TOOLS / PROMPT PERMIT
Prompt permit
← All tools AI risk analysis

Prompt permit

In industry, no hot work starts without a hot-work permit. Same logic before handing a task to an AI: two questions, a criticality matrix, protection barriers — and a verdict. Nothing is sent or stored: everything runs in your browser.

No. PP-— Scope this task only

Step 1 — Information sensitivity

What is the most sensitive piece of information you would have to give the AI for it to do the job? The most sensitive piece always classifies the whole.

Step 2 — Impact of an undetected error

If the AI gets it wrong and nobody notices, what is the worst plausible consequence? Think HAZOP: reason on the deviation, not the nominal case.

Criticality matrix

Raw position from steps 1 and 2; residual position after crediting the barriers ticked in step 3.

Delegate With conditions Restricted Refused

Step 3 — Protection barriers

As in LOPA: each independent protection layer earns one notch on the axis it protects. A barrier only counts if it is actually in place, not merely planned.

Verdict — AI delegation permit

Complete steps 1 and 2 to get the verdict.

VALIDITY: this task, this scope, these barriers. Any change of data or stakes requires a new permit.

Going further

An educational tool inspired by criticality matrices and the LOPA method. It replaces neither your company's information security policy nor your CISO or DPO — when torn between two levels, pick the higher one.