Promoted on Friday, managing on Monday: the first 90 days
Your best engineer now runs the team and nobody told them how. What the first ninety days should actually contain, and what the business owes them.
Read the articleGanesh HS ·
A services firm discovered, more or less by accident, that an analyst had been pasting sections of a client contract into a public chatbot to summarise them. She was not being careless in her own mind — she was under deadline pressure, the tool was obviously useful, and nobody had ever told her not to. There was no policy. There was not even an informal norm.
The reaction was a hurriedly circulated ban. Three months later the usage was identical and the visibility was worse, because people had simply stopped mentioning it.
The tools are free, they are on personal phones, and they make a genuinely difficult task easier. A policy that says no, with no enforcement mechanism and no alternative, asks people to be slower for a reason nobody has explained to them.
What a ban reliably produces is the worst configuration: the same usage, now invisible, by people who will not ask a question when they are unsure because asking would admit the behaviour. The organisation loses its ability to see the risk without reducing it.
The alternative is not permissiveness. It is a small number of clear rules that people can actually follow, plus the training to follow them.
Policies written around named products — this tool approved, that one not — are out of date within a quarter and become a list nobody reads. Writing the rules around what is being put in survives the churn.
RED NEVER into any external tool
Client data, contracts, personal data of
employees or candidates, salary information,
anything under an NDA, source code where the
contract forbids it, medical or ID documents.
AMBER Only into approved tools with a business account
Internal documents, draft strategy, unpublished
financials, meeting notes naming individuals.
GREEN Anything goes
Public information, generic drafting, learning,
code snippets with nothing identifying in them,
rewriting your own text for clarity.Most day-to-day use is green, which is worth saying explicitly — a policy that reads as a list of prohibitions gets ignored wholesale, including the parts that matter. Naming the large permitted space is what makes the red line credible.
One test people can apply without consulting anybody: would you be comfortable if this text appeared on a public website tomorrow with your employer's name attached? It is imprecise and it resolves the majority of cases correctly in about two seconds.
Data going in is the risk that gets attention. Output coming out unchecked causes at least as much damage and is harder to spot.
These tools produce fluent, confident text regardless of whether the content is correct. A summary that quietly inverts a contractual obligation, a figure that was never in the source, a citation that does not exist — all of it arrives looking exactly like competent work. The reviewer's usual signals for sloppiness, which are mostly stylistic, are absent.
Short enough to be read. One page is achievable and two is the limit. It needs five things and nothing else.
Generic examples do not transfer. "Client contracts" means something concrete in a services firm and something different in manufacturing, and the examples are what people remember.
A short named list with business accounts where data is not used for training, and the name of the person who adds to it. A route to request a new tool matters more than the list, because the list will be wrong within months.
One sentence: the person who uses the output is responsible for it. This is the sentence that does the most work in the whole document.
Somebody will paste something they should not have. A stated, non-punitive route to report it within 24 hours is the difference between finding out and not. Businesses that skip this line find out months later, from someone else.
A named person, not a mailbox. Most questions are five-second questions and they go unasked when there is nowhere obvious to put them.
A circulated policy changes very little on its own. What changes behaviour is a short, practical session using the tools people already use, on the work they actually do.
The useful version covers three things: where these tools are genuinely good and where they are quietly unreliable, how to check output without spending more time than you saved, and a walk through the three tiers using real examples from the business. Ninety minutes is usually enough, and it is more effective than the policy document by a wide margin — which is the case for treating this as digital and AI workplace productivity capability-building rather than as a compliance exercise.
It is also worth training managers separately, because they face a question their teams do not: how to evaluate work when they cannot tell how it was produced. The honest answer is that they should assess the output on its merits and hold the person accountable for it — which is what they were always meant to do, and which most performance conversations have never been explicit about. Where a business has competency frameworks, this is worth writing into them rather than leaving as a verbal norm, and competency and talent management is where that definition belongs.
Data protection obligations, contractual restrictions in client agreements, and sector-specific rules vary considerably and change. Nothing here is a legal position, and a policy that needs to stand up to a client audit or a regulator should be confirmed with a qualified professional before it is circulated.
What is safely within reach without legal advice is the readiness work: knowing which of your data is red, which tools people are already using, whether anyone has been told anything, and whether there is a route to report a mistake. Most businesses that think they have an AI policy problem in fact have not yet done that inventory.
Practically, that is a short exercise — ask each team what they use and for what, without consequence attached to the answer, and write down what comes back. It usually takes a week and it is the input to everything else, including deciding what digital and AI workplace productivity training should cover. Where it turns out the underlying problem is that nobody knows who owns which policy or how one gets updated, that is a governance gap rather than a technology one, and HR policies and governance work is the place it gets fixed.
Only if you can enforce it, which almost no business can while the tools are free and on personal devices. An unenforceable ban converts visible usage into invisible usage and removes your ability to manage the risk at all.
No confidential or personal data into tools you do not control. If a business only ever communicates one rule, that is the one, because it is the one whose consequences are hardest to undo.
Either works. A section inside an existing policy is often better because it is already part of onboarding and already has an owner. What matters is that someone is responsible for keeping it current.
Ask, without consequences attached to the answer. An amnesty question produces a far more accurate picture than monitoring, and it tells you what the tools are being used for, which is the more useful half.
Set the norm deliberately rather than leaving it to individuals. A reasonable default is no disclosure for routine drafting, explicit disclosure for analysis or client-facing work where the method affects how the output should be weighed.
Workplace behaviour and the management capability a growing business runs on.
Discuss a Custom Training ProgrammeYour best engineer now runs the team and nobody told them how. What the first ninety days should actually contain, and what the business owes them.
Read the articleGood trainer, engaged room, excellent feedback forms — and no observable difference six weeks later. What went wrong, and what a training day needs around it.
Read the articleFour people were copied, everyone read it, nobody moved. What separates an email that produces action from one that produces a thread.
Read the articleAs your team grows, manual coordination leads to compliance risks and payroll errors. A free HR audit shows you where yours are.
Prefer the full picture? Request a free 360-degree HR audit.