Protect the input
Set a data boundary before the trial
Decide which information may enter a trial, who can authorize it, what the provider may retain or use, and what must stay out.
What this guide should leave behind
A short approved-data rule identifies allowed examples, prohibited information, retention questions, access owners, and the cleanup path.
Work the evaluation in this order
- 01
Inventory the information the workflow normally uses. Separate public, internal, confidential, personal, customer, employee, financial, regulated, and credential material.
- 02
Use synthetic, public, or carefully de-identified examples first. Do not paste real records merely because a trial account is available.
- 03
Verify current provider terms and controls for retention, model training, human review, subprocessors, regional processing, deletion, export, administration, and audit evidence.
- 04
Document who can approve broader use, how people will be trained, where the rule lives, and how trial information and accounts will be removed.
Evidence worth seeing
- The trial starts with the least sensitive useful information.
- Provider statements are saved with a date and the applicable plan or configuration.
- A business-controlled administrator can remove access and retrieve needed records.
- The team knows which prompts, uploads, connectors, and generated outputs are business records.
Know when general guidance stops
Use qualified privacy, security, records, contract, employment, and sector review before using personal, confidential, regulated, privileged, safety-sensitive, or contract-restricted information.