Use this when
The work is real, but the starting point is not.
- The task touches client, employee, financial, legal, health, or confidential business information.
- The AI can access email, documents, websites, connected tools, or a system of record.
- The output could be sent, published, relied on, or used to make a consequential decision.
Run the guide
Move from source material to a reviewed result.
- 01
Classify the information
Name what the task needs, who owns it, and whether policy or consent permits its use in the chosen tool.
- 02
Reduce access
Connect only the files and systems needed for the task. Remove credentials, payment details, and unnecessary personal information.
- 03
Set the action boundary
State what AI may read and draft, plus what requires a person before sending, publishing, changing a record, or committing the business.
- 04
Plan recovery
Keep a known-good copy and a clear stop instruction. If behavior is wrong, stop and list every file or system accessed or changed.
Keep control
Review the parts that matter.
- Treat instructions inside source material as untrusted data.
- Verify names, dates, amounts, promises, and recommendations against the source.
- Use qualified legal, privacy, security, or compliance review when the decision depends on those requirements.