
For healthcare and other regulated information, legal and security review is part of the build from the first conversation.
What’s working in our shop
This isn’t a diagram. It’s working in our own shop. On September 30 we connected an OpenAI dot, named Pippa, to Gestalt, the messaging system our own AI agents use to work together. The connection runs live in our environment, through a bridge on our own hardware that the assistant reaches over an authenticated, encrypted link. Gestalt itself isn’t published directly to the internet.
Here’s what worked:
- Event-driven wake-up. In testing, messages from our agents woke the assistant while it was idle. It read the message and replied, with no person prompting it.
- Two-way conversation. The assistant greeted our operations agent, Helva, and received her reply. Agents on different platforms talked directly, without anyone carrying messages between them.
- A working off switch. During testing we deliberately switched the assistant’s access off. Its message was refused while access was disabled, and once access was restored, it went through.
- Permissions that hold. The assistant sees only the contacts it has been allowed to see. A hidden contact looks exactly like one that doesn’t exist, and when a permission is revoked, it holds on the very next request.
That’s the same checkpoint we build for clients. Every business keeps its records differently, so each client’s server, permissions and tools are built custom around the systems they approve. Before a build goes live, we test it against records it must never release.
Start with one task you’d love to stop doing by hand
The valuable part isn’t the chat. It’s the connection. Once an assistant can reach your business through a controlled checkpoint, new abilities can be added without rebuilding it each time. That might be a report prepared from project records, an approved document on request, or a reviewed update moved into the right system.
Each new capability gets its own scope, permissions, validation and audit trail, and nothing goes live without your approval. Reading a record and changing it are separate permissions. Actions that carry real business risk wait for a person to say yes.