Based on D365-IRL, Day 360 · September 14, 2026
Before delegating to an AI, classify what you share
Carlos Ocampo · Published: · Updated:
English translation of the original Spanish publication. Original dates, authorship and documentary images are preserved.
Before sharing a document with an artificial intelligence tool, does your team know what information it contains and what it is authorized to use it for?
Carlos Ocampo · Field Notes D31 · Based on D365-IRL, Day 360 · September 14, 2026
Before sharing a document with an artificial intelligence tool, does your team know what information it contains and what it is authorized to use it for?
On Day 360 of D365-IRL, we discussed AI risks, privacy, human control, trust and protocols. Among the next steps was a commitment to share a structure of information levels and best practices.
That commitment opens an organizational question: how do we turn care for information into an everyday practice people can apply?
An instruction such as “use AI responsibly” leaves many decisions unresolved.
Which document may be shared. What data the task actually needs. Who can authorize an exception. Where the result will reside. Who will be able to access it afterward.
At D31, we propose answering those questions before delegating.
Consider someone who needs to prepare a commercial proposal. They have customer background, meeting notes, prices and internal comments available. Each element serves a different purpose. Preparing a draft may require knowing the problem and expected scope without needing all the data in the file.
The first decision is to select relevant information and determine the conditions for using it.
Sharing information is also an exercise of authority over it.
That is why we propose describing each set of information through understandable criteria: its origin, sensitivity, permitted uses, authorized people and conditions for sharing.
Classification needs to translate into action. If a document has restricted circulation, the team must know which tools it can use, which parts require review and whom to consult when the intended use falls outside the agreed conditions.
A label becomes useful when it guides a decision.
We also need to distinguish access from authorization. A person's ability to consult a file inside the company leaves open what they may do with it, in what environment and for what purpose.
The same distinction applies to agents. The mandate must bound both the actions and the information available to execute them.
In our formulation of TechNúcleo™, we propose connecting context, capabilities and responsibilities. Information classification contributes a concrete condition to that architecture: each participant should have what is needed to act within a recognizable scope.
The 51/49 rule requires people to retain effective authority over those decisions. To exercise it, they need to understand what they are sharing, with whom and under what conditions.
At D31, we propose beginning with a bounded process. Choose a frequent task, identify its documents, agree on permitted uses and review how those decisions are applied. Exceptions reveal where instructions are missing or where the procedure needs to change.
HFE™ can give continuity to that review: what questions arose, what information proved unnecessary and what agreements need adjustment.
The aim is for the team to work with clarity and resolve everyday situations without improvising the rules each time.
The Day 360 conversation leaves a practical task: turning trust into agreements that can be understood, applied and reviewed.
If someone on your team wanted to share a file with an AI tomorrow, would they know what they can use and who can answer their questions?
Field note based on the recovered summary of Day 360. The classification criteria and sales example are proposed applications developed for this note; they are not presented as an already implemented protocol.
© 2026 D31. All rights reserved.
Before adding another layer of technology, it helps to see how ready the organization is to decide, coordinate and execute.
Take the Organizational Self Check-Up™ →