02 / Field note
Share the minimum useful input
Before a run, decide which details are necessary for the task. An action-item extractor may need a speaker alias and an agreed deadline, but not the speaker’s personal phone number. A product comparison may need approved specifications, but not customer records from the same spreadsheet.
Redaction should preserve the relationships needed for checking. Replace the same person with the same alias throughout the input, preserve the meaning of quantities and dates, and note where a removed field limits the result. Randomly deleting context can make the output impossible to verify.
Avoid copying an entire mailbox or shared drive simply because the interface accepts it. First try a bounded sample that you are authorized to use. Keep real secrets out of both source examples and saved test records.
03 / Field note
Read access and action access have different consequences
A connection that can read selected files is different from one that can modify every file or send messages. Read the actual permission screen and provider settings. A friendly integration name does not tell you the full scope of access.
For a first trial, prefer a separate test area with synthetic records. Limit the available operations where the platform supports that control. If the required scope is broader than the task needs and you cannot narrow it, reconsider that setup before connecting real data.
An instruction such as “ask before sending” is useful guidance, but it should be backed by the tool or application’s own approval boundary. Do not assume prose can revoke a permission already granted to a connected runtime.
04 / Field note
Inspect both the result and the proposed destination
Before approving a real action, check what will change, the exact recipient or destination, and which data will leave the system. Compare those details with the task you authorized. A plausible summary does not validate a hidden attachment or an unrelated outgoing request.
If source text asks the assistant to change roles, reveal credentials or contact another service, stop that part of the workflow and inspect the evidence. You can still read the document; you do not need to execute its embedded requests to understand it.
For a connected workflow, make sure you know where to review recent actions, revoke the connection and contact the service owner. Check what actually happened in the destination system rather than relying only on the assistant’s claim.
05 / Field note
Recheck the boundary when the workflow changes
A new connector, broader folder selection or unattended schedule changes the risk even if the task description stays the same. Review permissions again after those changes. Keep the resource version and the actual runtime configuration together in your operating notes.
The NCSC’s secure-AI guidance treats security as work across design, development, deployment and ongoing operation. For a personal or small-team workflow, the practical lesson is to keep reviewing access and behavior after the first successful run.
Keep this with your task
A permission review
Select and copy this template into your own notes. Keep sensitive task data in a location you control.