Team tool · Template
Team AI charter
One page that records how your team applies the ten principles: approved tools, data classification, checkpoints, sources, agents and who to contact when something goes wrong.
Principles involved
Overview
Most of the ten principles apply to individual practice. A few things only a team can decide, and the charter is where you write them down. Keep it to a page or two, in plain words, where the team works.
From the security side, the UK’s National Cyber Security Centre says individual users shouldn’t carry the whole burden of using AI safely. The charter is how a team shares it.
Data traffic light
Most teams need a simple way to say which information can go into which tools. A traffic light works well:
- Green: public information, fine in any approved tool.
- Amber: internal information, only in tools your organization has approved for it.
- Red: personal, client-confidential or regulated information, only in tools and processes cleared for it, and only the minimum the task needs.
Review
Review the charter when you add a tool, an agent or a new kind of data, after an incident or near miss, and at least twice a year.
The template
Each field says what to record. The fictional example shows what a finished record can look like.
Fictional example: the customer success team at Lumen, an invented software company.
- 01Approved AI tools (principle 3)
-
List the AI tools and accounts the team may use for work, and what each may be used for. Include assistants built into software you already use.
Fictional example
Lumen’s work assistant, under the company contract, for drafting, summaries and research. The CRM’s built-in assistant for account notes. No personal AI accounts for client information.
- 02Data traffic light (principle 3)
-
Say which kinds of information are green, amber and red for your team, with examples from your own work.
Fictional example
Green: our public help articles. Amber: internal roadmaps and team notes. Red: customer contracts, support tickets with personal data and anything from a customer’s systems.
- 03Human checkpoints (principle 1)
-
List the AI tasks the team repeats and the level for each: AI drafts, AI proposes, AI acts within limits, or you do it. Link to the checkpoint map if you have one.
Fictional example
Drafting replies: AI drafts. Refunds and credits: AI proposes, a team lead approves. Tagging tickets: AI acts within limits. Decisions about renewals and people: you do it.
- 04Where our facts live (principle 2)
-
Name the official home and owner of the facts the team uses most, and how people report a mistake.
Fictional example
Prices: the Pricing 2026 page, owned by revenue operations. Refund policy: the legal wiki, owned by Marta. Mistakes: post in #source-fixes.
- 05Agents we share (principle 4)
-
List each shared agent, its owner and where its permission card lives. Say who can switch it off.
Fictional example
Ticket triage agent, owned by Jon. Permission card in the team wiki. Jon or any team lead can pause it.
- 06Skills and learning (principle 5)
-
Say how people keep their core skills and how new colleagues learn to use AI well.
Fictional example
New colleagues answer their first 20 tickets without AI, then with it. A monthly 30-minute review of one AI-assisted case.
- 07Decisions (principle 6)
-
Say how the team makes sure decisions meet the case against them.
Fictional example
Every decision note includes the best argument against it and why we’re going ahead anyway.
- 08Verification levels (principle 7)
-
Say which outputs get a glance, spot checks or full verification.
Fictional example
Internal notes: a glance. Replies to customers: spot checks on names, dates and amounts. Anything contractual or published: full verification and a second reader.
- 09Norms for what we send (principle 8)
-
Agree simple norms for AI-assisted messages and documents.
Fictional example
Summary first. Customer replies under 150 words. Drafts that still need checking are marked as drafts.
- 10Disclosure (principle 9)
-
Agree when the team tells customers, colleagues or the public that AI played a part.
Fictional example
Our chat assistant introduces itself as an AI. Help articles drafted with AI are reviewed by a person. Realistic images of people are always labeled.
- 11When something goes wrong (principle 10)
-
Name the contact for AI problems and how the team shares near misses without blame.
Fictional example
Contact: the support operations lead. Near misses go in the retrospective held every two weeks, no names needed.
- 12Owner and review date
-
Name who keeps the charter current and when the team will review it next.
Fictional example
Owner: Priya, team lead. Next review: in six months, or when we add a new agent.
Sources
What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.
- AI and cyber security: what you need to know UK National Cyber Security Centre · February 13, 2024 · Official guidance Guidance for managers and boards: AI can present falsehoods as fact and can be manipulated, and individual users shouldn’t carry the burden of using AI safely. Limits: Written for leaders and boards.