For months now, every AI automation bro on LinkedIn has been building himself a second brain. Open Obsidian, dump in a few hundred Markdown notes, bolt on a chat, post the carousel. Looks great. Works right up until you actually use it.
In the demo, everything rocks
I get the appeal. You dump your notes into a folder, a plugin turns them into vectors,An embedding turns a piece of text into a long list of numbers. Similar meaning, similar numbers. That’s all the magic there is. and suddenly you’re chatting with your own knowledge. With forty notes it’s genuinely impressive. You ask something, the thing finds the right note, the model writes a nice answer. Screenshot, carousel, “Comment BRAIN and I’ll send you the template”.
It gets interesting three months later.
Because by then there are three hundred notes in there. Meeting notes, half-finished drafts, three versions of the same price list and (my favourite) summaries the AI wrote of notes the AI wrote. Somewhere around 200, 300 entries the whole thing starts to wobble. The search pulls three notes that sound almost the same. One of them is from last year. The model stirs them into an answer that sounds completely convincing. And is wrong.
The wrong answer comes from your own data. So you believe it.
A knowledge store you can’t trust is worse than none at all. Without it, you’d at least have checked yourself.
Call it what it is
Let’s start with the name. Second brain. Sounds like something that thinks along with you. It doesn’t. The thing stores text and searches it, which makes it a knowledge base. Less sexy, I know. But once you call it that, the right questions come up on their own: Where does this entry come from? Is this the current version? And who’s actually allowed to read it?
At hiveo, the knowledge base I built for a client, there’s one rule I don’t negotiate on: whatever the AI writes only goes into the store after a human has approved it. Otherwise you’ve got the Obsidian problem, just with company knowledge. At some point the AI starts quoting itself and treats that as a source.
Your company knowledge isn’t Markdown
Every second brain tutorial assumes knowledge lives in neat .md files. Take a look at the network drive of a mid-sized company. You’ll find contracts someone put on the copier crooked in 2014. Excel lists with seven sheets. PDFs with a table that runs across two pages. An HTML export from the old intranet. And photos of inspection forms filled in with a ballpoint pen.
Before you can search any of that, you need an OCR pipeline that does more than recognise letters. It has to understand headings, columns and tables. If a table turns into running text on the way in, at some point the notice period ends up next to the wrong contract, and nobody notices. On top of that, every chunk has to know which document and which page it came from. Otherwise you can’t verify a single answer.
OCR reads handwriting surprisingly well these days, by the way. I still wouldn’t bet on names and numbers.
And then there’s a bug almost nobody talks about. You update a document, but the old chunks stay in the index and keep getting found. I call them ghost hits. They’re nasty because they look like a perfectly normal answer.
Vectors can’t count
Vector search is great when it’s about meaning. You ask “How do we handle a complaint?” and it finds the right section, even if the word complaint never appears in it. That’s the part everyone shows.
Now ask: “Which maintenance contracts end in 2027?” That has nothing to do with meaning. The answer sits in a table, and a table you’ve chopped into snippets and vectorised isn’t a table anymore. Same with part numbers, names and industry standards. A plain old full-text search finds those better than any embedding.
So I always use both. Text gets vectors and a full-text index, tables stay tables and get queried with SQL. At hiveo, all of it lives in a single Postgres database: tables, vectors, full text, permissions. Sounds boring. It is. And boring here means: you can run it, back it up and still understand it in five years.
Not everyone gets to know everything
In a private Obsidian vault this question never comes up. In a company it comes up constantly. Salaries, personnel files, contracts and the minutes of the last shareholders’ meeting tend to sit on the same drive as the workshop manual.
The fix I see most often: you tell the model in the prompt not to talk about salaries. That’s about as secure as a “please don’t open” note on a safe. Whatever the model has in its context can end up in the answer. Permissions have to kick in before anything is searched. At hiveo the permission check is part of the database query itself. The search only finds what the person asking could open themselves.
Meaning: two people ask the same question and get two different answers. Neither of them notices there would have been more.
Ten thousand documents later
With a hundred documents, almost any search works. Or so I thought. In the first test set for hiveo there were eleven inspection reports for the same machine, identical except for the date. Plus a regulation with nine near-identical tables that simply took every top spot for some questions. With a hundred documents, mind you. With tens of thousands, that’s everyday life.
For that you need a proper retrieval pipeline. Mine looks like this: permissions filter first. Then full-text and vector search run in parallel, and the results get merged. No document gets more than three chunks, so a single regulation can’t clog everything again. And every chunk carries around which document and which chapter it comes from.
And then you measure. Every client has a fixed set of real questions with known answers, and every change has to pass it. One example: it feels like every other RAG tutorial says you need a reranker. I added one and measured. The results got worse, so it got thrown out again. Without measuring, it would still be in there, and I’d feel good about it.
Please don’t build a chat
The classic to finish: the company gets its own AI portal with its own chat window. Three weeks later nobody opens it, because everyone works in ChatGPT or Claude anyway.
That’s why I hook the knowledge base up to exactly those tools via MCP.MCP stands for Model Context Protocol. Anthropic released the standard at the end of 2024, and the big providers speak it by now. People ask where they already ask, and the answer comes back with a source down to the page. One click and the document is open.
Side effect, and honestly my main reason: you’re no longer tied to any provider. Today Claude is ahead, next year maybe someone else. The knowledge base stays where it is, with all its permissions and sources. You swap the model like a printer driver.
So now what?
If you collect notes for yourself: build your Obsidian thing, it’s great. If you want this for a company, you need everything above. Really everything. Otherwise in three months you’ll have the same problem as the Obsidian vault, just with personnel files.
More work than a plugin and a YouTube tutorial, sure. There’s no template for it, by the way. Not even if you comment BRAIN.