
The Workflow Edit | AI Governance Basics
Before You Paste That Client File Into AI, Use This Three-Color Rule
Your team does not need a forty-page AI policy before using AI responsibly. It does need a clear rule for what can be pasted, what must be cleaned, and what stays out.
Dear Suzannah
Dear Suzannah, my small marketing agency wants to use AI to summarize notes, draft content, and clean up messy client material. The problem is that half the team thinks every file is fine to paste into a chatbot, and the other half acts like uploading a PDF will summon the compliance police. We need something simple that real people will actually follow. How do we sort client files before they touch AI?
Use a green, yellow, and red rule before anything gets pasted or uploaded.
Guess what I found. Most teams do not fail because they lack a giant policy binder. They fail because nobody can answer one very basic question in the moment: can I put this into the tool or not? The three-color rule fixes that fast. Green means go. Yellow means clean it first. Red means keep it out. Cute idea, but please do not let “I was just testing the tool” become the reason client data wandered somewhere it never should have gone.
Here’s the deal
NIST’s guidance on managing generative AI risk keeps coming back to the same grown-up themes: know your data, know your risk, set clear rules, and do not assume the tool understands your boundaries. That matters a lot for a small agency because client information comes in all shapes, from harmless creative briefs to contracts, reports, contact lists, and raw exports full of details no one should casually toss into an AI prompt.
Official tool documentation backs this up. OpenAI explains that training controls, chat retention, and file retention are separate considerations. In other words, turning one setting off does not magically answer every data-handling question. Google makes similar distinctions across Gemini activity, privacy settings, and connected apps, and it also warns that connected apps may expose additional information depending on what the user links.
Here’s the part people miss: a data-sharing rule is not just about the tool. It is about the document. Before anyone pastes, uploads, or connects anything, your team should classify the material and choose the right path. That is where the three-color rule becomes an actual process instead of a well-meaning speech in a staff meeting.
What this actually helps you do
This method helps a small marketing agency decide what client material can safely go into an AI tool, what needs cleanup first, and what should never leave the approved system. The goal is not to scare your team away from AI. The goal is to stop them from treating every file like a harmless blog draft when some of those files are basically a trust fall with client data attached.
Use the rule any time an employee wants to paste text into a chat, upload a file, connect a workspace app, or let an AI feature access stored material.
| Color | What it means | Typical examples | What to do |
|---|---|---|---|
| Green | Low-risk material that is already public, generic, or approved for broad internal use. | Public website copy, generic content outlines, non-client process notes, sanitized examples. | Use in approved AI tools with normal review. |
| Yellow | Useful material that contains client context but needs cleanup first. | Draft briefs, campaign notes, internal summaries, sample reports with names or identifiers. | Remove names, emails, account numbers, exact financials, and other sensitive details before use. |
| Red | Sensitive, confidential, regulated, or highly revealing information that should stay out unless a specifically approved secure workflow exists. | Contracts, raw client exports, credentials, HR files, health data, financial records, full contact lists. | Do not paste or upload into general AI tools. Use a different approved process. |
The real use case
This post focuses on one practical use case: helping a small marketing agency classify client documents before employees paste or upload them into an AI tool. Think campaign recaps, content drafts, analytics notes, screenshots, lead lists, client strategy documents, and mystery attachments that someone swears are “probably fine.” That last category is how people earn themselves a new training session.
Example: an account manager wants AI help drafting a campaign summary. The client folder contains a clean public case-study draft, an internal performance report with named contacts and budget details, and a raw spreadsheet export from the CRM. Under the three-color rule, the public draft is green, the performance report is yellow and must be cleaned, and the raw export is red and stays out.
Three benefits
- Faster team decisions: Employees stop guessing because the rule gives them a simple test they can use in real time.
- Safer handling of client information: Yellow items get cleaned before use and red items stay out, which reduces careless oversharing.
- Better AI output quality: When people prepare clean inputs, the tool produces more useful work instead of confused summaries built on messy, overloaded files.
No prompt needed: use this workflow instead
This is not a magic prompt problem. It is a decision problem. Use this workflow every time someone wants AI help with client material.
- Identify the file, text, or app connection the employee wants to use. Be specific. “Client stuff” is not a category.
- Ask the first question: is this already public, generic, or fully safe for broad internal sharing? If yes, it is probably green.
- Ask the second question: does it contain client names, email addresses, strategy details, account information, financials, or other identifying details? If yes, it is at least yellow.
- Ask the third question: would you be uncomfortable if this exact file were exposed to the wrong person, retained longer than expected, or pulled into another connected context? If yes, move it to red unless you have a specifically approved secure workflow.
- For yellow items, create a cleaned version. Remove names, personal details, exact identifiers, credentials, confidential numbers, and anything else the tool does not need.
- Label the cleaned file clearly so the team uses the sanitized version, not the original. This is where the magic-looking thing becomes an actual process.
- Use only the approved AI tool and check its relevant settings, such as data controls, retention choices, activity history, connected apps, and privacy options.
- Generate the output, then do a human review to make sure no sensitive details slipped into the prompt or the output.
- Store the final result in the right client location and delete temporary working copies if your internal rules require it.
- When in doubt, stop and escalate. “I was not sure, so I asked” is a beautiful sentence. Use it more.
Make the result less generic
- Create a one-page cheat sheet with real agency examples under each color so the team is not left interpreting theory.
- Put a cleaning checklist next to the yellow category: remove names, emails, phone numbers, budgets, client IDs, login details, and contract language unless specifically approved.
- Keep a short list of red-zone file types such as raw CRM exports, signed agreements, invoices, health information, payroll files, and credentials.
- Train the team on both chat tools and connected tools. A connected app can expose more than the single file they meant to use.
- Review tool settings separately from document classification. Turning off training does not automatically answer retention or sharing questions.
- Use a naming rule like
clientname-summary-cleaned-for-aiso sanitized files are easy to spot.
Common mistakes
- Treating settings like a permission slip: Data controls matter, but they do not replace judgment about what should be pasted in the first place.
- Forgetting connected apps: People think about the prompt box and forget that app connections may expose additional information.
- Calling something anonymous when it is not: If the document still points clearly to the client, it is not really cleaned.
- Using the original instead of the sanitized copy: This is an annoyingly common way to break your own rule.
- No red category at all: If everything is green or yellow, your team does not have a rule. It has optimism.
Quick human check
- Did someone classify the document before using the tool?
- If the file is yellow, was a cleaned version created and saved separately?
- Does the cleaned version remove names, identifiers, sensitive numbers, and confidential extras the AI does not need?
- If a connected app is involved, did the employee check what additional information the connection can expose?
- Did the user confirm relevant activity, privacy, and retention settings for the approved tool?
- Would you be comfortable explaining this exact upload choice to the client if asked?
- Does the final output avoid reintroducing restricted details?
How to measure success
- Classification rate: Track whether employees are consistently marking items green, yellow, or red before AI use.
- Sanitized-input rate: Count how often yellow items are cleaned properly before they are used.
- Escalation quality: Measure whether uncertain cases are being flagged instead of guessed through.
- Incident reduction: Watch for fewer near misses involving overshared client information.
- Output usefulness: Check whether cleaner inputs produce better summaries, drafts, and analysis.
FAQ
Do we need a legal department to use this rule?
No. You need a simple operating rule that your team can actually follow. If you do have legal or compliance support, even better. But a small agency can still start with clear categories and real examples.
Can green files include client information?
Usually, green is best for public or generic material. If client information is present, you should be very sure it is low risk and approved for that use. Most client-specific material ends up yellow or red.
What belongs in yellow most often?
Drafts, notes, summaries, and planning material that are useful for AI work but contain identifiers or confidential details that can be removed first.
What if the AI tool says it does not train on my content?
That is only one part of the decision. You still need to think about retention, file handling, activity history, app connections, and whether the document belongs in the tool at all.
What if my team is unsure about a file?
Default upward, not outward. Ask before using it. A five-minute check is cheaper than an apology tour.
Glossary
- Green: Material that is low risk and generally safe for approved AI use.
- Yellow: Material that may be used only after sensitive or identifying information is removed.
- Red: Material that should not be pasted or uploaded into general AI tools without a specifically approved secure process.
- Connected app: A linked service that gives an AI tool access to content beyond the text typed into a single chat.
- Retention: How long chats, files, or related activity may be stored by the system.
- Data controls: Settings that affect how content may be used, retained, or linked across the tool.
Sources and further reading
- NIST: AI Risk Management Framework, Generative AI Profile
- OpenAI Help Center: Data Controls FAQ
- OpenAI Help Center: Chat and File Retention Policies in ChatGPT
- Google Help: Gemini Apps Activity
- Google Help: Connected Apps in Gemini Apps
- Google Account Help: Review your privacy settings
A three-color rule is not fancy. That is why it works. Give people a rule they can use in ten seconds, and you have a real shot at safer AI use before the chaos starts improvising.
