Explain the rule without becoming its author
Practise with the fictional policy below. For real work, use the current approved version and the relevant surrounding clauses, not an old screenshot or a sentence remembered from a meeting. Remove sensitive data from any working copy unless the exact policy and approval allow its use; removing names alone may not remove identifying or confidential detail. You can explain the excerpt yourself or use one approved assistant where your organisation permits it. Verify every quote and conclusion against the source. This page does not grant permission, check a vendor or decide your organisation’s rules. Plain language should shorten the sentence, not quietly widen the permission.
Keep the policy and question side by side
Fictional training policy, version 1. This is not your organisation’s policy or a legal opinion.
[R1] External AI use requires approval of both the tool and the data-handling arrangement for the specific task. This excerpt does not supply an approved-tool list.
[R2] Customer names, email addresses and account IDs must not be sent unless the data owner has explicitly approved that use in writing. The data owner is the person responsible for approving use of that dataset under this policy.
[R3] Removing those fields does not by itself approve the remaining text; other details may still identify someone or reveal confidential information.
[R4] When approval or scope is unclear, use fictional data and ask the data owner before sending real records. Describe the intended tool, task and data categories without attaching the records.
[R5] This excerpt does not specify who the data owner is, whether any approval exists, or which storage and retention terms apply.
Question: “Can I paste customer names into an external AI tool to summarise feedback? What if I remove the names first?”
No approval record or vendor details have been supplied. Keep the R labels with the excerpt.
Ask for an answer with the exact rule behind it
Use only the supplied policy excerpt and question, preserving their actual clause labels. Answer the question first, then build a compact four-question ladder in this order: scope, exception, evidence and stop condition. For each question, show the exact supporting wording, then give an answer in a clear format: yes/no where the source supports it; otherwise a named date, owner, clause reference or “unresolved” only when the source provides or requires it.
For the scope question, identify whether the supplied rule covers the proposed action. For the exception question, test every stated condition without assuming it has been met. For the evidence question, list what the excerpt says is missing; do not fill the gap from common practice. For the stop-condition question, state whether the excerpt supports proceeding or requires a pause and clarification.
If the question or relevant clause is missing, ask for it and say what this excerpt cannot answer; do not claim the entire policy is silent. If you receive only a URL, retain it as a reference but do not infer the page contents from the URL; ask for the relevant text or excerpt. Separate what the excerpt requires, missing evidence and the next action. Quote the exact relevant clause for every policy conclusion; do not fabricate wording or extend the excerpt into unseen policy. Preserve the stated conditions and exceptions. For the fictional R1–R5 data-sharing example, a paid account or removal of names is not approval; for another policy, do not add that example’s vendor, data or approval rules. Do not invent responsible people, approval records, retention periods or legal requirements. Finish with a short clarification request for the policy owner or relevant contact if known; do not assign a contact the source does not name. Use no sensitive records in the request. This is a draft explanation, not authorisation to act. Source:
Compare with a complete policy answer
Worked output for the fictional input:
Short answer: not on the evidence supplied. Do not paste the customer names yet. Removing the names is not enough to establish permission either.
Four-question ladder:
1. Scope — Does the excerpt cover sending customer data to an external AI tool for this task?
Answer format: yes/no + exact clause.
Answer: Yes. R1 says: “External AI use requires approval of both the tool and the data-handling arrangement for the specific task.”
2. Exception — Has the R2 written-approval exception been shown to apply?
Answer format: yes/no or unresolved + approval evidence.
Answer: Unresolved; the required evidence has not been supplied. R2 says: “Customer names, email addresses and account IDs must not be sent unless the data owner has explicitly approved that use in writing.” This does not claim that no approval exists; it marks that approval is not established here.
3. Evidence — What does the excerpt say is missing?
Answer format: missing item + clause reference.
Answer: R5 says the excerpt does not specify who the data owner is, whether any approval exists, or which storage and retention terms apply. R1 also does not supply an approved-tool list.
4. Stop condition — Can the real records be sent now based on this excerpt?
Answer format: yes/no + condition or next action.
Answer: No. R4 says: “When approval or scope is unclear, use fictional data and ask the data owner before sending real records.” Use fictional feedback while preparing the summary method. Before using real records, ask about the exact tool, task and data categories. Do not attach those records just to ask permission.
What else the excerpt says:
• R3 says: “Removing those fields does not by itself approve the remaining text”. A feedback comment may still identify a person or disclose something confidential after the name is removed.
• We cannot fill these gaps with a vendor’s reputation or another team’s practice. A paid account does not establish tool approval or data-handling approval.
Draft question for the owner:
“I want to summarise feedback using an external AI tool. Which tool and data-handling arrangement, if any, are approved for this task? May it receive customer names, email addresses, account IDs or free-text comments? Please point me to the written approval and its limits. I have not attached any customer records.”
Wrong: “Delete the names and use any paid AI account.”
Repair: “Removing names does not establish approval. Confirm the tool, handling arrangement and permitted data scope first [R1–R4].”
If an approval is later supplied, check whether it covers this task and these data categories. Do not turn one permission into approval for every future use. This answer interprets the fictional excerpt; it does not declare what a real organisation or provider permits.
Check every yes, no and exception
Trace every answer sentence and each ladder question to R1–R5. Check that:
• The four questions really narrow in this order: scope, exception, evidence and stop condition.
• Each question has an exact supporting phrase and a clear answer format.
• The scope answer keeps R1’s “for the specific task” condition.
• The exception answer preserves both the restriction and the written-approval exception in R2 without claiming that approval does or does not exist.
• Missing evidence is marked unresolved, rather than filled with common practice or treated as proof that the entire policy is silent.
• Tool approval, data-handling approval and allowed data scope remain distinct.
• The answer rejects “names removed means safe” without inventing a universal legal ban.
• The final stop condition is directly supported by R4 and does not invent a deadline, owner or approval route.
• The quoted wording matches the excerpt, including words such as “unless” and “for the specific task”.
If two clauses appear to conflict or the excerpt is incomplete, list the exact question for the owner instead of choosing whichever rule is easier. Keep real records out of the clarification request. Verify the completed explanation against the supplied source before ticking these checks; a checked explanation does not itself grant permission.
Get the clarification into the source first
Copy the reviewed explanation before leaving; edited worksheet text is not saved. Take the open questions to the authorised policy/data owner through your normal channel. Record the confirmed wording, version and scope in the approved policy source before changing team guidance. Do not turn an informal suggestion into a new rule. Once that source is approved, use the internal-announcement Task below to explain the change to the affected audience. AhaDo does not contact the owner, update the real policy or approve a data transfer. Completion here means you prepared an explanation and questions, not that permission was granted.