Policy, guardrails and how far AI is allowed to go
You asked for policies and guardrails. Policy isn't a legal document nobody reads — it's four decisions, written down, that let your people move quickly without guessing.
Four decisions
People
Who may use the system?
- Role-based, not company-wide guesswork.
Data
What information may it access?
- Tie the answer to your information levels.
Models
Which model or provider may process that information?
- Different jobs, different models — and different data rules.
Actions
What is the AI actually allowed to do?
- Suggest, draft, send, update, approve? Be specific.
What may go into AI — and where
Public
Already published. Website copy, brochures, public pricing, press.
- Service descriptions
- Public case studies
- Job postings
Internal
Not secret, but not for outsiders. Fine in approved tools.
- Process documents
- Route notes
- Training material
Confidential
Customer and commercial information. Needs an approved system and a rule.
- Customer records
- Contracts
- Pricing
- CRM exports
- Call transcripts
Restricted
Rarely belongs in a general AI tool at all without redaction.
- Employee/HR data
- Financials
- Legal matters
- Anything regulated
The ten-second check before pasting anything
- Public?
- Internal?
- Customer data?
- Employee data?
- Financial?
- Confidential?
- Restricted?
Five levels of control — pick one per process
- Level 1
AI suggests
Human does the action. — Suggested follow-up email a rep rewrites and sends.
- Level 2
AI prepares
Human reviews. — Call brief and CRM update drafted, manager reviews.
- Level 3
AI acts after approval
Human authorizes. — Quote follow-up sequence queued, waiting on one click.
- Level 4
AI acts automatically inside rules
Defined low-risk actions. — Lead research, scoring and assignment on every web form.
- Level 5
AI operates autonomously with monitoring
Clearly defined, tested processes. — Review monitoring with escalation on negative sentiment.
What sits between a raw model and your business
- Raw model
- Company knowledge
- System instructions
- Examples
- Brand standards
- Policies
- Tools
- Guardrails
How something gets from idea to production safely
- 01Idea
- 02Sandbox
- 03Instructions
- 04Knowledge
- 05Choose model
- 06Test
- 07Try to break it
- 08Refine
- 09Add guardrails
- 10Let users try it
- 11Decide whether to productionize
Personal AI vs a business AI system
- Flexible
- Individual
- Conversational
- Great for experimentation and knowledge work
- Shared
- Repeatable
- Company knowledge
- Guardrails
- Approvals
- Multiple models
- Integrations
- Tools
- Consistent outcomes
The problems this solves
- —Different models give different answers
- —Companies need model flexibility
- —Companies need policies
- —Companies need guardrails
- —Companies need shared knowledge
- —Companies need safe experimentation
- —Companies need reusable workflows

