01
Governance does not need to be complicated
A small business needs clear decisions more than a large policy manual: which tools are approved, what information may be entered, which outputs require review, who owns each workflow and how problems are reported.
02
Set five minimum controls
- Approved toolsName the business accounts and versions staff may use. Personal accounts should not hold business data.
- Data rulesDefine information that must never be entered and when de-identification is required.
- Human reviewKeep approval for money, legal or professional advice, health and safety, staffing, sensitive customers and final records.
- AccessGive connected workflows only the systems and permissions they genuinely require.
- Testing and logsTest normal cases and exceptions, preserve useful records and define how to stop the workflow.
03
Accuracy and hallucinations
AI can produce confident but incorrect answers. Require source-grounded work where facts matter, ask the system to identify uncertainty, and make verification part of the workflow rather than an optional final thought.
04
Help the team adopt it
- Explain the problem being solved, not just the tool being installed.
- Show approved examples and unacceptable uses.
- Invite staff to report weak outputs and awkward exceptions.
- Measure whether the new method reduces work rather than adding another step.
- Update documentation when the workflow changes.
The safest useful design is usually routine automation with visible exceptions—not pretending every case can run without people.
05
Monthly review
Check usage, errors, exceptions, access, staff feedback and actual business value. Pause or simplify any workflow that creates more checking, confusion or risk than the manual process it replaced.