1. Tool and data
- Is the tool approved for this task?
- What is the data classification?
- Can the task use sanitized or public inputs instead?
AI TRAINING & ENABLEMENT
Use these short templates during real work. Replace bracketed text, keep inputs inside approved tools, and preserve the human review point that matches the risk.
Run this check before sharing data or connecting a tool. If one answer is unclear, pause and use the approved governance or security path.
Use the fields that change the work. Leave out fields that add length without changing the result.
I need [artifact, decision, or change] for [audience or owner].
Use [approved sources]. The relevant current state is [facts].
Stay within [scope]. Follow [policy, tone, standard]. Do not [exclusions].
Use [representative input or approved pattern] as a reference. Keep policy in its approved source.
Return [structure] with [required fields, citations, or labels].
Before finishing, compare the output with [acceptance criteria, source, tests] and mark uncertainty.
Review effort should match the cost of being wrong.
Use this brief for an approved technical harness. Ask it to inspect and propose a plan before changes.
Goal: [requested behavior]
Relevant evidence: [ticket, files, error, logs]
Acceptance criteria: [observable conditions]
In scope: [areas that may change]
Out of scope: [areas and actions excluded]
Ask first: [commands or decisions requiring approval]
[architecture], [conventions], [approved dependencies], [test commands], [security requirements]
[tests pass], [diff reviewed], [docs updated], [assumptions reported], [required owner approves]
Choose a pattern after the workflow is clear. Prefer a prompt, skill, or fixed automation when it solves the problem with less risk.
Trigger, frequency, inputs, output, current time or quality baseline, and accountable owner.
Chat, reviewed template or skill, deterministic automation, supervised harness, or agent.
Approved data, minimum tools, narrow permission scopes, and actions that require approval.
Checks, logs, tests, output review, pilot metric, failure signal, and recovery path.
Keep each case to five minutes and remove confidential or identifying information.
What task did you improve? Who performs it? How often? What did the old workflow cost in time, quality, or rework?
Which approved tool and context did you use? What could it access? Where did a person review or approve?
What changed? Show comparable artifacts, elapsed time, test output, review findings, or repeated examples.
What should the team standardize, test again, or stop? Name the owner and the next evidence needed.
The curriculum uses EXIST’s internal assessment for program priorities and primary sources for technical and risk guidance.
Internal survey summary with 113 responses collected from 26 August to 3 September 2026.
Program objectives, maturity model, delivery format, session runbooks, and success signals.
Risk guidance covering confabulation, information integrity, privacy, security, human oversight, testing, and monitoring.
Govern, map, measure, and manage functions, including explicit human roles and repeatable evaluation.
Primary security guidance on prompt injection, sensitive information disclosure, improper output handling, excessive agency, and related risks.
Practical guidance on clear goals, specific requirements, relevant context, examples, and avoiding ambiguity.
Official overview of prompts, resources, tools, control boundaries, and connection patterns.