playbook

AI policy for support teams using ChatGPT

A practical ChatGPT policy for small support teams covering customer tickets, reply drafting, redaction, connectors, retention, escalation, and human review.

Audience: Support leads, founders, customer success managers, and operators using ChatGPT for ticket triage or customer replies Risk: High Evidence: OpenAI ChatGPT Business privacy and data controls documentation, FTC data security guidance, NIST Privacy Framework, and Cybergiz customer-data playbooks

Bottom line

Support teams can use ChatGPT to draft replies, summarize tickets, classify urgency, and turn messy customer reports into action items. They should not use it as an unmanaged copy-paste bin for raw tickets, customer exports, screenshots, account records, credentials, or regulated data.

Use this default policy:

Support may use approved AI tools only with redacted customer context, approved data sources, human review before sending, and a documented deletion or retention rule.

Start with the AI Tool Risk Checker for the exact support workflow, then record the operating rule in the Small Team AI Security Checklist. If the team uses ChatGPT Business, pair this policy with the ChatGPT Business retention questions guide and the customer ticket redaction workflow.

Support use-case matrix

Support taskAllowed by default?Required control
Drafting a generic help-center reply from public docsYesHuman review before sending.
Summarizing a redacted customer ticketYes, if approvedRedaction checklist and deletion rule.
Classifying ticket urgency or product areaYes, if redactedNo raw customer identifiers or secrets.
Rewriting tone of a support replyYesRemove customer identifiers first.
Using ChatGPT to search Gmail, Drive, Slack, CRM, or helpdesk dataNo, not by defaultConnector approval and source-system permission review.
Uploading customer screenshots, logs, contracts, invoices, or exportsNo, not by defaultWorkflow-specific approval; summarize manually when possible.
Answering legal, security, compliance, refund, or contractual questionsNo, not as final authorityQualified owner review before customer response.
Handling security incidents, exposed secrets, vulnerability reports, or abuse reportsNoRoute to incident/security workflow.
Processing regulated health, financial, HR, child, government, or legal dataNoEscalate before AI use.

The policy should make low-risk work easy and high-risk work explicit.

One-page support AI policy

Copy this into your support handbook and replace the bracketed fields.

Support AI Policy
Owner: [support lead]
Admin owner: [workspace admin]
Last reviewed: [date]

Approved tools:
- [Tool/workspace] for redacted ticket summaries, reply drafts, and internal triage.

Support may use approved AI tools for:
- Drafting customer replies from redacted ticket excerpts.
- Summarizing redacted ticket history.
- Classifying urgency, product area, and missing information.
- Rewriting tone or structure of a human-written reply.
- Creating internal troubleshooting checklists from public or approved internal docs.

Support must not enter:
- Passwords, API keys, tokens, session cookies, private keys, or recovery codes.
- Payment card, bank, payroll, tax, refund, invoice, or billing details unless explicitly approved.
- Health, HR, legal, child, government, financial, or other regulated data.
- Raw screenshots, logs, exports, contracts, or attachments unless the workflow is approved.
- Customer names, emails, phone numbers, addresses, account IDs, or company identifiers unless approved for the task.
- Security incident, vulnerability, abuse, or breach details outside the incident workflow.

All AI-generated customer replies must be reviewed by a human before sending.
Employees must report accidental restricted-data exposure to [owner] the same business day.

Keep the first version short. The goal is to change daily behavior, not produce a policy nobody reads.

Redaction rule

Support agents should use a redacted ticket excerpt by default.

Data typeRuleExample replacement
Customer identityReplace unless required for the task.[customer_name], [customer_company]
Contact detailsRemove.[email_removed], [phone_removed]
Account or order identifiersReplace with stable placeholders.[account_id_1], [order_id_1]
Payment or billing dataRemove and route through secure billing flow.[billing_detail_removed]
Secrets or credentialsStop and escalate.[secret_removed]
Screenshots or attachmentsSummarize manually.Screenshot shows SSO error after redirect.
Regulated or high-risk dataDo not use in the normal AI workflow.Route to owner/legal/security.

Use the full redaction checklist for any workflow that touches customer tickets.

Approved prompt patterns

These prompts keep the AI task narrow.

Using the redacted ticket below, draft a concise support reply.
Do not infer customer identity, account details, billing status, or policy exceptions.
Ask for missing information when needed.
Do not include placeholders in the final reply.

Redacted ticket:
[paste redacted excerpt]
Summarize this redacted support ticket for internal triage.
Return:
1. Customer impact
2. Product area
3. Missing information
4. Suggested owner
5. Escalation required: yes/no
Rewrite this human-drafted reply to be clearer and calmer.
Do not add new facts, promises, timelines, refund commitments, security claims, or legal advice.

Do not use prompts like:

Search everything we know about this customer and write the best response.

Broad prompts encourage over-collection and make it harder to review what data the AI used.

Human review checklist

Before sending an AI-assisted support reply:

  • The source ticket was redacted or the workflow was explicitly approved.
  • The AI did not invent facts, timelines, product behavior, policy exceptions, or compensation.
  • The reply does not include placeholders, internal notes, customer identifiers, or unrelated context.
  • Security, legal, billing, refund, compliance, or contractual statements were reviewed by the right owner.
  • The reply does not expose another customer’s data.
  • The tone is appropriate and does not over-apologize, blame, or promise unavailable fixes.
  • The ticketing system remains the system of record.
  • The ChatGPT conversation was deleted or retained according to the approved retention rule.

Support quality still belongs to the support team. AI output is a draft, not a final answer.

Connector and helpdesk rules

Do not connect ChatGPT to Gmail, Google Drive, Slack, CRM, Zendesk, Intercom, Help Scout, GitHub, or another support source just because the integration exists.

Use this approval sequence:

  1. Name the business purpose.
  2. Name the source system and data owner.
  3. Define which tickets, channels, folders, repos, or accounts are in scope.
  4. Remove stale users and broad sharing in the source system.
  5. Decide whether the connector is read-only, search-only, or action-capable.
  6. Pilot with one support workflow and named users.
  7. Review sample outputs before expanding.

Record the decision with the ChatGPT connector approval template.

Escalation matrix

SituationSupport action
Customer pasted an API key, password, token, cookie, private key, or recovery codeStop AI use and route to security or the credential owner.
Ticket includes health, HR, child, legal, government, payment, or regulated financial dataRoute to the responsible owner before AI use.
Customer asks for legal, compliance, security assurance, or contractual commitmentsDraft internally only; qualified owner approves before sending.
Customer reports a vulnerability, breach, abuse, or active security incidentUse incident response process.
AI output suggests a refund, credit, contract change, SLA commitment, or deadlineSupport lead or business owner approves before sending.
Bulk support export or trend analysis across many customersRequire workflow approval, sampling, retention rule, and data minimization.

Rollout plan

PhaseActionExit criteria
Day 1Publish the one-page support AI policy.Support team acknowledges the policy.
Week 1Pilot redacted reply drafting for one low-risk ticket category.Five reviewed replies have no privacy or accuracy issues.
Week 2Add triage summaries and urgency classification.Support lead confirms output is useful and not over-collecting data.
Week 3Review whether any connector is truly needed.Connector request has owner, source scope, and approval record.
MonthlyReview mistakes, deleted chats, exceptions, and customer complaints.Policy is updated with real examples.

Evidence checked

FAQ

Can support use ChatGPT Business for customer replies?

Yes, if the workflow is approved, customer context is minimized, and a human reviews the final answer. OpenAI says ChatGPT Business workspace data is excluded from training by default, but that does not remove redaction, retention, connector, or customer-commitment risks.

Should support agents paste full tickets?

No. Use the minimum relevant excerpt. Full tickets often include unrelated customers, internal notes, logs, screenshots, billing details, old attachments, and security information.

Can AI send replies automatically?

Not for a small team starting out. Keep AI as drafting or triage support until the team has measured quality, privacy, escalation, and retention behavior.

What should we do if an agent pasted restricted data?

Report it the same business day to the support owner and workspace admin. Record the tool, account, data type, approximate time, and deletion or containment step. If credentials were involved, rotate them.

Do we need a different policy for connectors?

Yes. A connector can expose far more than one redacted ticket. Use a separate connector approval record before enabling ChatGPT access to email, files, Slack, CRM, helpdesk, GitHub, or calendars.

Pick one low-risk ticket category and run a one-week pilot with redacted excerpts only. Use the AI Tool Risk Checker before rollout and store the final rule in the Small Team AI Security Checklist.