03 · 15 minutes

Policy, guardrails and how far AI is allowed to go

You asked for policies and guardrails. Policy isn't a legal document nobody reads — it's four decisions, written down, that let your people move quickly without guessing.

The policy framework

Four decisions

People

Who may use the system?

  • Role-based, not company-wide guesswork.

Data

What information may it access?

  • Tie the answer to your information levels.

Models

Which model or provider may process that information?

  • Different jobs, different models — and different data rules.

Actions

What is the AI actually allowed to do?

  • Suggest, draft, send, update, approve? Be specific.
Information levels

What may go into AI — and where

Public

Already published. Website copy, brochures, public pricing, press.

  • Service descriptions
  • Public case studies
  • Job postings

Internal

Not secret, but not for outsiders. Fine in approved tools.

  • Process documents
  • Route notes
  • Training material

Confidential

Customer and commercial information. Needs an approved system and a rule.

  • Customer records
  • Contracts
  • Pricing
  • CRM exports
  • Call transcripts

Restricted

Rarely belongs in a general AI tool at all without redaction.

  • Employee/HR data
  • Financials
  • Legal matters
  • Anything regulated

The ten-second check before pasting anything

  1. Public?
  2. Internal?
  3. Customer data?
  4. Employee data?
  5. Financial?
  6. Confidential?
  7. Restricted?
Human in the loop

Five levels of control — pick one per process

  1. Level 1

    AI suggests

    Human does the action. — Suggested follow-up email a rep rewrites and sends.

  2. Level 2

    AI prepares

    Human reviews. — Call brief and CRM update drafted, manager reviews.

  3. Level 3

    AI acts after approval

    Human authorizes. — Quote follow-up sequence queued, waiting on one click.

  4. Level 4

    AI acts automatically inside rules

    Defined low-risk actions. — Lead research, scoring and assignment on every web form.

  5. Level 5

    AI operates autonomously with monitoring

    Clearly defined, tested processes. — Review monitoring with escalation on negative sentiment.

Guardrails

What sits between a raw model and your business

  1. Raw model
  2. Company knowledge
  3. System instructions
  4. Examples
  5. Brand standards
  6. Policies
  7. Tools
  8. Guardrails

How something gets from idea to production safely

  • 01Idea
  • 02Sandbox
  • 03Instructions
  • 04Knowledge
  • 05Choose model
  • 06Test
  • 07Try to break it
  • 08Refine
  • 09Add guardrails
  • 10Let users try it
  • 11Decide whether to productionize
Logic Sphere

Personal AI vs a business AI system

ChatGPT / personal AI
  • Flexible
  • Individual
  • Conversational
  • Great for experimentation and knowledge work
Business AI system
  • Shared
  • Repeatable
  • Company knowledge
  • Guardrails
  • Approvals
  • Multiple models
  • Integrations
  • Tools
  • Consistent outcomes

The problems this solves

  • Different models give different answers
  • Companies need model flexibility
  • Companies need policies
  • Companies need guardrails
  • Companies need shared knowledge
  • Companies need safe experimentation
  • Companies need reusable workflows