Decision inputs
Facts that change the policy answer
For this request, a real customer case and internal learning objective is the input boundary and a de-identified training example is the output boundary. A useful check makes both explicit.
- 1Task and owner
- Support trainer wants to redact a customer story for internal training. The request needs an accountable owner for a de-identified training example, even when the tool prepares most of the first draft.
- 2Information involved
- A real customer case and internal learning objective. Account for every route by which the tool receives the material, including plug-ins and linked storage.
- 3Tool and account
- An approved company account. Confirm the approved account, retention setting and any connected service before the request begins.
- 4Intended result
- The expected result is a de-identified training example. Follow the result to its real endpoint so the request captures its practical effect.
- 5Consequence if it is wrong
- Names can be removed while combinations of events still identify the customer. Use this consequence to distinguish a routine request from one needing specialist approval.
- 6Human review
- privacy or training owner should inspect, change, reject or stop the result. Make the review happen before reliance and give the reviewer a real way to stop the work.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
The lower-friction route begins when the exact account is approved, only the minimum customer personal information is used, a de-identified training example remains within the stated purpose, and privacy or training owner reviews it before use.
Approval may be required
Specialist approval becomes relevant if the account or data handling is uncertain, names can be removed while combinations of events still identify the customer, or a de-identified training example reaches people or systems beyond the requester’s authority.
The request may need to stop or change
A stop or redesign route becomes relevant if restricted information would enter an unapproved service, the output would act before privacy or training owner can intervene, or remove indirect identifiers and test whether colleagues could recognise the case cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Does the selected account retain or reuse anything supplied while trying to redact a customer story for internal training?
- 02
Does the proposed input include more of a real customer case and internal learning objective than the result actually requires?
- 03
Who receives a de-identified training example, and what will they do with it?
- 04
Will privacy or training owner review before the result is sent, published or acted upon?
- 05
Does the intended use extend beyond the region and audience covered by the current policy?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- support trainer
- task
- Use AI to redact a customer story for internal training.
- information
- a real customer case and internal learning objective
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Draft or analyse
- impact
- Internal work
- review
- Complete human review
- owner
- privacy or training owner
Useful safeguards
Controls that fit this request
- ✓
Remove indirect identifiers and test whether colleagues could recognise the case
- ✓
Start with a de-identified sample of a real customer case and internal learning objective before considering broader access.
- ✓
Write the boundary around a de-identified training example clearly so later users do not expand the approval by assumption.
- ✓
Preserve who accepted a de-identified training example, when they did so and which rule version they applied.
Questions people ask
About this AI use
Is using AI to redact a customer story for internal training automatically allowed?
Even an ordinary redact a customer story for internal training request can change route when it involves restricted information, an external audience or weak review.
What belongs in the employee’s request?
Describe a de-identified training example, identify a real customer case and internal learning objective, name the exact tool and account, explain who will receive or rely on the output, and state how privacy or training owner will review it.
How should a later reviewer understand this decision?
Preserve who accepted a de-identified training example, when they did so and which rule version they applied. A classification and controlled reference may be enough when copying a real customer case and internal learning objective would create unnecessary risk.