checklist
Customer data AI approval form
A reusable approval form for small teams deciding whether customer data can be used in ChatGPT, AI assistants, connectors, support workflows, meeting summaries, or internal automation.
Bottom line
Small teams need a written approval record before customer data goes into an AI workflow. The record does not need to be a heavyweight compliance artifact. It does need to answer the questions that matter: what customer data is involved, why AI is needed, which tool will process it, who owns the decision, what must be redacted, how long the output stays around, and what happens if something goes wrong.
Use this rule:
No customer data enters an AI tool until the workflow has an owner, allowed data classes, prohibited data classes, redaction rule, retention rule, and escalation path.
Run the AI Tool Risk Checker before approving the workflow, then store the decision in the Small Team AI Security Checklist. For ChatGPT-specific workflows, pair this form with the ChatGPT Business retention questions guide and the ChatGPT connector approval template.
Approval decision matrix
| Customer-data workflow | Default decision | Required review |
|---|---|---|
| Redacted support reply drafting | Pilot allowed. | Support owner and workspace admin. |
| Redacted ticket summarization | Pilot allowed. | Support owner and retention owner. |
| Customer call transcript summarization | Conditional. | Meeting owner, customer owner, and retention owner. |
| CRM or helpdesk connector | Restricted. | Source-system owner, admin owner, and workflow owner. |
| Customer contracts, invoices, pricing, or renewal notes | Restricted. | Business owner and contract/account owner. |
| Security incident, abuse report, vulnerability detail, or exposed secret | Block normal AI workflow. | Security or incident owner. |
| Health, HR, legal, child, government, payment card, bank, tax, or regulated financial data | Block lightweight approval. | Legal/security/compliance owner before any AI use. |
| Bulk customer export or many-ticket analysis | Restricted. | Data owner, sampling plan, retention rule, and minimization plan. |
If a workflow lands in “Restricted” or “Block”, do not approve it through a Slack message. Use the full form below.
Approval form
Copy this into a ticket, Notion page, spreadsheet row, or security review issue.
Customer data AI approval
Workflow name:
Requester:
Business owner:
Data owner:
AI tool or workspace:
Tool account type:
Source system:
Source-system owner:
Business purpose:
Customer data involved:
Data classes allowed:
Data classes prohibited:
Exact inputs allowed:
Exact inputs prohibited:
Files or screenshots allowed:
Connectors or apps involved:
Output destination:
Human review owner:
Redaction rule:
Retention or deletion rule:
Offboarding step:
Escalation triggers:
Customer contract constraints:
Security/privacy evidence reviewed:
Approval decision:
Approved users or group:
Approval date:
Review date:
Notes:
This form is intentionally explicit. Most risky AI workflows fail because nobody names the source system, data owner, deletion rule, or prohibited inputs.
Data classification checklist
Use this checklist before approving the form.
- Public information only.
- Internal low-risk company information.
- Customer name, company name, email, phone, or address.
- Customer ticket content, support history, chat history, or call transcript.
- Account ID, tenant ID, order ID, invoice ID, or CRM object ID.
- Contract, pricing, renewal, discount, or commercial terms.
- Product logs, usage logs, IP addresses, device identifiers, or trace IDs.
- Source code, repository metadata, GitHub issues, or security discussions.
- Screenshot, file upload, attachment, spreadsheet, or exported report.
- Password, API key, token, cookie, private key, recovery code, or secret.
- Payment card, bank, payroll, tax, health, HR, legal, child, government, or regulated financial data.
Any checked item below ordinary customer contact details should trigger a narrower workflow, redaction rule, or escalation.
Minimum controls
| Control | Minimum rule |
|---|---|
| Tool account | Use a managed business/team workspace for work data. |
| Owner | Every approved workflow has a business owner and data owner. |
| Redaction | Customer identifiers, secrets, payment details, and unrelated context are removed unless specifically approved. |
| Human review | AI output is reviewed before it reaches a customer, CRM record, ticket, public page, or production workflow. |
| Connectors | Gmail, Drive, Slack, CRM, helpdesk, GitHub, calendar, and custom MCP access require separate connector approval. |
| Retention | The workflow defines whether chats, files, project data, summaries, and outputs are deleted or retained. |
| Offboarding | User removal includes source-system access and AI workspace/project access. |
| Incident path | Secrets, regulated data, breach reports, and customer complaints have a named escalation owner. |
| Review cadence | New workflows are reviewed after two weeks, then monthly or quarterly depending on risk. |
OpenAI says ChatGPT Business workspace data is excluded from training by default, but that does not replace customer-data approval. Training policy, access scope, retention, sharing, and customer commitments are separate controls.
Approval outcomes
| Outcome | Meaning | Next action |
|---|---|---|
| Approved | Narrow workflow, named owner, managed tool, clear data boundary, and review date. | Add to approved AI workflow register. |
| Pilot | Useful workflow but limited evidence, new team behavior, or uncertain output quality. | Limit users and review after two weeks. |
| Restricted | Customer data is sensitive, broad, connected, contractual, or hard to redact. | Narrow scope, add owner review, or move to a safer system. |
| Blocked | Secret, regulated data, no owner, unmanaged account, broad customer export, or unclear retention. | Do not use AI until remediated. |
| Escalate | Legal, security, compliance, contractual, or incident context is present. | Route to the responsible owner. |
Workflow register
After approval, store the decision in a simple register.
| Field | Example |
|---|---|
| Workflow | Redacted support reply drafting |
| Status | Pilot |
| Tool | ChatGPT Business |
| Owner | Support lead |
| Data allowed | Redacted ticket excerpts |
| Data prohibited | Secrets, screenshots, payment data, contracts, regulated data |
| Users | Tier 1 support team |
| Retention | Delete chats after reply draft is reviewed |
| Review date | 2026-06-17 |
| Evidence | OpenAI business data docs, support policy, redaction checklist |
The register should live where support and operations actually look: handbook, Notion, Linear, Jira, spreadsheet, or a security wiki.
Escalation triggers
Stop the lightweight approval process when any of these appear:
| Trigger | Escalation owner |
|---|---|
| Password, API key, token, cookie, private key, or recovery code | Security or credential owner |
| Customer breach allegation, vulnerability report, abuse report, or incident evidence | Incident owner |
| Payment card, bank, tax, payroll, or regulated financial data | Finance/security owner |
| Health, HR, child, government, legal, or regulated data | Legal/security/compliance owner |
| Customer contract limits AI processing, subcontractors, data residency, or retention | Contract/account owner |
| Bulk customer export or cross-customer trend analysis | Data owner and business owner |
| Connector to Gmail, Drive, Slack, CRM, helpdesk, GitHub, or calendar | Source-system owner and workspace admin |
Escalation does not always mean “never use AI.” It means the normal small-team approval path is not enough.
Evidence checked
- OpenAI business data privacy, security, and compliance
- Managing data, sharing, and privacy in ChatGPT Business
- FTC Protecting Personal Information: A Guide for Business
- FTC Data Security guidance
- NIST Privacy Framework
- NIST AI Risk Management Framework
- How to redact customer tickets before using AI
- AI policy for support teams using ChatGPT
FAQ
Is this a legal approval form?
No. It is an operating control for small teams. If the workflow touches regulated data, customer contractual limits, legal files, payment data, health data, or security incidents, route it to a qualified owner.
Do we need the form if we use ChatGPT Business?
Yes. ChatGPT Business improves the baseline compared with unmanaged personal accounts, and OpenAI says Business workspace data is excluded from training by default. You still need to decide which customer data is allowed, who can use it, what gets redacted, and how outputs are retained.
Who should approve customer-data AI workflows?
At minimum: the business owner, data owner, and workspace admin. Add legal, security, finance, HR, or account-owner review when the data class requires it.
How often should approvals be reviewed?
Review new workflows after two weeks. After that, review monthly for high-risk workflows and quarterly for stable low-risk workflows. Review immediately after customer complaints, tool changes, connector changes, employee offboarding, or incidents.
Should approvals live in the AI tool?
No. Keep the approval record in your normal system of record: ticketing, wiki, spreadsheet, security tracker, or operations handbook. The AI tool should not be the only place where the approval is documented.
Recommended next step
Pick one customer-data workflow your team already wants to use with AI, fill out the approval form, and run the AI Tool Risk Checker. Add the final approval status to the Small Team AI Security Checklist.