AI Data Classification and Access Matrix
Classify what information AI may access, restrict, retain, or escalate before context boundaries go live.
Fill this onlineTemplate preview
The exact sections inside the download.
Frame the operating decision
Which sources can AI use freely? Which sources are safe only inside the organization? Use the combined view to name the business outcome, source of truth, and owner who will decide whether to proceed.
Set the control boundary
Which sources require role, purpose, or approval constraints? Which personal, financial, or regulated data needs strict handling? State the risk to avoid, review or escalation route, and record needed to keep the workflow controlled.
Commit to the first move
Which data should never enter this AI workflow? Who can use each data class and for what purpose? Record the smallest safe scope, baseline, owner, evidence, decision date, and next action.
Decision summary
Who can use each data class and for what purpose? What can be stored, logged, cached, or forgotten? Summarize the proposed move, operating benefit, and the evidence that supports it.
Evidence and control
When should legal, privacy, security, or leadership review be triggered? State the source, review boundary, accountable owner, and condition that would require revision or pause. Keep the decision receipt with the workflow record.
Next review
Record the decision owner, evidence source, review date, and the explicit condition to scale, revise, defer, or stop. Confirm how the resulting decision will be communicated, implemented, and retained in the operating record.
01 / 03
Frame the decision
Name the real operating need before designing a solution.
Name where AI will retrieve, read, write, or remember data.
Customer, employee, financial, confidential, regulated, or internal-only.
Name who approves use and handles exceptions.
How to use it
Start with one real decision.
Complete the canvas with the workflow owner, then use the blank areas to expose missing context and controls.