Playbooks
AI security playbooks
Policies, checklists, and rollout guidance for small teams using AI at work.
30-day AI security rollout plan for small teams
A practical 30-day rollout plan for approving AI tools, setting data rules, reviewing connectors, browser extensions, meeting bots, developer AI, incidents, and monthly AI security operations.
Password managers and AI browser extensions
A practical small-team playbook for deciding when AI browser extensions can run near password managers, autofill forms, admin pages, and credential workflows.
Chrome Enterprise extension policy for startups
A practical startup playbook for using Chrome Enterprise extension policy to block unknown extensions, allow approved AI tools, restrict sensitive sites, and manage offboarding.
AI extensions that can read Gmail or Google Docs
A small-team playbook for reviewing AI browser extensions and connected apps that can read Gmail, Google Docs, Google Drive files, or selected browser content.
How to review an AI Chrome extension before install
A practical review workflow for AI Chrome extensions before they read pages, inject scripts, connect to SaaS apps, or run inside sensitive work tabs.
Customer call AI summary approval workflow
A practical approval workflow for AI-generated customer call summaries before they are shared, emailed, stored in CRM, or used for account decisions.
Where should AI meeting transcripts be stored?
A practical storage policy for AI meeting transcripts, summaries, recordings, clips, and action items in small teams.
AI meeting bot policy for hiring interviews
A practical policy for using AI meeting bots in recruiting calls, hiring interviews, candidate screens, panel interviews, and debriefs.
AI meeting bot policy for sales calls
A practical policy for small sales teams using AI meeting bots, call summaries, transcripts, CRM notes, and follow-up drafts on prospect and customer calls.
ChatGPT projects and shared workspace risks
A practical security guide for small teams using ChatGPT Projects, shared projects, files, instructions, memory, links, and workspace collaboration.
AI policy for support teams using ChatGPT
A practical ChatGPT policy for small support teams covering customer tickets, reply drafting, redaction, connectors, retention, escalation, and human review.
How to redact customer tickets before using AI
A practical redaction workflow for small teams that want to use ChatGPT or other AI tools on customer support tickets without exposing unnecessary personal, account, billing, or security data.
ChatGPT Business retention questions for small teams
The practical retention questions small teams should answer before using ChatGPT Business with customer data, files, projects, shared links, apps, and offboarded employees.
ChatGPT connector approval template for small teams
A practical approval template for ChatGPT apps and connectors that can reach Gmail, Drive, Slack, GitHub, calendars, tickets, CRM records, or internal knowledge.
AI code review policy for small engineering teams
A practical policy template for small engineering teams using AI to write code, review pull requests, and enforce secure review gates.
How to approve AI agents that can run terminal commands
A practical approval workflow for small engineering teams deciding when AI coding agents may run shell commands, install dependencies, or touch production-adjacent systems.
AI coding tools and production incident risk
A practical production-risk playbook for small engineering teams using AI coding assistants or agents near production systems.
Cursor Privacy Mode checklist for small teams
A practical checklist for verifying Cursor Privacy Mode before a small engineering team uses Cursor with private source code.
Cursor rules for repositories with secrets
A practical rule set for using Cursor in repositories that may contain API keys, private keys, .env files, customer fixtures, or deployment credentials.
AI meeting bot consent and retention template for small teams
A practical notice, consent, retention, and sharing template for AI meeting bots, transcripts, summaries, and meeting recaps.
ChatGPT connectors and customer data: small-team security checklist
How small teams should approve ChatGPT connectors to Gmail, Drive, Slack, GitHub, CRM, and other systems before customer data becomes searchable.
Chrome AI extension permissions explained for small teams
A practical guide to Chrome AI extension permissions, host access, match patterns, clipboard access, and extension approval for small teams.
Cursor AI agent permissions checklist for small teams
A practical checklist for deciding when Cursor agents may read files, run commands, use terminals, and touch repositories.
AI browser extensions security checklist
A practical checklist for reviewing AI browser extensions before they read pages, write text, inject scripts, or connect to company apps.
AI meeting bots: privacy and compliance risks
How small teams should evaluate AI meeting bots before recording calls, transcribing customers, or summarizing internal meetings.
Can employees paste customer data into ChatGPT?
A small-team decision guide for customer data, ChatGPT, AI workspaces, masking, approval, retention, and employee rules.
How to write an AI usage policy for a 10-person company
A short AI usage policy framework for small companies that need rules before employees use AI tools with work data.