fieldcraft 46.7867° N · 92.1005° W
Menu

Field Guide / All guides

What never goes in

Before handing a file to AI, I want three things clear: who is allowed to share it, which account may receive it, and why the task needs it. Removing a name or paying for a subscription does not settle those questions.

What you will leave with

A data decision you can explain before you share a file.

Practice time: about 20 minutes

Separate three kinds of material

  • Suitable starting material: Your published content, approved public templates, and clearly fictional practice data. Still check that you have the right to reuse it and that attachments contain no private comments or hidden details.
  • Needs explicit approval: Internal documents, customer information, employee records, financial details, health information, and material covered by confidentiality commitments. Use only when the data owner has approved the particular tool, account, purpose, and controls. Until then, keep it out.
  • Keep out of prompts and attachments: Passwords, private keys, recovery codes, and other credentials. Use an approved connection or secret-handling process when a system needs authentication. Never share material you are not authorized to disclose.

"Would I send this to a stranger?" can flag discomfort, but it cannot decide whether a managed business tool is approved. Use the actual organizational rule. If no one can explain that rule, work from a fictional example while the owner decides.

Less information can still teach the pattern

Worked example / Fictional practice material

The job: Practice drafting a polite reminder.

Unnecessary input: A full customer ledger, contact details, balances, and account history.

Enough for practice: "A fictional customer has missed an agreed follow-up date. Draft a brief reminder asking them to confirm the next step. Do not add fees or payment instructions."

Deleting names is not reliable anonymization. A distinctive role, date, location, transaction, or combination of facts may still identify someone. Use made-up details for practice rather than assuming a lightly edited real record is safe.

For approved live work, include only the fields needed for that purpose. Check extra spreadsheet tabs, comments, document metadata, email signatures, and attachments before sharing.

Check more than the training setting

Ask the account owner to confirm training use, retention, access, enabled connections, deletion, and the relevant organizational commitments. "Not used for training" does not mean "never stored" or "no one else can access it." OpenAI's business privacy page and Anthropic's commercial data guidance distinguish particular products and conditions; check the terms for yours.

Connected office assistants also make existing sharing permissions matter. Google and Microsoft describe controls around authorized access. A tool being able to retrieve a file is not a decision that this task should use it.

For a first rollout, I recommend a clear output rule: nothing an AI system writes reaches a customer, an employee, a payment, or a public statement before a person has approved it. Record the reviewer and the approval step.

If something goes into the wrong place

Stop the activity and tell the named internal contact promptly. Record which tool and account were involved, when it happened, and the type of material without spreading another copy. Follow your incident process for access changes, deletion requests, and any required notifications. Deleting a chat alone is not evidence that every retained copy is gone.

A useful boundary gives people somewhere to ask before they act and someone to tell when they make a mistake. Make those names easy to find.

Keep this

Before you share a file

Copy this into your own document and fill in the brackets. Use approved or fictional material when trying it with AI.

PURPOSE: [What is the task, and what information does it need?]
MATERIAL: [Public / fictional / internal / sensitive / credentials.]
AUTHORITY: [Who owns it and who approved this use?]
TOOL / ACCOUNT: [Exact approved workspace and enabled connections.]
CONTROLS: [Training, retention, access, deletion, relevant commitments.]
MINIMUM INPUT: [Remove fields and attachments the task does not need.]
HIDDEN CONTENT: [Check comments, tabs, metadata, signatures.]
DECISION: [Proceed within approval / use fictional material / ask owner.]
OUTPUT REVIEWER: [Name and approval step.]
INCIDENT CONTACT: [Name and contact route.]
Download text file

Want help applying this to your organization? Bring the job you have in mind, and we can work out a useful next step.