One page acceptable use rules (L1)
Before any rollout, publish one page everyone can actually read: which tools are sanctioned, what data may be pasted, what must never be pasted, and who to ask. Most shadow AI is a documentation failure, not a discipline failure.
The steps
- 01
Name the sanctioned tools
Tool: Notion
List the approved assistants and note the enterprise agreement status of each. If the list is empty, that is the first problem to solve, not a reason to delay the page. Owner: security plus IT. DoD: sanctioned list published with owners.
- 02
Write the data rules in plain language
Tool: Manual
Three columns: always fine, ask first, never. Use real examples from your business, such as customer contract text or personal data in support tickets. Pitfall: legal language nobody can apply in the moment. DoD: a non technical employee can classify five examples correctly.
- 03
Give people a fast route to ask
Tool: Slack
One channel, a named owner, and a two day response commitment. If asking is slow, people stop asking and start hiding. Owner: security. DoD: channel created with a stated response time.
- 04
Review quarterly
Tool: Manual
Tools and agreements change fast. Date the page and review it every quarter, publishing what changed. Owner: security. DoD: page shows a last reviewed date within 90 days.
Tools in this playbook
Next playbooks
Unfamiliar terms are defined in the AI and Revenue Dictionary. Related frameworks live in the framework library.
