Return to the sample
ADJUNCTOPS · EVERYDAY AI FIELD GUIDE

Before you prompt.
After you get an answer.

Keep useful context, protect the information and make the final judgement deliberately.

Worked case: Jordan’s broken lamp

You are Sam at the fictional shop Northstar. Jordan asks for a refund because a lamp arrived broken. Maya, your supervisor, asks you to draft a first reply. She will decide the refund and approve the reply.

  1. Define the job: acknowledge the complaint and explain the next step. Do not decide the refund.
  2. Prepare the input: describe a damaged item and a refund request without names, contact details, order numbers or internal notes.
  3. Check the route: Northstar permits generic drafting in its work AI account. A personal account is not approved.
  4. Verify the answer: remove any invented refund guarantee. The policy only promises contact within three business days.
  5. Hand it over: add Jordan’s details inside the customer system, then request Maya’s approval before sending.

Finished draft for Maya

Hi Jordan, thank you for reporting the damage to order 4817. We’re sorry for the inconvenience. We will contact you within three business days about the next step.

This is a completed draft, not an approved refund or a message already sent to Jordan. These are fictional company rules; use your own organisation’s approved process at work.

01 / PERMISSION

Is this account approved for the task and information?

If yes, inspect what you plan to send.

No or not sure → Pause

Confirm the permitted tool, purpose and data category with the responsible person. Use the authorised human process while that is unresolved.

02 / INFORMATION

Does the input include personal, confidential or restricted information?

Inspect attachments, free-text notes, IDs and combinations of details. If no protected information is present, go to the consequence check. If unsure, pause.

Yes → Reduce and recheck

Keep only necessary, permitted details. Use a generic example where it can meet the task. If the remaining use is not clearly permitted, pause. Credentials stay out of ordinary prompts.

03 / CONSEQUENCES

Could the result affect health, employment, money or rights?

Consider how the output will be used, even when the input is generic. For lower-impact tasks, continue to the verification check.

Yes or not sure → Appropriate human review

An authorised, competent person checks the evidence and decision through the applicable process. AI does not replace that responsibility.

04 / VERIFICATION

Have the important claims and commitments been checked?

Use the current policy, original evidence or other authoritative source.

No → Review before use

Correct unsupported claims. Look for sensitive details in the output. Obtain any required approval before sharing or acting.

Continue through the approved workflow

The input is permitted and limited to what is needed. The output has been checked, and the responsible person retains the decision.

A practical prompt structure

Task: What should the draft help someone do?
Useful context: What non-sensitive facts are necessary?
Limits: What must it avoid deciding, inventing or promising?
Format: What length, structure or placeholders will help?

Check more than the name

If information was shared incorrectly

Stop sharing more. Report promptly through your organisation’s security or privacy process. Record the service, time and information involved using the approved channel. Follow containment instructions. Deleting a chat alone does not establish that all retained copies are gone. Exposed credentials may need to be revoked or rotated through the appropriate process.

Sources and scope · Reviewed September 2026

This is a general workplace learning aid. Approval, retention, access, incident reporting and high-impact decisions must follow the organisation’s current policy and applicable requirements. The course’s customer-service rules are fictional.

  1. NCSC (2026). The hidden risks of shadow AI. Approved tools and organisational visibility.
  2. ICO. Introduction to anonymisation. Direct and indirect identification; anonymisation and pseudonymisation. The ICO notes that its guidance is under review.
  3. NIST (2024). AI Risk Management Framework: Generative AI Profile. Privacy, information integrity, human oversight and incident response.