
Index
An AI solution should receive only the data necessary for the task. The architecture needs to control access, transport, and retention before connecting internal documents to a model.
How to evaluate this decision
Map what information comes in, where it is processed and what is recorded. Evaluate masking, segregation, and restriction of fields based on use. The supplier's conditions need to be verified in current documents and analyzed by those responsible for the company. No single configuration should be presented as a guarantee of legal compliance.
Criteria for comparing proposals
- Minimization: Justify each dataset sent to the model or stored for evaluation.
- Access: Apply permissions to the source and results, including attachments and history.
- Retention: define deadline and destination of technical records, avoiding copying sensitive content to unnecessary logs.
A scenario to discuss with the supplier
Hypothetical example: To classify a request by subject, it may not be necessary to submit personal identifiers present in the document. Removing these fields can reduce exposure without harming the task.
What to validate upon delivery
Inspect the path of a test input and the logs generated. Check that users without access to the document do not obtain its content through responses, search or history.
Prepare the conversation about the project
Take the purpose, data classification and approved internal rules to Quantum9. Technical work must be monitored by those responsible for privacy and security when the context requires it.
Development with agentic AI · Map the company's priority