Before you prompt.
After you get an answer.
Keep useful context, protect the information and make the final judgement deliberately.
Worked case: Jordan’s broken lamp
You are Sam at the fictional shop Northstar. Jordan asks for a refund because a lamp arrived broken. Maya, your supervisor, asks you to draft a first reply. She will decide the refund and approve the reply.
- Define the job: acknowledge the complaint and explain the next step. Do not decide the refund.
- Prepare the input: describe a damaged item and a refund request without names, contact details, order numbers or internal notes.
- Check the route: Northstar permits generic drafting in its work AI account. A personal account is not approved.
- Verify the answer: remove any invented refund guarantee. The policy only promises contact within three business days.
- Hand it over: add Jordan’s details inside the customer system, then request Maya’s approval before sending.
Finished draft for Maya
Hi Jordan, thank you for reporting the damage to order 4817. We’re sorry for the inconvenience. We will contact you within three business days about the next step.
This is a completed draft, not an approved refund or a message already sent to Jordan. These are fictional company rules; use your own organisation’s approved process at work.
Is this account approved for the task and information?
If yes, inspect what you plan to send.
Confirm the permitted tool, purpose and data category with the responsible person. Use the authorised human process while that is unresolved.
Does the input include personal, confidential or restricted information?
Inspect attachments, free-text notes, IDs and combinations of details. If no protected information is present, go to the consequence check. If unsure, pause.
Keep only necessary, permitted details. Use a generic example where it can meet the task. If the remaining use is not clearly permitted, pause. Credentials stay out of ordinary prompts.
Could the result affect health, employment, money or rights?
Consider how the output will be used, even when the input is generic. For lower-impact tasks, continue to the verification check.
An authorised, competent person checks the evidence and decision through the applicable process. AI does not replace that responsibility.
Have the important claims and commitments been checked?
Use the current policy, original evidence or other authoritative source.
Correct unsupported claims. Look for sensitive details in the output. Obtain any required approval before sharing or acting.
Continue through the approved workflow
The input is permitted and limited to what is needed. The output has been checked, and the responsible person retains the decision.
A practical prompt structure
Task: What should the draft help someone do?
Useful context: What non-sensitive facts are necessary?
Limits: What must it avoid deciding, inventing or promising?
Format: What length, structure or placeholders will help?
Check more than the name
- Contact details, record numbers and other direct identifiers
- Small groups, unique roles, locations and unusual events
- Private notes, financial details and confidential business facts
- Attachments, copied chat history and unnecessary source files
If information was shared incorrectly
Stop sharing more. Report promptly through your organisation’s security or privacy process. Record the service, time and information involved using the approved channel. Follow containment instructions. Deleting a chat alone does not establish that all retained copies are gone. Exposed credentials may need to be revoked or rotated through the appropriate process.
This is a general workplace learning aid. Approval, retention, access, incident reporting and high-impact decisions must follow the organisation’s current policy and applicable requirements. The course’s customer-service rules are fictional.
- NCSC (2026). The hidden risks of shadow AI. Approved tools and organisational visibility.
- ICO. Introduction to anonymisation. Direct and indirect identification; anonymisation and pseudonymisation. The ICO notes that its guidance is under review.
- NIST (2024). AI Risk Management Framework: Generative AI Profile. Privacy, information integrity, human oversight and incident response.