Start here
You do not need to become a programmer. Pick a task you already understand, use information you are allowed to share, and ask for a result you can check.
The point is not more words. The point is useful work—without giving up accuracy, privacy, or the decision.
Start with a task you understand. Give a brief, not a topic. Check the result. Keep control of what happens next. For data handling, connected tools, and incidents, use the hygiene guide.
1. What you are using
Generative AI writes text, images, audio, or code from patterns it learned and from whatever you give it in this session. The model is the engine. The app is the product around it—chat, files, settings, and any connected tools.
That split matters. Two apps can sit on the same model and still differ on privacy, file access, and what they can actually do. A fluent answer is not proof it searched the web, read your files, or took an action.
Fluent and wrong still happens. People call that a hallucination. Length, confidence, and a professional tone are not evidence.
- Prompt — your question or instructions.
- Context — what the model can see for this reply.
- Context window — how much it can consider at once. Long threads get trimmed.
- Tool / connector — extra access: files, mail, search, a terminal.
- Agent — a setup that can run a sequence of steps with those tools.
You do not need the glossary memorized. You do need to tell an answer from evidence, and a draft from an action.
2. A useful first task
Start low-stakes and reversible:
- Transform — rewrite a non-sensitive note for a different audience, or turn rough notes into a checklist.
- Organize — pull decisions and open questions from material you already have.
- Learn — ask for a plain explanation, an example, and a short quiz, then check the important bits against a source you trust.
Define “done” before you start: “100 words that keep every stated date,” not “make this better.”
Do not make your first experiment a medical call, a legal interpretation, a hiring decision, a production change, or anything that needs unapproved confidential data. Use fictional practice data if you are unsure. Keep high-stakes work inside a process with a qualified reviewer.
3. Give a brief, not a topic
“Help with this report” is not a brief. Say what you need, who it is for, which material to use, and what the result must contain.
A reusable starting point:
Task: [what to produce, explain, or compare] Audience: [who will use it, what they already know] Source material: [approved notes, facts, or attachments] Requirements: [length, format, tone, must-include] Boundaries: [what must not be invented, disclosed, or changed] Separate supported facts from assumptions. If something essential is missing, ask or mark it “not provided.” Return a draft only. Do not send, publish, or change anything.
Use only the parts the task needs. A simple ask does not need the whole template. Example:
Rewrite the notes below as a 120-word update for non-technical managers. Cover completed work, blockers, and the next decision. Keep the numbers. Do not invent reasons, owners, or deadlines. Mark missing information as “not provided.”
4. Useful context—without dumping everything
Give the material the question actually needs. For a summary, attach the approved document or excerpt. For a comparison, give the options and the criteria. For a calculation, give the values, units, and time period.
Label sources and versions. Say whether you want a summary of what you supplied, outside research, or new ideas. For source-based work, ask it to separate what the source says from its own suggestions.
Check that the tool actually has the file. A local path or a private link is not the same as a successful attach. Do not make a restricted document public just so a chatbot can open it.
Keep the thread on one job. When the subject changes, or the chat keeps repeating a mistake, start a new one with a short, checked brief. Do not assume every old instruction is still in play.
5. Work in passes
For anything that matters, split it: understand, draft, then review. Get the facts and gaps first. Correct those before you ask for the write-up. Then read the draft against the original brief.
Vague feedback wastes a turn. Be specific:
Keep the first paragraph. Cut the unsupported claim about cost savings. Change “deployment completed” to “pilot completed.” Two sentences at the end. Do not change the stated dates.
Recheck after a revision. A fix in one place can break another. Do not keep regenerating until the model agrees with what you hoped to hear. When answers conflict, go back to the evidence or get a qualified reviewer.
6. Check the kind of work you asked for
- Summaries — compare with the original. Watch for dropped exceptions, softened hedges, or a possibility turned into a decision.
- Research — open the sources. Confirm they support the claim, still apply, and are current enough. A tidy citation list is not verification.
- Numbers and code — check units, totals, and assumptions. Recalculate the important values. Test formulas or code on sample data in a safe place before real records.
- Writing — does it say what you mean, for this audience, with claims you can stand behind? Strip filler and fake certainty. Check rights and disclosure before you publish.
Asking “what might be wrong?” is useful for finding questions. It does not prove the answer is right. Neither does asking another AI to agree.
7. Before you connect tools
Use an approved account. Keep live passwords, keys, tokens, and recovery codes out of prompts and uploads. Do not practice on real customer, employee, financial, or health records without explicit permission. Paid, private, “enterprise,” or local does not automatically authorize a particular use.
Start with drafting. Narrow, read-only access if you must connect anything. You do not need your whole mailbox or drive to learn.
“Draft an email” and “send an email” are different permissions. Before you approve an action, look at what will happen, to whom, and with which information. Limits have to live in the system, not only in a sentence in your prompt.
Instructions inside a webpage, PDF, or email are not your permission. If the source starts steering the tool, stop. That can be prompt injection. Do not follow it to “investigate.”
The full picture on data, connectors, retention, and incidents is in AI at Work: Hygiene, Context & Judgment.
8. Practice with a task you can check
These notes are fictional. No real customers:
Twelve service requests were received. Nine are complete. Three are awaiting customer information. No owners or completion dates were recorded.
- Summarize. Status update, 60 words max. Keep the facts. Do not invent names, deadlines, reasons, or a claim that work is on schedule.
- Organize. A table: status, count, next information needed. Separate recorded facts from suggested follow-ups. Mark gaps “not provided.”
- Check. Percentage complete. Show numerator and denominator. State what the notes do not tell us.
Your check: 9 + 3 = 12. Completion is 9 ÷ 12 = 75%. The notes do not name owners, deadlines, whether anything is late, or why customers have not replied.
A polished answer that invents any of that fails. A useful answer keeps the facts and makes the gaps visible.
9. Keep what works—and keep your judgment
Save good prompts as templates with placeholders, not with live data in them. Store the reviewed output and the sources where the work actually lives. Chat history is not your project file.
For ongoing work, keep a short checked brief: goal, current facts, decisions, constraints, open questions. Reuse it when you change chats or tools. Verify it first—an AI summary can carry errors forward.
Product “memory” is not an official record. Deleting a chat may not delete copies stored elsewhere. Learn the actual controls on the app you use.
Judge the whole cycle: brief, generate, fix, file. A draft that takes longer to repair than to write is not a win.
10. Before you call it done
Print this page or screenshot the list.
- Appropriate task, approved tool, permitted information.
- Clear goal, relevant sources, and a definition of done.
- Facts, assumptions, and suggestions are labeled separately.
- Important claims and calculations checked independently.
- I read the actual output (and any proposed action)—not just the AI’s description of it.
- Final work saved in the right place. I still own the decision.
Next: hygiene at work · 50 marketing prompts
Want this trained into your team’s habits?
APS delivers hands-on enablement so people use the AI tools they already have— beyond search-box habits, confidently and safely.
Educational and general—not legal advice. Follow your organization’s policies and applicable law. Grounded in NIST AI risk guidance, OWASP GenAI risks, and vendor prompting docs; examples here are original training material.