Retour au blog

A Practical Routine for Using AI Well

13 septembre 20266 min
Gestion des flux de travail

Cet article n'est pas encore traduit — voici la version originale en anglais.

AI is most useful when a person can say what a good result looks like. That can be a rough outline, a first draft, a summary or a small piece of working software. The useful starting point is a job with a boundary and a way to check it.

The AI Control Layer is our way of connecting that boundary to documentation, permissions and evidence. You can apply the routine below with a simple chat tool or an integrated assistant.

1. Write a brief before a prompt

State the outcome, the audience, the inputs and the acceptance check. Separate facts from assumptions. Include the constraints that would make an otherwise impressive answer unusable.

For example:

Draft a short internal guide for recording equipment returns. Use the approved process below. The audience is a new support colleague. Preserve the named approval step. Mark missing details as questions. A reviewer must be able to trace every operational instruction to the supplied process.

This brief gives the reviewer a concrete test. “Make this better” leaves the model and reviewer guessing about the same things.

2. Choose the minimum data

Use invented examples when real records are unnecessary. Remove secrets, private identifiers and unrelated customer details. Check the organization's rules and the provider's current handling of submitted material before sharing sensitive information.

Local execution changes where a model runs. It does not tell you everything about extensions, telemetry, logs, network calls or access to the machine. Trace the complete workflow before describing it as private.

3. Separate reading from acting

Ask for a draft or proposed change first when the action has consequences. Decide who can approve sending, deploying, deleting or changing a record, and enforce permissions in the connected system.

An assistant reading a document can encounter instructions planted inside it. OWASP describes this as a prompt-injection risk and recommends measures including constrained access and separation of untrusted material. Treat retrieved text as material to inspect; it cannot authorize new actions. OWASP prompt-injection guidance.

A sentence saying “ignore malicious instructions” is useful guidance but does not replace an allowlist or a server permission check. Try a harmless hostile sentence in a synthetic document and check what happens before trusting a workflow with real data.

4. Review against the job

Use different checks for different outputs:

  • For a summary, compare the important statements with the underlying records and look for omissions.
  • For a calculation, recompute a representative example and test missing or unusual values.
  • For code, inspect the diff and run tests that would catch the original failure.
  • For a message, verify names, facts, recipients and the action being requested before sending.

Do not ask the same model to approve its own output and count that as independent verification. A second review can help, but evidence still needs to come from the source or a meaningful test.

5. Keep a small evaluation set

Save a few sanitized tasks with expected outcomes: a normal request, missing data, conflicting instructions and an out-of-scope action. Repeat them when changing a model, integration or prompt. Record mistakes as well as successful results.

Decide what should happen when the assistant cannot complete a task. A clear “data unavailable” can be the correct answer. Quietly inventing a value cannot.

6. Improve the process

Record what needed correction. Was the source outdated, the instruction ambiguous, the permission too broad or the acceptance check missing? Update the appropriate document and test, then try the task again.

Start with the workbook. For this product's actual tool boundaries, use the OpenTechnologyApp AI control guide. General good practice should never be mistaken for a feature the app has already implemented.

Contactez-moi

Un sujet vous intéresse ? Laissez un mot et choisissez une catégorie. Je suis aussi disponible pour une réunion de conseil gratuite — écrivez-moi et nous organiserons cela.