The decision
What can an approved assistant help draft without receiving restricted operational detail?
This workbench creates the instruction set, not the finished security document. It separates the work objective from the site context so a practitioner can decide what information is approved before using an external assistant.
Work product, audience, sensitivity, format, approved context, and constraints.
A structured prompt with explicit evidence, uncertainty, privacy, and review requirements.
The practitioner who approves the context and reviews the resulting work product.
Before you begin
Prepare four pieces of governance evidence.
- Approved service: Name the assistant your organization allows for this use.
- Data boundary: Confirm what is public, approved internal, restricted, or prohibited.
- Source set: Identify the policy, record, or reference the output must use.
- Named reviewer: Assign the person responsible for factual, policy, and operational review.
Working tool
Build the governed prompt
Restricted context is withheld from the generated prompt by design.
Do not paste confidential incidents, personal data, credentials, floor plans, device locations, vulnerabilities, or evidence into an AI service unless your organization has explicitly approved that service and use.
Interpret the output
A strong prompt has eight inspectable parts.
Defines the job without granting decision authority.
Sets length, structure, and level of detail.
States what information may and may not be used.
Requires sources for consequential claims.
Prevents missing facts from becoming invented facts.
Names the sections the reviewer expects.
Withholds restricted detail and autonomous decisions.
Names the accountable final reviewer.
Method and limits
This tool governs a prompt, not a model.
The generator is deterministic and browser-local. It does not contact an AI service, verify a model, inspect organizational policy, or determine whether a particular dataset is lawful or appropriate to use.
Review the generated prompt against your AI policy, records rules, privacy obligations, collective-bargaining requirements, and incident procedures before use.
Read the complete methodology