Data sensitivity and approved environments

Classify data before selecting a model, connector, or storage path.

The practical distinction

Classify data before selecting a model, connector, or storage path. Data classification describes the material; environment approval is an organizational authorization covering provider behavior, retention, access, logging, connectors, and permitted tools. One does not imply the other.

Worked example

Support records approved for an enterprise workspace may still be prohibited in a consumer chatbot or a connector that logs prompts elsewhere. The task owner verifies the exact environment, not merely the model brand.

Apply it

Use only an environment approved for the data class and minimize what is supplied.

  1. Classify the minimum fields the task truly needs before selecting a tool.
  2. Confirm approval for the model, account, retention, region, access, connectors, and intended action.
  3. Remove unrelated identifiers and define deletion, export, and incident handling.

Evidence to collect

  • Trace data through prompts, retrieval, logs, caches, evaluation records, and outputs.
  • Test that unauthorized users and tools cannot retrieve or infer protected records.
  • Reassess approval whenever the provider, configuration, connector, or data class changes.

Common mistake

Assuming a paid account, encryption claim, or “no training” setting by itself establishes organizational approval.

Scope limit

This guidance on data sensitivity and approved environments helps define a task and its review evidence. It does not certify a model, source, reviewer, environment, legal position, or residual-risk level.