AI Strategy & Governance for Business Leaders

Draw the Data and Accountability Map

Identify what enters the workflow, where copies travel, and who owns each control and decision.

In this chapter

  • Map inputs, outputs, logs, and retention assumptions
  • Separate accountability from tool operation
  • Identify questions that must be resolved before real data is used
Follow data and responsibility
  1. Source tickets
  2. Drafting step
  3. Draft storage
  4. Review evidence
  5. Internal handoff

Each stage needs a data inventory and an accountable role, even in a small pilot.

Follow the copies

A workflow diagram should show more than the arrow from user to assistant. Information may also enter a browser history, application log, exported document, support ticket, or retained conversation. Harbor Pilot starts with synthetic service tickets stored in a local exercise folder. Its draft summaries go into a separate review sheet. No customer account, mailbox, or production system is connected. Label these facts explicitly rather than assuming everyone shares the same mental model.

Create a map with five boxes: source tickets, drafting step, draft storage, review record, and final internal handoff. Under each box, list the data fields and owner role. Synthetic fields might include ticket ID, product label, reported symptom, and requested next step. Contact information is unnecessary for learning summary quality, so exclude it. Removing unnecessary fields reduces the information you must protect and the number of questions you must answer.

Assign decisions and controls

Use an accountability table with decision, accountable role, operator, evidence, and escalation contact. The pilot sponsor decides scope; the workflow owner maintains instructions; the reviewer checks drafts; the security or privacy reviewer assesses proposed real-data use. One person may hold several roles in a small team, but the decisions should remain visible. 'The vendor handles security' is not a complete assignment of your organization's responsibilities.

Work through an example: an employee proposes pasting fifty real customer tickets into a personal AI account. The data map cannot confirm approval, retention settings, or contractual terms. The correct status is blocked pending authorized review, not 'safe because the sample is small.' Continue the educational exercise with fictional tickets. A missing answer on the map is a work item, not permission to invent a reassuring assumption.

Distinguish deletion from a button label

A delete button does not explain backups, logs, or copies. Ask about retention, export, deletion propagation, access, and incident contacts. Date and source the answers. Real deployments require appropriate organizational and legal review; this register is not a compliance determination.

Create the pilot data register

  • Draw the five-box synthetic workflow and list every field stored at each step.
  • Create five accountability rows for scope, data approval, draft review, incident response, and retirement.
  • Add a proposed real-ticket upload as a blocked change request. Identify the unanswered evidence needed before anyone could approve it.

Expected checks

  • No real personal information is necessary for the exercise.
  • Every stored artifact has an owner role and a retention question.
  • Unanswered questions remain visibly unresolved and do not become assumed vendor capabilities.

Check your understanding

A tool offers a delete-conversation button. What does that establish by itself?

  • All provider backups and logs disappear immediately.
  • The organization has met every privacy requirement.
  • Only that a deletion action exists; its full scope still needs evidence.
Answer explanation

A user-interface control does not describe every storage layer or contractual obligation. The team must inspect the relevant documentation and terms before making broader claims.

Official tools & further reading

The curriculum

  1. Start with the Process, Not the Tool — Free preview

    Select a bounded workflow using evidence, reversibility, and consequences.

  2. Draw the Data and Accountability Map — Free preview

    Identify what enters the workflow, where copies travel, and who owns each control and decision.

  3. Turn Vendor Claims into Evidence — Sign-in access

    Ask precise security, service, and exit questions without confusing a sales response with a verified control.

  4. Measure Useful Work, Not Output Volume — Sign-in access

    Evaluate missing facts, unsupported claims, and reviewer burden against a baseline.

  5. Calculate the Cost of a Usable Result — Free preview

    Build a transparent cost model with human review, retries, setup effort, and explicit assumptions.

  6. Make Human Review a Real Control — Sign-in access

    Design review authority, evidence, workload limits, and escalation so approval is more than a checkbox.

  7. Roll Out with a Way Back — Sign-in access

    Plan a small, observable adoption sequence with staff training, feedback, rollback, and change control.

  8. Present the Harbor Pilot Decision — Sign-in access

    Assemble the evidence into an honest go, revise, defer, or stop recommendation that another manager can inspect.