Decision inputs
Facts that change the policy answer
For this request, email headers, message content and links is the input boundary and a phishing assessment and response steps is the output boundary. A useful check makes both explicit.
- 1Task and owner
- Security analyst wants to analyse a suspected phishing email. The request needs an accountable owner for a phishing assessment and response steps, even when the tool prepares most of the first draft.
- 2Information involved
- Email headers, message content and links. Account for every route by which the tool receives the material, including plug-ins and linked storage.
- 3Tool and account
- An approved company account. Treat a new plug-in or connector as a change to the approved setup.
- 4Intended result
- The expected result is a phishing assessment and response steps. State whether another person will see it, rely on it or receive an action produced from it.
- 5Consequence if it is wrong
- The message may contain personal information or malicious content and the classification can be wrong. A familiar task still needs escalation when this consequence becomes plausible.
- 6Human review
- security analyst should inspect, change, reject or stop the result. Make the review happen before reliance and give the reviewer a real way to stop the work.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
The company can consider a standard route where the exact account is approved, only the minimum potentially malicious and personal information is used, a phishing assessment and response steps remains within the stated purpose, and security analyst reviews it before use.
Approval may be required
Specialist approval becomes relevant if the account or data handling is uncertain, the message may contain personal information or malicious content and the classification can be wrong, or a phishing assessment and response steps reaches people or systems beyond the requester’s authority.
The request may need to stop or change
The proposed use should pause if restricted information would enter an unapproved service, the output would act before security analyst can intervene, or use a safe analysis environment and verify indicators before blocking or notifying users cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Does the selected account retain or reuse anything supplied while trying to analyse a suspected phishing email?
- 02
Who is permitted to expose email headers, message content and links to this tool and for this purpose?
- 03
Does a phishing assessment and response steps create an external statement, a decision or an automated action?
- 04
Will security analyst review before the result is sent, published or acted upon?
- 05
Would another region, audience or frequency activate a different company rule?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- security analyst
- task
- Use AI to analyse a suspected phishing email.
- information
- email headers, message content and links
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Analyse
- impact
- Security response
- review
- Complete human review
- owner
- security analyst
Useful safeguards
Controls that fit this request
- ✓
Use a safe analysis environment and verify indicators before blocking or notifying users
- ✓
Start with a de-identified sample of email headers, message content and links before considering broader access.
- ✓
Write the boundary around a phishing assessment and response steps clearly so later users do not expand the approval by assumption.
- ✓
Make the final route reproducible from the recorded facts, safeguards and policy version.
Questions people ask
About this AI use
Is using AI to analyse a suspected phishing email automatically allowed?
The task name cannot settle the answer. Apply the company’s published rules to email headers, message content and links, the exact account, a phishing assessment and response steps, its audience and the proposed review.
How specific should the workplace AI request be?
Describe a phishing assessment and response steps, identify email headers, message content and links, name the exact tool and account, explain who will receive or rely on the output, and state how security analyst will review it.
How should a later reviewer understand this decision?
Make the final route reproducible from the recorded facts, safeguards and policy version. A classification and controlled reference may be enough when copying email headers, message content and links would create unnecessary risk.