HD Field Guide 02
Classify before you paste
A practical decision path for prompts, uploads, chat history, AI workspaces and connected information sources.
An AI tool can be useful without being an approved destination for every type of information. Decide what the data is, why it is needed and what the service may retain before entering it.
Use a simple classification question
Ask: would it be acceptable for this information to appear in a support ticket, supplier system or unintended recipient’s inbox? If not, do not paste it into an unapproved AI service.
Consider the complete context. A document may look harmless while names, identifiers, commercial details or hidden metadata make it sensitive.
Minimise before use
Use the least information needed for the task. Replace real names, customer details and internal identifiers with neutral placeholders. Remove secrets and technical configuration that could support an attack.
Do not assume that deleting a conversation immediately removes every retained copy. Follow the service’s actual contract and configured retention controls.
Control connectors and retrieval
Connected drives, mailboxes and collaboration platforms can expose far more information than a single upload. Grant the narrowest possible access and test which content the AI system can retrieve.
Review sharing permissions, logs and offboarding processes whenever a connector, plugin or agent is introduced.
Before you close the guide
- Data classification known
- Minimum data used
- Secrets and identifiers removed
- Retention, sharing and connector access understood
Continue with primary guidance
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.