Data sensitivity and approved environments
Classify data before selecting a model, connector, or storage path.
The practical distinction
Classify data before selecting a model, connector, or storage path. Data classification describes the material; environment approval is an organizational authorization covering provider behavior, retention, access, logging, connectors, and permitted tools. One does not imply the other.
Worked example
Support records approved for an enterprise workspace may still be prohibited in a consumer chatbot or a connector that logs prompts elsewhere. The task owner verifies the exact environment, not merely the model brand.
Apply it
Use only an environment approved for the data class and minimize what is supplied.
- Classify the minimum fields the task truly needs before selecting a tool.
- Confirm approval for the model, account, retention, region, access, connectors, and intended action.
- Remove unrelated identifiers and define deletion, export, and incident handling.
Evidence to collect
- Trace data through prompts, retrieval, logs, caches, evaluation records, and outputs.
- Test that unauthorized users and tools cannot retrieve or infer protected records.
- Reassess approval whenever the provider, configuration, connector, or data class changes.
Common mistake
Assuming a paid account, encryption claim, or “no training” setting by itself establishes organizational approval.
Scope limit
This guidance on data sensitivity and approved environments helps define a task and its review evidence. It does not certify a model, source, reviewer, environment, legal position, or residual-risk level.
