For executive assistants, the confidentiality decision needs to happen before information enters the model.

Removing a name after a sensitive thread has already been uploaded does not undo the disclosure. A safer workflow classifies the input, minimizes it, and uses the organization’s approved environment from the start.

Use organizational rules first

The useful question is not simply “is this AI tool secure?”

Ask whether this specific use is authorized under the employer’s policies, account type, data controls, retention rules, access controls, and technical configuration. A capability available in one managed workspace may not be suitable in a personal account.

If a category of information is not permitted, do not upload it because the task would be more convenient.

Classify the information elements

A routine-looking task can contain several different sensitivity levels.

The book uses working categories such as public, internal, sensitive, and restricted. These are not legal definitions; they are a prompt-screening device that should be replaced by the organization’s own classification scheme where one exists.

Consider individual elements rather than assuming the whole document has one risk level. An agenda may contain an ordinary meeting title alongside personnel, board, commercial, legal, or security-sensitive details.

Minimize before redacting

AI often needs much less context than users first assume.

A tone rewrite may need the current draft and desired style, not the whole historical email chain. An agenda may need objectives and topics, not biographies. A travel comparison may need dates, locations, policy constraints, and preferences, not identity or payment data.

When real identities are unnecessary, use neutral placeholders such as [EXECUTIVE], [CLIENT], [PROJECT ALPHA], or [CITY A].

Redaction is more than removing names

A person or organization can remain identifiable from the combination of role, date, location, unusual event, salary, contract figure, or other context.

Sanitization means removing or generalizing details that are not required for the task, not merely deleting proper nouns.

Create a safe stop

Stop when the task requires information you are not authorized to disclose, when you cannot confirm which workspace or account is active, or when the output would expose source material to a new audience without permission.

For recurring tasks, define a standard input package: permitted fields, prohibited fields, and the authoritative source for each field. This reduces repeated privacy decisions under time pressure.

Then continue with the five-stage controlled workflow and keep external communication inside clear authority and disclosure boundaries.

The complete book is The AI Workflow Playbook for Executive Assistants.