playbook

AI meeting bot consent and retention template for small teams

A practical notice, consent, retention, and sharing template for AI meeting bots, transcripts, summaries, and meeting recaps.

Audience: Founders, operators, sales leads, customer success leads, and managers Risk: Medium Evidence: Microsoft Teams recording policy, Zoom AI Companion privacy and retention controls, and small-team meeting bot rollout guidance

Bottom line

AI meeting bots should not join every meeting by default. They create recordings, transcripts, summaries, action items, and sometimes searchable recaps. That output can contain customer names, pricing, hiring discussions, legal issues, health details, security incidents, roadmap plans, and employee performance notes.

Use a written rule before inviting bots to customer, hiring, legal, support, or internal-sensitive meetings.

This template extends the broader AI meeting bots privacy and compliance risks playbook.

Meeting classification

Meeting typeBot defaultReason
Public webinar or public demoAllow with noticeContent is intended for broad distribution.
Internal team standupAllow if team agreesLow sensitivity, but still may include customer or employee details.
Customer success callApproval requiredMay include customer issues, account details, contracts, or roadmap expectations.
Sales callApproval requiredMay include pricing, buying committee, contract, and personal data.
Hiring interviewRestrict by defaultCandidate privacy and employment law risk.
Legal, HR, finance, security incidentBlock by defaultSensitive and often privileged or regulated.
Board, acquisition, fundraisingBlock by defaultStrategic and confidential.

Use plain language at the start of a meeting and in the calendar invite:

This meeting may use an AI assistant to create a transcript, summary, and action items.
The output may be stored in our company workspace and shared with meeting participants or relevant internal owners.
Please say before we begin if you do not want the meeting recorded, transcribed, or summarized.
Do not share passwords, payment details, health information, private keys, or other restricted data during recorded parts of the call.

For external meetings, do not rely only on a small bot notification. Say it out loud or put it in the invite.

Retention settings

Decide retention before rollout:

OutputDefault retentionOwner
Audio/video recordingOff by default unless neededMeeting owner
Transcript30-90 days for normal business callsTeam lead
AI summarySame as transcript unless copied to CRM or project toolTeam lead
Action itemsKeep in task system, not only in bot appFunctional owner
Sensitive call outputDelete or restrict quicklyFounder, legal, or security owner

Microsoft documents Teams recording and transcript policy controls, including storage and permissions in OneDrive or SharePoint. Zoom documents AI Companion privacy, retention, and access controls, including admin-managed sharing behavior and zero data retention options for some temporary transcript inputs.

The practical point: choose a default retention period instead of letting every employee decide.

Sharing rules

Use these defaults:

  • Summaries from external customer calls can be shared with the account team, not the whole company.
  • Hiring summaries stay with the hiring team.
  • Incident summaries stay with incident owners.
  • Do not forward raw transcripts to vendors unless approved.
  • Do not paste transcripts into unrelated AI tools without a separate approval.
  • Do not use bot summaries as final legal, HR, financial, or security decisions.

If the bot cannot enforce sharing rules, enforce them in the workflow and audit access periodically.

Vendor approval checklist

Before approving a meeting bot, collect:

  • Which meeting platforms it joins.
  • Whether it records audio/video or only generates notes.
  • Whether it stores transcripts, summaries, chat, screen content, or metadata.
  • Whether admins can set retention.
  • Whether admins can disable email delivery or public summary links.
  • Whether summaries can be downloaded, copied, or forwarded.
  • Whether legal hold, eDiscovery, or export features apply.
  • Whether the vendor uses meeting content for model training.
  • Whether the bot can join external meetings automatically.
  • How offboarding removes bot access.

Rollout policy

AI meeting assistants are allowed only for approved meeting types.

Meeting owners must notify participants when AI recording, transcription, or summarization is used.

Employees may not invite AI meeting bots to legal, HR, finance, board, acquisition, security incident, regulated-data, or highly sensitive customer meetings unless leadership approves the specific use case.

Meeting summaries and transcripts must follow the team's retention and sharing rules.

If restricted information is captured, notify the meeting owner and delete or restrict the output where possible.

Evidence checked

FAQ

Is a calendar bot notice enough?

Not for sensitive external meetings. Put the notice in the invite and say it at the start. Give participants a clear chance to object.

Should transcripts be retained forever?

No. Default to a short retention period unless there is a business, legal, or contractual reason to keep them longer.

Should bots join hiring calls?

Restrict by default. If the team uses a bot for hiring, make the notice explicit, limit access, and define retention before the first interview.

Add the notice template to your meeting invite policy, then run the AI Tool Risk Checker for the first meeting bot workflow.