Playbooks

AI security playbooks

Policies, checklists, and rollout guidance for small teams using AI at work.

30-day AI security rollout plan for small teams

A practical 30-day rollout plan for approving AI tools, setting data rules, reviewing connectors, browser extensions, meeting bots, developer AI, incidents, and monthly AI security operations.

Founders, operators, IT owners, engineering leads, and managers rolling out AI security controls in a 1-50 person team Medium

Password managers and AI browser extensions

A practical small-team playbook for deciding when AI browser extensions can run near password managers, autofill forms, admin pages, and credential workflows.

Small-team founders, IT owners, Google Workspace admins, operations leads, and security-conscious managers reviewing AI browser extensions near password managers Medium

Chrome Enterprise extension policy for startups

A practical startup playbook for using Chrome Enterprise extension policy to block unknown extensions, allow approved AI tools, restrict sensitive sites, and manage offboarding.

Startup founders, Google Workspace admins, operations leads, IT owners, engineering managers, and security-conscious teams that need lightweight Chrome extension controls Medium

AI extensions that can read Gmail or Google Docs

A small-team playbook for reviewing AI browser extensions and connected apps that can read Gmail, Google Docs, Google Drive files, or selected browser content.

Small-team founders, Google Workspace admins, IT owners, support leads, sales managers, recruiters, and operators approving AI extensions that touch Gmail, Docs, Drive, or browser content High

How to review an AI Chrome extension before install

A practical review workflow for AI Chrome extensions before they read pages, inject scripts, connect to SaaS apps, or run inside sensitive work tabs.

Founders, workspace admins, IT owners, operations leads, support managers, sales leaders, recruiters, and small-team security owners reviewing AI Chrome extensions before employee installation High

Customer call AI summary approval workflow

A practical approval workflow for AI-generated customer call summaries before they are shared, emailed, stored in CRM, or used for account decisions.

Small-team founders, sales leaders, customer success managers, account owners, RevOps leads, support leads, and workspace admins approving AI summaries from customer calls Medium

Where should AI meeting transcripts be stored?

A practical storage policy for AI meeting transcripts, summaries, recordings, clips, and action items in small teams.

Small-team founders, operators, workspace admins, sales leads, customer success leads, recruiters, and department owners deciding where AI meeting transcripts should live Medium

AI meeting bot policy for hiring interviews

A practical policy for using AI meeting bots in recruiting calls, hiring interviews, candidate screens, panel interviews, and debriefs.

Founders, recruiters, hiring managers, people operations leads, interviewers, and workspace admins approving AI meeting bots for candidate interviews High

AI meeting bot policy for sales calls

A practical policy for small sales teams using AI meeting bots, call summaries, transcripts, CRM notes, and follow-up drafts on prospect and customer calls.

Small-team founders, sales leads, customer success leads, revenue operators, and workspace admins approving AI meeting assistants for sales calls Medium

ChatGPT projects and shared workspace risks

A practical security guide for small teams using ChatGPT Projects, shared projects, files, instructions, memory, links, and workspace collaboration.

Small-team founders, operators, workspace admins, support leads, and project owners using ChatGPT Projects Medium

AI policy for support teams using ChatGPT

A practical ChatGPT policy for small support teams covering customer tickets, reply drafting, redaction, connectors, retention, escalation, and human review.

Support leads, founders, customer success managers, and operators using ChatGPT for ticket triage or customer replies High

How to redact customer tickets before using AI

A practical redaction workflow for small teams that want to use ChatGPT or other AI tools on customer support tickets without exposing unnecessary personal, account, billing, or security data.

Support leads, founders, operators, and customer-facing teams using AI to summarize, triage, or draft replies from customer tickets High

ChatGPT Business retention questions for small teams

The practical retention questions small teams should answer before using ChatGPT Business with customer data, files, projects, shared links, apps, and offboarded employees.

Small-team founders, operators, workspace admins, and support or sales leads evaluating ChatGPT Business data retention Medium

ChatGPT connector approval template for small teams

A practical approval template for ChatGPT apps and connectors that can reach Gmail, Drive, Slack, GitHub, calendars, tickets, CRM records, or internal knowledge.

Small-team founders, operators, workspace admins, and data owners approving ChatGPT apps and connectors High

AI code review policy for small engineering teams

A practical policy template for small engineering teams using AI to write code, review pull requests, and enforce secure review gates.

Small engineering teams using AI to write or review pull requests Medium

How to approve AI agents that can run terminal commands

A practical approval workflow for small engineering teams deciding when AI coding agents may run shell commands, install dependencies, or touch production-adjacent systems.

Small engineering teams approving AI agents with shell or terminal access High

AI coding tools and production incident risk

A practical production-risk playbook for small engineering teams using AI coding assistants or agents near production systems.

Small engineering teams using AI coding agents near production code High

Cursor Privacy Mode checklist for small teams

A practical checklist for verifying Cursor Privacy Mode before a small engineering team uses Cursor with private source code.

Small engineering teams evaluating Cursor Privacy Mode Medium

Cursor rules for repositories with secrets

A practical rule set for using Cursor in repositories that may contain API keys, private keys, .env files, customer fixtures, or deployment credentials.

Small engineering teams using Cursor on source code High

AI meeting bot consent and retention template for small teams

A practical notice, consent, retention, and sharing template for AI meeting bots, transcripts, summaries, and meeting recaps.

Founders, operators, sales leads, customer success leads, and managers Medium

ChatGPT connectors and customer data: small-team security checklist

How small teams should approve ChatGPT connectors to Gmail, Drive, Slack, GitHub, CRM, and other systems before customer data becomes searchable.

Founders, operators, support leads, and workspace admins High

Chrome AI extension permissions explained for small teams

A practical guide to Chrome AI extension permissions, host access, match patterns, clipboard access, and extension approval for small teams.

Founders, operators, IT admins, and technical leads High

Cursor AI agent permissions checklist for small teams

A practical checklist for deciding when Cursor agents may read files, run commands, use terminals, and touch repositories.

Engineering leads, developers, and technical founders High

AI browser extensions security checklist

A practical checklist for reviewing AI browser extensions before they read pages, write text, inject scripts, or connect to company apps.

Remote teams and browser-heavy operators High

AI meeting bots: privacy and compliance risks

How small teams should evaluate AI meeting bots before recording calls, transcribing customers, or summarizing internal meetings.

Sales, customer success, recruiting, and leadership teams High

Can employees paste customer data into ChatGPT?

A small-team decision guide for customer data, ChatGPT, AI workspaces, masking, approval, retention, and employee rules.

Founders, operators, and support leads High

How to write an AI usage policy for a 10-person company

A short AI usage policy framework for small companies that need rules before employees use AI tools with work data.

Founders and operations leads Medium