n8n Multitenant RAG Chatbot

A per-tenant RAG chatbot over each client's own documents, answered with cited sources and strict isolation.

A per-tenant RAG chatbot that lets each client ask questions over their own documents, reports and onboarding material, answered by a large language model with cited sources. Each tenant's content lives in an isolated vector index so one client can never see another's data at the query level, a multi-layer prompt-injection guard protects the system prompt, and a per-tenant cost cap keeps spend predictable. It works across WhatsApp and a web widget, and answers carry a source footer so they read as grounded, not guessed.

$15 one-time
Add to a kit →

Prices include 20% VAT. · Forged on real agency work · one-time, no lock-in

  • Type Skill
  • Category Automation & Ops
  • Delivery Email · instant
  • License One-time
Run preview
forgehouse, n8n-multitenant-rag-chatbot

Inside the run · no black box

See the actual work before you buy it.

A grounded client bot has to answer from the right documents and only the right documents. This pipeline isolates, retrieves, guards and cites:

  1. Chunks each client's documents and stores them in a vector index keyed to that tenant
  2. On a question, retrieves the top matching chunks with a mandatory tenant filter enforced in the database query
  3. Passes only those chunks to the language model and generates an answer with a source footer
  4. Runs a multi-layer prompt-injection guard so the system prompt and isolation cannot be overridden
  5. Serves the answer over WhatsApp or a web widget and meters usage against a per-tenant cost cap
Use cases · what happens when you plug it in

One power source. 6 lines out.

n8n-multitenant-rag-chatbot · core

core active · 6 lines

  1. Giving clients a 24/7 first-line bot over their own reports and docs

    ✓ giving clients a 24/7 fi…
  2. Answering how a client ranked last month without re-reading a document

    ✓ answering how a client r…
  3. Letting customers self-serve over contracts, audits and onboarding files

    ✓ letting customers self-s…
  4. Adding a grounded Q&A layer to a content-heavy product or course base

    ✓ adding a grounded q&a la…
  5. Isolating each tenant's knowledge so data never crosses clients

    ✓ isolating each tenant's
  6. Offering chat answers with cited sources to reduce hallucination risk

    ✓ offering chat answers with
Benefits · what you walk away with

Yours to keep.

Drag time forward. Watch what stays.

Forever

That's what owning means.

The rented stack

ai writing tool: subscription

expired · access lost

analytics suite: subscription

expired · access lost

design platform: subscription

expired · access lost

(nothing left)

Your forge

  1. Clients get instant answers grounded in their own documents

    license: perpetual
  2. Strict tenant isolation keeps one client's data invisible to another

    license: perpetual
  3. Cited sources make answers feel trustworthy, not invented

    license: perpetual
  4. A per-tenant cost cap keeps spend predictable

    license: perpetual

subscriptions expire · deeds don't

What's included · the full manifest

Everything in the box.

Pick a piece up. Watch it work.

Document chunking and a vector index per tenant

part 01 of 06 · in the box

6 parts · one working system · ships instantly by email

Who it's for

This wasn't forged for everyone.

  • Not for you if you'd rather rent a tool than own one.
  • Not for you if you want someone else to run your stack.
  • Not for you if you're happy guessing.
Still here? Good.

Service businesses with document-rich client relationships who want a grounded, isolated, cited Q&A bot per client.

then this was forged for you.

Works with

Universal by design: these run in any AI. Delivered in the open Agent Skills + MCP format (native in Claude); ChatGPT, Gemini, Cursor and Copilot adapt the same files their own way.

  • Claude Native format
  • ChatGPT Adapts via open standards
  • Gemini Adapts via open standards
  • Cursor Adapts via open standards
  • Copilot Adapts via open standards
Questions · still in the air

Catch what's on your mind.

the air is clear. nothing between you and the forge.
catch a spark: the forge will answer

  1. Can one client's bot ever see another client's data?

    No. Isolation is enforced at the database query level with a mandatory tenant filter, so retrieval can only ever return the asking tenant's own documents.

  2. What stops it from making things up?

    Answers are generated only from the retrieved documents and carry a source footer pointing to where they came from. A multi-layer guard also blocks prompt-injection attempts to override that behavior.

  3. When is a bot not worth it?

    When a client has very few documents or asks only a handful of questions a month. Below that, a manual reply or an FAQ page is faster and the bot has no real return.

  4. How is it delivered?

    By email right after purchase: ready to run, downloaded instantly, no setup wait.

  5. One-time or subscription?

    A one-time purchase; no subscription or hidden fees. VAT (20%) is included.

  6. Can I get a refund?

    As a digital product, it can’t be refunded once downloaded. That’s why we show exactly what’s inside and who it’s for, right here.