Lesson 09 — Governance: writing your own AI-use rules for source protection
Standard: — · Bloom's: — · Structure: —.
Notice the Say-See-Do cycles running on Priya S.'s actual work — not a canned exercise — and that every capability claim is cited to the frozen doc-set. The exit ticket climbs Bloom's to —, and the lesson closes by writing to the ledger.
Learning objective
(Bloom's: Create) Create your own written AI-use policy — what never gets uploaded unredacted, which conversations run as temporary/incognito chats, and what a standing account instruction enforces automatically — to protect a confidential source's identity across your whole claude.ai workflow, not just one chat.
Standard named: AIHC.1.C2 (Governance). At consumer scale, governance is the practitioner's own rules for how AI gets used — here, the point where an action is irreversible and where the blast radius of a mistake extends beyond one chat (X6), and the discipline of deciding in advance what you'll ask permission for versus what you'll simply never do (X9).
Cycle 1 — Two settings that are actually governance tools
SAY — Two claude.ai controls double as confidentiality tools. A temporary/incognito chat — the "ghost-icon" chat — "isn't saved or searchable at all" [S12]; it's also excluded from chat search generally [S12]. Separately, Memory — Claude's "ongoing memory from conversations" covering "your role, projects, and professional context... details of ongoing work" — explicitly "does not remember incognito-chat content" [S12]. Toggle memory generation off with "Pause memory" (reversible: keeps existing memories, stops new ones) or "Reset memory" (verbatim: "permanently deletes all memories — irreversible") [S12]. That reversible/irreversible distinction is the X6 point made concrete.
SEE — A described Settings > Memory panel with "Pause memory" and "Reset memory" shown side by side, the irreversible one visually flagged; next to it, the ghost-icon temporary-chat indicator in the message composer.
DO — Look at your real upcoming interviews. Identify which one is sensitive enough that the conversation itself should run as a temporary/incognito chat, and open one now, for practice.
⏸ Pause point. One sensitive conversation identified and one incognito chat opened. Stop here if needed.
Cycle 2 — Write the rule once, not every time
SAY — claude.ai's broadest personalization layer is Profile instructions — "Instructions for Claude" — "account-wide, applies to every conversation" [S13], set via "click your initials (lower left) → 'Settings' → 'Instructions for Claude'" [S13], "available to all users, including free accounts" [S13]. A confidentiality floor belongs here, once, rather than re-stated in every new chat. Referent (IPL cricket, flavor only): a fielding side doesn't re-brief the same standing rule before every over — it's briefed once, to the whole XI.
SEE — A described Settings > "Instructions for Claude" text box with one drafted policy sentence shown inside it (e.g., "never draft a passage that includes a named source's employer or address without flagging it to me first").
DO — Write one real Profile Instruction enforcing your confidentiality floor and save it [S13].
⏸ Pause point. One account-wide instruction written and saved. Stop here if needed.
Cycle 3 — Know what memory keeps, so you know what to remove
SAY — Memory entries are "included in data exports" and "follow the account's existing data-retention policy" [S12] — a normal (non-incognito) chat can leave a trace even about something you didn't mean to keep. You can "view/edit memories at Settings > Memory; delete individual entries" [S12].
SEE — A described Settings > Memory entry list with one entry flagged: "this references a source's employer — delete."
DO — Open your real Memory settings. Review existing entries for anything source-identifying that may have leaked in from a non-incognito chat, and delete anything that shouldn't be there [S12].
⏸ Pause point. Memory reviewed, any leaks removed. Stop here if needed.
Cycle 4 — Uploads are sticky; decide before, not after
SAY — Project knowledge-base files persist as standing context — "effectively unlimited quantity (bounded by the context window)" [S07] — meaning once a document is in, it stays until you remove it. Governance means deciding before upload whether a document needs redaction, not discovering the problem afterward.
SEE — A described before/after: an interview transcript with a source's employer and home address visible, versus a redacted version with those fields blacked out, labeled "this version goes in the Project."
DO — Check your real interview-notes file for identifying details. Redact anything that shouldn't sit in standing context before it goes into (or stays in) the knowledge base.
Independent at-bat
Unscaffolded: using "Create and edit files" [S08] to produce an actual document, draft your full one-page personal AI-use policy — covering what never gets uploaded unredacted, which conversations run incognito, what your standing Profile Instruction enforces, and how often you'll audit Memory — as a real, reusable file for your business.
Exit ticket (climbing to Create; graded against the doc-set)
- (Remember) Name the two Memory controls that stop new memories from forming — one reversible, one not. [S12]
- (Understand) Why does an incognito chat protect a source more reliably than typing "don't remember this" inside a normal chat? [S12 — incognito is structurally excluded from memory and search; a normal chat still follows the account's retention/export policy regardless of what you ask]
- (Apply) You're about to upload a scanned interview consent form showing a source's home address. What do you do before it goes into the Project?
- (Apply) Write the one sentence you'd put in your account-wide Profile Instructions to enforce your confidentiality floor across every future project, not just this one.
- (Create — objective level) Produce your full one-page AI-use policy (the four elements from this lesson) as a real Claude-created file, ready to reuse on your next investigation.
Ledger write
ledger_write:
learner_id: L3-CONS-PRIYA
lesson_id: L3-09-C2
standards: [AIHC.1.C2]
tags: [X6, X9]
exit_ticket:
score:
bloom_reached:
auto_score:
self_score:
calibration_gap:
journal_prompt: >
Before writing your one-page policy, what was your actual practice for protecting a source's
identity in claude.ai — a habit, or nothing formal? What does having it written down change
about how you'll work on your next investigation?
structure_used: PBL
referents_used: [cricket-IPL]
next_lesson_seed: "carry the written policy into Lesson 11 (D1 Orchestration) as the Profile Instruction layer every project inherits."
Rubric self-audit (R1–R13)
| # | Indicator | Verdict | Evidence |
|---|---|---|---|
| R1 | One Bloom's-leveled objective, ≥1 named AIHC standard, learner-visible | PASS | Objective names Create + AIHC.1.C2 |
| R2 | Every product claim traces to the frozen doc-set; no invented UI | PASS | Incognito/memory (S12), Profile Instructions (S13), file-creation (S08), knowledge-base persistence (S07) all quoted; no claim of guarantees beyond stated (e.g., no claim that incognito chats bypass server-side handling generally — only what S12 states) |
| R3 | 3–6 SSD cycles, complete | PASS | 4 cycles: incognito/memory settings, standing instruction, memory audit, upload redaction |
| R4 | Each SEE anchors its SAY | PASS | SEEs describe only stated Settings panels and a hand-labeled document comparison |
| R5 | Every DO acts on the learner's real work | PASS | Real upcoming interviews, real Settings, real interview-notes file |
| R6 | Media doctrine | PASS | No motion; static/annotated only |
| R7 | Exit ticket 3–5 Qs, Bloom's-climbing, SSOT-graded | PASS | 5 Qs, Remember→Create |
| R8 | Ledger write complete | PASS | anchor codes, scores, journal_prompt present |
| R9 | Scaffolding with fade; at-bat present | PASS | Cycles fully scaffolded; at-bat (full policy doc) unscaffolded |
| R10 | Referents elected-only, flavor-only | PASS | Cricket used once as a standing-rule analogy |
| R11 | Timing-tolerance honored | PASS | Pause points after Cycles 1–3 |
| R12 | Non-replication | PASS | Keyed to Priya's specific sources, interviews, and confidentiality needs — a different learner's governance content (e.g., a nonprofit admin's team-permissioning) would look nothing like this |
| R13 | Consumer trust boundaries named, never over-reassured | PASS | Scope note up top explicitly bounds the lesson to account-level controls, not an org-compliance claim the doc-set doesn't make; Cycle 3 states retention/export facts plainly |
Escalation verdict: all load-bearing indicators PASS → clears; auto-ships.