Data Handling and Responsible Reliance

The question every new user actually has is "can I paste this in?" — and it is the right question. The first safety habit is not about what Claude can do. It is about what information may be used here, and how the result will be checked before anyone relies on it.

Classify before you share

Your organization's data policy is the authority; this program's job is to make it usable in the moment. If no policy exists yet, pause on anything beyond clearly public material until Phase 3, where you will help write one.

InformationDefault action
PublicUse within normal quality controls
InternalUse only in an approved company account and workflow
ConfidentialConfirm the approved enterprise surface, retention settings, and access
Restricted or regulatedDo not use unless policy and an authorized owner explicitly permit it

At Northstar Components that looks like: a published product datasheet is public — go ahead. The sales playbook is internal — fine in the company workspace, not in a personal account. The Helios contract terms are confidential — enterprise surface only, and check who can see the conversation. A spreadsheet of employee salaries is restricted — it does not enter a prompt because someone happens to have the file.

Then minimize. Having access to information does not make it appropriate to include. If the task is "improve the tone of this support reply," Claude does not need the customer's name, order history, or email address — strip what the task does not require. The best-protected data is the data that never entered the context.

Make Claude show its uncertainty

Claude fills gaps with reasonable-looking assumptions — helpful in a brainstorm, dangerous in sensitive work. For anything consequential, make uncertainty visible by instruction:

Before answering: state your assumptions, list any information that is
missing, and clearly separate what the sources say from what you are
inferring. If the evidence is insufficient for a recommendation, say so
instead of recommending.

This single paragraph, added to a sensitive prompt or a Project's instructions, prevents more quiet errors than any amount of after-the-fact checking.

Decisions stay with people

Claude can prepare the analysis, draft the language, and flag the issues. The accountable person still makes employment, legal, financial, security, safety, and customer-impacting decisions. This is not a disclaimer — it is a design rule you will build into every workflow in this course: the workflow ends at a named human, and everyone can see where.

Stop and escalate when

  • The data classification is unclear
  • You do not know which surface is approved for this material
  • The output could materially affect a person
  • The workflow would create an external commitment without review

"Stop and ask" is a fluency skill, not a failure. The escalation path gets a named owner in the AI Usage Policy lesson.

Practice

Classify three examples from your own department:

  1. A public webpage and a draft marketing brief
  2. A customer support conversation containing personal details
  3. An internal spreadsheet with forecasts and employee names

For each: what can be used, where may it be used, what should be stripped out first, and who approves the final output?

Ready to move on

You can classify the data in your chosen workflow, name the approved surface for it, strip what the task does not need, and say who verifies the result.