An AI tool can be useful before it deserves access to client data.
That distinction matters for a solo professional. There may be no security team between a convenient upload button and a file containing a client’s plans, contacts, pricing, credentials, or private conversations. The practical question is not whether a tool is popular. It is whether this use, with this data and these permissions, is justified.
This checklist turns that decision into a small, repeatable preflight.
Testing status. This is an editorial decision framework informed by the public guidance listed below. It has not been validated as a security control, legal standard, or compliance program. Contractual, regulated, or high-impact work may require qualified professional review.
Start with the use, not the tool
Write one sentence that describes the proposed use without product language.
Turn approved, non-sensitive interview notes into a first-draft project summary for my review.
That is more useful than “use AI for meeting notes.” It defines an input, an output, and a review point. It also exposes scope changes. Uploading raw recordings, sending the result automatically, or connecting the tool to an entire drive would each create a different decision.
If the intended use cannot be described precisely, do not connect real client data yet.
Classify the information before uploading it
Use a simple working classification. This is an editorial aid, not a legal determination.
| Working class | Typical examples | Default treatment |
|---|---|---|
| Public | Published website copy, public documentation, approved press material | May be suitable for a bounded test |
| Internal | Your own process notes, unpublished drafts, routine schedules | Review the tool and minimize the input |
| Confidential | Client strategy, private correspondence, proposals, pricing, unpublished research | Do not upload without a clear need, permission basis, and reviewed controls |
| Restricted | Credentials, payment data, government identifiers, health records, privileged material, regulated records | Keep out unless the use is specifically authorized and professionally reviewed |
One file can contain several classes. A public brochure attached to a private email thread is not simply “public.” Classify the information the tool will actually receive, including metadata, attachments, prompts, connected folders, and prior chat context.
The eight-part preflight
1. Confirm that the use is permitted
Check the commitments that already govern the work:
- the client agreement and confidentiality terms;
- promises made in proposals, privacy notices, or project plans;
- industry or professional obligations that may apply;
- the client’s documented instructions about third-party tools;
- internal rules you have adopted for your own business.
Silence is not the same as permission. If the answer depends on interpreting a contract, regulation, or professional duty, obtain appropriate advice or use a safer workflow that excludes the data.
Editorial analysis. The easiest risk to manage is the transfer that never happens. Start by asking whether the task can be completed with public, synthetic, anonymized, or manually summarized input.
2. Minimize the input
The Federal Trade Commission’s business guidance recommends knowing what sensitive information a business holds, keeping only what is needed, protecting it, and disposing of it securely. Apply the same discipline before an AI upload.
Remove anything the task does not require:
- names, email addresses, phone numbers, and account numbers;
- hidden spreadsheet columns, comments, revision history, and document metadata;
- unrelated pages or earlier messages in a thread;
- credentials, access links, and security details;
- other clients’ information;
- precise figures when a range or placeholder would work.
Redaction is useful only if the remaining context cannot easily re-identify the person or client. Replacing a name while leaving a unique company, job title, location, and project description may not meaningfully reduce exposure.
3. Inspect the vendor’s data path
Do not rely on a homepage claim such as “secure” or “enterprise-grade.” Look for the current terms and documentation that govern the exact plan and feature you will use.
Record answers to these questions:
- Can submitted content be used to train or improve models?
- Is that behavior on by default, optional, or unavailable on this plan?
- How long are prompts, files, outputs, and logs retained?
- Can you delete them, and what does deletion cover?
- Which subprocessors or model providers may receive the data?
- Where is the data processed or stored, if location matters to the engagement?
- What export and account-deletion options exist?
- Does the vendor publish security contacts and incident-notification terms?
Policies change. Save the URL and review date rather than copying a promise into a permanent checklist as if it cannot change.
For a broader tool assessment covering switching cost, failure modes, and operating burden, use the AI tool evaluation scorecard.
4. Secure the account
Use a dedicated business account when the vendor supports it. Turn on multi-factor authentication, keep recovery methods current, and avoid shared logins.
The FTC’s small-business cybersecurity guidance recommends multi-factor authentication, strong access controls, timely updates, encryption, backups, and limiting sensitive information to people and vendors that need it. A one-person business still benefits from those boundaries: they reduce the damage from a compromised password, abandoned integration, or personal account mix-up.
Review connected applications as part of the account, not as a separate concern. A browser extension or automation connector may have broader access than the AI feature itself.
5. Grant the smallest useful permission
Prefer a single selected file over an entire drive, one calendar over all calendars, read-only over write access, and draft creation over automatic sending.
Ask what the tool can do after it receives access:
- read new files without another prompt;
- follow links or retrieve attachments;
- invite users or share outputs;
- update or delete source records;
- send messages;
- call other tools or run actions.
The permission boundary should match the stated use. If a summary tool needs the ability to delete files or send email, the connection is broader than the task.
The automation risk ladder can help when the tool moves from producing a private draft to changing a system or contacting another person.
6. Test with a safe substitute
Before using client information, create a synthetic sample that has the same structure but no real identities, facts, or secrets.
Use it to observe:
- what the tool stores in history;
- whether the output can be deleted and exported;
- which integrations activate;
- whether unrelated context appears in the result;
- how the tool behaves when fields are missing or ambiguous;
- whether a human can review the complete output before use.
This does not prove the service is secure. It verifies that the visible workflow behaves as expected before the consequences become real.
7. Plan the output review
Client-data safety does not end after upload. Generated output can reproduce sensitive input, invent facts, expose hidden instructions, or place private material in a more shareable format.
Define the review before the first real run:
- compare material claims with the approved source;
- remove client identifiers that are not needed in the final artifact;
- inspect links, citations, calculations, and names;
- confirm the destination and audience;
- require approval before sending, publishing, or updating a record;
- retain the authoritative source separately.
NIST’s AI Risk Management Framework treats AI risk management as a lifecycle activity that includes governing, mapping, measuring, and managing risk. For a solo operator, a short review record is a practical way to preserve that lifecycle mindset without pretending to run an enterprise program.
Use the human-review release checklist when an AI-assisted draft will reach a client; it covers claim evidence, completeness, calculations, final recipients, attachments, and the approve-or-stop decision.
8. Define the exit and incident path
Before adoption, know how to stop.
Document:
- how to revoke integrations and sessions;
- how to export necessary work;
- how to delete files, chats, and the account;
- which local copies or backups remain;
- how to contact the vendor about a security or privacy issue;
- which client commitments would control notification;
- the manual workflow that replaces the tool.
Do not wait for a vendor change or suspected exposure to discover that deletion is unclear and the original process has disappeared.
Record a one-page decision
A lightweight decision record makes later review easier.
| Field | Record |
|---|---|
| Intended use | One bounded input-to-output sentence |
| Data allowed | Specific classes and fields |
| Data excluded | Credentials, identifiers, regulated or unrelated records |
| Permission basis | Client instruction, contract term, internal decision, or review needed |
| Vendor evidence | Terms, privacy, retention, training, subprocessors, review date |
| Account controls | Business account, MFA, recovery, connected apps |
| Tool permissions | Exact sources and allowed actions |
| Human review | What is checked and who approves external use |
| Exit path | Revoke, export, delete, manual fallback |
| Recheck trigger | Policy, plan, feature, integration, scope, or incident change |
Example, not a tested case. A consultant wants help drafting a project recap. They remove names and unrelated commercial details, replace exact figures with ranges, paste only the approved notes needed for the recap, and keep the result in draft. They verify the current plan’s data-use and retention terms, use a business account with MFA, and compare every commitment in the draft with the source notes before sending it manually.
If the same workflow later gains access to the full client drive or can email the recap automatically, the old decision no longer covers it.
Stop signs
Pause the use when:
- the client has not authorized a material third-party data transfer;
- the tool’s data-use or retention terms are missing or too vague for the use;
- deletion, export, or account ownership is unclear;
- the integration asks for unrelated access;
- restricted data cannot be reliably removed;
- nobody will meaningfully review an external output;
- the task affects legal rights, health, credit, employment, housing, or another high-impact decision;
- a safer manual or synthetic-data method would meet the need.
Convenience is not evidence that the risk is acceptable.
Recheck when the workflow changes
Review the decision when the vendor changes its terms, the subscription plan changes, a new model or integration is enabled, the data becomes more sensitive, or the output gains more authority.
Also review after the first few real uses. Record unexpected inputs, corrections, data that was broader than necessary, and any output that was hard to verify. Future testing for this framework should examine whether solo operators can complete the record consistently and whether it identifies permission creep before a workflow expands.
Sources and further reading
- NIST AI Risk Management Framework — voluntary framework for managing AI risks across the lifecycle.
- NIST Generative AI Profile — cross-sector companion resource describing generative-AI risks and suggested actions.
- FTC: Start with Security — business guidance on data minimization, access, retention, and security.
- FTC: Cybersecurity for Small Business — practical guidance on vendor access, MFA, encryption, backups, and incident response.