Skip to content

Protect the input

Set a data boundary before the trial

Decide which information may enter a trial, who can authorize it, what the provider may retain or use, and what must stay out.

TARGET OUTPUT

What this guide should leave behind

A short approved-data rule identifies allowed examples, prohibited information, retention questions, access owners, and the cleanup path.

SEQUENCE / 04

Work the evaluation in this order

  1. 01

    Inventory the information the workflow normally uses. Separate public, internal, confidential, personal, customer, employee, financial, regulated, and credential material.

  2. 02

    Use synthetic, public, or carefully de-identified examples first. Do not paste real records merely because a trial account is available.

  3. 03

    Verify current provider terms and controls for retention, model training, human review, subprocessors, regional processing, deletion, export, administration, and audit evidence.

  4. 04

    Document who can approve broader use, how people will be trained, where the rule lives, and how trial information and accounts will be removed.

CHECK BEFORE GATE

Evidence worth seeing

  • The trial starts with the least sensitive useful information.
  • Provider statements are saved with a date and the applicable plan or configuration.
  • A business-controlled administrator can remove access and retrieve needed records.
  • The team knows which prompts, uploads, connectors, and generated outputs are business records.
ESCALATION BOUNDARY

Know when general guidance stops

Use qualified privacy, security, records, contract, employment, and sector review before using personal, confidential, regulated, privileged, safety-sensitive, or contract-restricted information.