Prompt permit
In industry, no hot work starts without a hot-work permit. Same logic before handing a task to an AI: two questions, a criticality matrix, protection barriers — and a verdict. Nothing is sent or stored: everything runs in your browser.
Step 1 — Information sensitivity
What is the most sensitive piece of information you would have to give the AI for it to do the job? The most sensitive piece always classifies the whole.
Step 2 — Impact of an undetected error
If the AI gets it wrong and nobody notices, what is the worst plausible consequence? Think HAZOP: reason on the deviation, not the nominal case.
Criticality matrix
Raw position from steps 1 and 2; residual position after crediting the barriers ticked in step 3.
Step 3 — Protection barriers
As in LOPA: each independent protection layer earns one notch on the axis it protects. A barrier only counts if it is actually in place, not merely planned.
Complete steps 1 and 2 to get the verdict.
Going further
- AI comparison: sovereignty, GDPR and pricing → to pick an "approved tool" with full knowledge.
- Guide: choosing your AI assistant → the criteria that really matter.
- GDPR checklist → if your prompts touch personal data.
An educational tool inspired by criticality matrices and the LOPA method. It replaces neither your company's information security policy nor your CISO or DPO — when torn between two levels, pick the higher one.