Put Authority Around Capability
A model can produce an answer without having permission to see the data, make the decision, or take the action. Classify information and use cases before selecting a Claude surface or workflow. Separate technical capability from organizational permission and human authority. Design controls for privacy, security, bias, transparency, retention, and misuse. Place human review according to consequence, reversibility, and ambiguity. Build an incident and escalation path for unsafe or noncompliant behavior. A customer-success manager wants faster account reviews. They paste support transcripts, contract excerpts, and renewal notes into an unapproved personal AI account. Claude produces useful summaries, so the manager asks it to rank customers by renewal risk and automatically send special offers. The workflow has several failures before output quality is considered: The transcripts contain personal and commercially sensitive data. Nobody checked which product terms and retention controls apply. The ranking may create uneven treatment across customer groups. The manager has no authority to approve discounts automatically. There is no record of sources, review, or sent messages. Adding "protect privacy" to the prompt does not repair the system. Governance defines who may use which data, for which purpose, on which surface, with which controls, and who remains accountable. Start with the data and the decision, not the model. A simple organizational classification might be: These labels are examples, not…
Put Authority Around Capability: A model can produce an answer without having permission to see the data, make the decision, or take the action.
This free lesson is part of the AI Engineering from Scratch curriculum. Read the full explanation, run the lesson code, and verify the result in the interactive reader or from the repository source.
Browse the complete course catalog or open this lesson on GitHub.