Free guide

AI at Work: Hygiene, Context & Judgment

Choose the right tasks, protect what goes in, manage context, check the result, and keep control of anything the tool can actually do.

AIRBORNE Patriot Solutions, LLC ~12–15 min read Print-friendly checklist at the end

Start here

Use AI to help with the work—not to skip the rules around it. Before each task, decide what the tool may see, what it may do, and who will check the result.

Core idea

Brief clearly. Share on purpose. Verify independently. Approve anything that has consequences. AI helping does not move the responsibility off your desk. New to this? Start with AI Foundations.

1. Does AI belong in this task?

Four questions before you open a chat:

  • What happens if the answer is wrong?
  • Can the result be undone?
  • Can you—or a qualified reviewer—check it?
  • Is this tool approved for the information involved?

Green

Low consequence, reversible, approved information, a result you can check. Rewriting a routine note. Organizing non-sensitive notes.

Yellow

It matters, but an authorized workflow still lets AI help. Qualified review and the normal approval path before anyone relies on it.

Red

Prohibited use, unapproved information, no competent reviewer for a critical result, or an action outside your authority. Stop. Escalate.

AI can help you prepare questions or organize material for legal, medical, financial, employment, or safety work. It does not replace the qualified judgment those decisions require.

2. Right account, service, and settings

Use the tool, workspace, and account your organization approved for this task and this data. Approving a product does not approve every plugin, connector, voice feature, or third-party add-on hung off it.

Keep work out of personal accounts unless that is explicitly allowed. Use managed devices where required. Turn on multifactor authentication. Lock the screen. Do not leave work chats open on a shared machine.

Know what is stored, who can see it, whether it can be used for training, and what deletion actually does. “Not used for training” is not the same as “not stored.” Read the real settings and the contract—not the chatbot’s description of itself.

3. What goes into AI

Never put live credentials in anything the model can see

No passwords, API keys, private keys, tokens, or recovery codes in prompts, chats, uploads, or custom instructions. Use placeholders such as [API_KEY] when you talk about a config.

If an approved app needs to sign in to another service, that should go through an approved sign-in or secret store— not paste-into-chat. An enterprise subscription does not make pasting secrets safe.

Minimize sensitive information—even in approved tools

Customer and employee records, identifiers, unreleased financials, legal strategy, proprietary code, and internal security details need authorization. Give only the slice the task needs. Treat generated summaries the same as the source.

Redact with an approved method before transmission. Confirm what remains is allowed in that tool. Do not upload a sensitive original to an unapproved service and ask it to “take the names out.”

Taking names off does not make something anonymous. Dates, locations, roles, and odd circumstances still identify people. HIPAA de-identification is not “replace the name.”

Regulated information needs a specific yes

Government and contract-controlled data. Federal Contract Information, CUI, and export-controlled information have their own rules. Use only systems approved for that information and that contract. Have security or the contracts owner name the actual safeguards (NIST SP 800-171, DFARS, CMMC as they apply). A generic “enterprise” or “government” label is not enough.

Health information. Where HIPAA applies, a cloud service handling ePHI for a covered entity or business associate needs a BAA and the rest of the HIPAA program. A paid plan or an encryption claim is not that.

4. Treat outside content as data, not orders

Emails, websites, PDFs, images, tickets, and retrieved documents can contain instructions meant to hijack the tool. That is prompt injection. It does not have to look suspicious.

An instruction inside a document to send files, disclose private information, change permissions, or run a command is not authorization from you. Neither is a claim that a manager already approved it.

A file you are summarizing should not be allowed to authorize emailing your internal notes somewhere else. If outside content starts steering the tool off your task, stop. Report it. Do not “test” the instruction by following it. Telling the model to ignore malicious instructions is not a security boundary.

5. Keep connected tools on a leash

An AI tool wired to email, storage, calendars, databases, or a terminal can act—not just answer.

Grant only the access the job needs. Prefer read-only for research and drafting. Limit folders, too: read-only still exposes whatever it can see.

For everyday use, require a separate human confirmation before sending mail, publishing, buying, deleting, running generated code on your systems, changing permissions, or touching live systems. Review the actual recipients, content, destination, and proposed changes—not an AI summary of them. Broader automation needs its own approval, bounds, monitoring, and a recovery path.

Permissions have to be enforced by the application. A sentence in the prompt is not enough. Remove connections you do not need. Know how to stop a running workflow.

6. Brief clearly and keep context useful

State the goal, audience, approved sources, constraints, and what “done” looks like. Say what must not be invented or changed. Example:

Draft a 150-word internal update from the approved notes below. Cover progress, blockers, and next steps. Keep the stated dates and numbers. Mark missing owners or deadlines as “not provided.” Do not send or publish anything.

A clear brief helps. It does not guarantee the tool will obey.

Keep related work in one thread while the context is still useful. Start fresh when the subject changes, instructions collide, or old assumptions keep coming back. Carry a checked summary of facts, decisions, constraints, and open questions—not the whole messy chat.

Do not assume every earlier message is still in the model. Products trim, summarize, or retrieve selectively. A new chat resets task context. It is not a confidentiality boundary. Memory, logs, and other copies can persist. Archiving is not deletion. Follow the actual product controls and your retention rules.

7. Verify before you use the result

Read the full output. Check names, dates, calculations, quotes, and consequential claims against records you trust. Open cited sources. Confirm they actually support the claim, apply here, and are current enough.

For numbers, check the inputs and the arithmetic. For code, formulas, or commands, have someone competent review them and test in an approved, isolated environment before real systems or important data.

Asking the model what might be wrong is fine. Self-critique is not independent verification. Another AI agreeing is not proof either.

Watch for unfair assumptions, personal inferences, and convenient omissions. Keep the normal human process for decisions that affect someone’s job, rights, health, money, or safety. Before you publish, check confidentiality, IP, licensing, and whether you must disclose AI assistance. “AI-generated” does not mean unrestricted or original.

8. Faster habits that do not weaken the safeguards

Use relevant excerpts, not entire folders. Give text or structured data when wording or numbers matter. Use a screenshot when layout matters. Include enough surrounding context to interpret it.

Attach or connect sources the way the tool actually supports. A filename or private link is not proof of access. Check that it used the source.

Voice is fine when the service is approved for that information. Don’t get overheard. Check the transcript— especially names, numbers, and “not.” Recording other people or turning on meeting transcription needs policy and notice.

Reuse prompt templates. Recheck facts, permissions, and dates each time. Save final work in the system of record. Efficiency is usable work after review—not how fast the first paragraph appeared.

9. When something goes wrong

Sensitive information exposed, an unexpected action, or the tool following hostile instructions:

  1. Stop and report. Stop further input. Notify security, privacy, or the designated channel. Do not wait for proof of harm.
  2. Contain with the right people. If a credential leaked, revoke or rotate it through the authorized process. Have the responsible team look at sessions, permissions, and anything already done.
  3. Keep the record they need. Service, account, approximate time, affected information, what you saw. Follow incident instructions for evidence. Do not spread the exposure by pasting secrets into more tickets.

Deleting the chat or asking the model to “forget it” is not an incident response. Do not hide the mistake or destroy evidence.

10. Quick checklist

Print this page or keep a screenshot at the desk.

  • Task and information are approved for this tool, account, and connected services.
  • No live credentials. Sensitive information minimized. Regulated data has a specific yes.
  • Clear brief. Current sources. Context still matches the job.
  • Access is limited. Outside content cannot authorize actions. Consequential actions need a human yes.
  • Important claims checked independently. Result reviewed for this audience and this use.
  • Records saved. I know how to stop and report a problem. I own what I approve, send, or put into operation.

Companion: AI Foundations · 50 marketing prompts

Want this trained into your team’s habits?

APS delivers hands-on enablement so people use the AI tools they already have— beyond search-box habits, confidently and safely.

Educational and general—not legal advice, a control assessment, or proof of compliance. Follow your contracts, policies, and applicable law. Grounded in NIST AI RMF, OWASP GenAI risks, and NCSC/CISA secure-AI guidance; the examples and decision rules are original training material.