How this page is built
This tool turns a few plain-language answers into a short list of harms and guardrails, using a fixed library you can read below. It doesn't use AI to write your page, so the same answers always give you the same result, and nothing you enter leaves your browser.
Last updated: September 18, 2026
Where it comes from
- Microsoft's Responsible AI Impact Assessment template and guide (June 2022). Its consolidated harms-and-mitigations table with named owners is the model for the page you get. That template predates generative AI and agents, so the "how much does the tool do on its own" prompt is our addition.
- The NIST AI Risk Management Framework (Govern, Map, Measure, Manage), used as a check on coverage.
- The four principles in Chapter 4 of Managing the Machine: fairness, transparency, accountability, and privacy.
Prompt mapping
(function-level, draft, to be verified against the NIST Playbook before publishing)
| Prompt | Chapter 4 principle | Microsoft template section | NIST function |
|---|---|---|---|
| P1 Who it touches | Fairness | Adverse impact (stakeholders) | Map |
| P2 Worst realistic result | Accountability | Adverse impact | Map |
| P3 How much it does on its own | Accountability | Intended uses | Govern |
| P4 Who checks its work | Accountability | Intended uses | Govern |
| P5 What information goes in | Privacy | Data requirements | Map |
| P6 Whether people know | Transparency | Adverse impact | Govern |
| P7 Whether they can appeal | Accountability | Summary of impact | Manage |
| P8 What it must never be used for | Accountability | Intended uses (restricted uses) | Map |
| P9 Owner and review date | Accountability | Summary of impact (owners, sign-off, review) | Govern |
How rows are chosen
a plain-English version of the Section 2 rules (severity from your answers, scenario floors, one row per principle where it applies, capped at six).
What this is not
A compliance sign-off, a legal opinion, or a substitute for a full assessment. Hiring, pay, and scheduling uses in particular can be regulated, and the rules differ by location.
Go deeper
The full row library
Every row a page can contain is listed here. Each use starts with its own three rows, and the general rows are added when your answers match their trigger. The trigger key: W is how serious the worst realistic result is, M is how much the tool does on its own, C is who checks its work, D is what information goes in, T is whether people are told AI is involved, and P is whether they can question the result.
Rows for each use
Screening candidates
Sorting incoming resumes into a shortlist that a person reviews.
First row: A person reads every application before anyone is turned down. The tool sorts and we decide.
Pre-checked as never-use:
- Final rejections without a person reading the application
- Judging "culture fit" or personality from text
- Weighing anything beyond the role's listed requirements
- Inferring age, gender, background, or health from a resume
- Ranking candidates against each other on subjective traits
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| SCR-1 | Qualified people are filtered out for reasons unrelated to the job | Fairness | You | Write the screening criteria down before the tool sees a resume, and limit them to skills and experience the role needs. |
| SCR-2 | The shortlist quietly mirrors who you've hired before | Fairness | Hiring lead | Each cycle, read a sample of the resumes the tool set aside (ten is plenty) and confirm none deserved a second look. |
| SCR-3 | The ranking rewards resumes written for the tool | Accountability | Hiring lead | Some applicants add keywords or hidden text to game screening tools. Read a sample each cycle, and lean on a person's read over the ranking alone. |
Discussion question: If a candidate asked why they didn't make the shortlist, what would we tell them?
Performance feedback and reviews
Drafting and summarizing feedback that a person edits before it reaches anyone.
First row: A person owns every rating, ranking, and recommendation. The tool can help you find the words, and the judgment stays yours.
Pre-checked as never-use:
- Ratings, rankings, or pay and promotion recommendations
- Anything delivered without my own edit
- Private conversations, health details, or things shared in confidence
- Comparing one person's review directly with another's
- Predicting who will leave or underperform
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| PER-1 | The summary misses context only you know | Accountability | You | Read it against your own notes and add the context before the conversation. If a line doesn't sound like something you'd say, rewrite it. |
| PER-2 | Similar work gets described in different language for different people | Fairness | You | Draft each person's feedback from their own concrete examples, then read two side by side to see that similar performance gets similar words and weight. |
| PER-3 | What's easy to measure crowds out what matters | Fairness | You | Decide what good looks like in the role before pulling any data, and treat the summary as one input next to your own observations. |
Discussion question: If someone on the team saw how their review was drafted, what would they want us to explain?
Customer communications
Drafting replies, announcements, and outreach that a person reviews before sending.
Pre-checked as never-use:
- Sending anything without a read-through
- Promising prices, refunds, policies, or timelines
- Replying to complaints involving safety, legal threats, or vulnerable customers
- Including account-specific or payment details
- Pretending to be a person when someone asks
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| COM-1 | The draft promises something the company doesn't offer | Accountability | You | Keep a short list of what you can and can't promise, and check each draft against it. Anything involving money or dates gets a human read every time. |
| COM-2 | The tone misses the moment, like a cheerful reply to an upset customer | Accountability | You | Read complaints and sensitive messages yourself first, and use the tool for structure if it helps. Add a personal line before sending. |
| COM-3 | Customers can't tell it's AI, or can't reach a person | Transparency | Team lead | If a customer might reasonably wonder, tell them, and always offer an easy way to reach a person. |
Discussion question: What's one message we'd never want AI to send, and how do we make sure it doesn't?
Support triage
Sorting and prioritizing incoming requests so the right person sees the urgent ones first.
Pre-checked as never-use:
- Closing or deleting tickets without a person
- Deciding refunds or escalations by customer value alone
- Ranking by name, location, or writing style
- Handling safety, outage, or legal issues without a person
- Replying to customers on its own
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| SUP-1 | Urgent issues get labeled routine and wait | Accountability | Support lead | Add an always-escalate list (safety, outages, legal, cancellations) that skips the tool, and review the misses weekly for the first month. |
| SUP-2 | Some customers are consistently ranked lower, like short messages or non-native writers | Fairness | Support lead | Each month, compare priority ratings across customer groups and writing styles on a sample. If a pattern shows up, adjust the instructions or routing rules. |
| SUP-3 | Customer messages with personal details flow through the tool | Privacy | IT contact | Confirm what the tool does with message contents (storage, training use), and mask account numbers and IDs before they reach it. |
Discussion question: What's the worst thing that could sit unseen in the queue for a day?
Scheduling and assignments
Proposing shifts, schedules, or task assignments that a person approves.
First row: A person approves every schedule before it's published, especially any change to someone's hours.
Pre-checked as never-use:
- Cutting or adding hours without approval
- Penalizing anyone for schedule requests
- Using personal circumstances shared in confidence
- Setting schedules that skip required breaks or rest periods
- Assigning work by anything other than skills, availability, and agreed rules
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| SCH-1 | The tool optimizes coverage, and the same people end up with the least desirable shifts | Fairness | You | Once a month, look at who's getting the hardest shifts and rebalance by a simple rule. |
| SCH-2 | People can't see why they got their schedule or how to change it | Transparency | You | Post the rules the tool follows (such as availability, skills, and seniority) and offer a simple way to ask for swaps or corrections. |
| SCH-3 | A schedule is assumed to follow labor rules and agreements, but nobody checked | Accountability | You | Check each proposed schedule against your labor rules, agreements, and required rest periods before publishing. The tool may not know all of them. |
Discussion question: Who would notice first if this made things unfair, and how would they tell us?
Forecasting and reporting
Drafting forecasts, spotting trends, and writing up reports that a person checks before decisions are made.
Pre-checked as never-use:
- Publishing numbers no one has checked against the source
- Making budget or headcount decisions from the output alone
- Presenting projections as certain
- Reporting to leadership or customers without a review
- Using data we aren't permitted to use for this purpose
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| REP-1 | A number looks plausible but is wrong or made up | Accountability | You | Trace every figure that drives a decision back to its source. Ask the tool to show its work, then check two or three yourself. |
| REP-2 | Past under-investment reads as low demand, so gaps widen | Fairness | You | Ask what the data leaves out and who is missing from it. Where a group or region has thin history, note that in the report so a low number isn't mistaken for low need. |
| REP-3 | Confidence looks higher than it is | Transparency | You | Include the range and main assumptions with each forecast so readers can see how sure we are. |
Discussion question: Which decision would we most regret making from one wrong number?
Meeting notes and summaries
Transcribing and summarizing meetings, with a person confirming decisions and action items.
Pre-checked as never-use:
- Recording without everyone knowing
- Serving as the official record for HR, legal, or disciplinary matters
- Capturing personnel, legal, or confidential discussions
- Assigning action items no one has confirmed
- Sharing outside the meeting without attendees' okay
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| MTG-1 | People don't know they're being recorded or summarized | Transparency | You | Tell attendees in the invite and at the start, and make it easy to ask for something to go off the record. |
| MTG-2 | The summary gives an action to the wrong person or misses a disagreement | Accountability | You | Read the action items aloud before the meeting ends, or send a two-minute confirm-by-reply so nothing stands unchecked. |
| MTG-3 | Sensitive conversations end up stored in a tool | Privacy | IT contact | Turn it off for personnel, legal, and confidential topics, and check where transcripts are stored and who can see them. |
Discussion question: What conversations do we want to keep off the transcript, and how will we signal it?
An internal knowledge bot
Answering team questions from company documents such as policies, how-tos, and past decisions.
Pre-checked as never-use:
- Being the final word on HR, legal, or benefits questions
- Being the only place a policy lives
- Answering from documents no one has checked
- Showing anyone documents they couldn't otherwise access
- Giving answers without naming the source
| ID | Harm | Principle | Owner | Guardrail |
|---|---|---|---|---|
| KNB-1 | Out-of-date or conflicting documents produce confident wrong answers | Accountability | Document owners | Give each source document an owner and a review date, so the bot draws on material someone stands behind. |
| KNB-2 | People can see information they shouldn't | Privacy | IT contact | Test with an ordinary account before launch by asking for things that account shouldn't reach, and match the bot's access to your existing document permissions. |
| KNB-3 | Answers arrive with no source and no sign of uncertainty | Transparency | You | Have it cite its source and say when it doesn't know, and point to the policy owner for anything with consequences. |
Discussion question: Where do people go when the bot doesn't know, and is that path any good?
Something else
For any use not on the list, the page is built from the general rows below.
Pre-checked as never-use:
- Making final decisions about people without a person involved
- Sharing personal or confidential information
- Sending anything outside the team without a read-through
- Anything where being wrong would be hard to undo
Discussion question: What's the worst thing this could get wrong, and how would we find out?
General rows
| ID | Harm | Principle | Weight | Trigger | Owner | Guardrail |
|---|---|---|---|---|---|---|
| ESC-01 | No person makes the final call | Accountability | (always row 1) | W = 3, OR (M = alone AND affects others) | You | A person reads the full picture before anything affects someone's job, pay, or standing. The tool helps you sort and draft, and you decide. |
| ACC-01 | Nobody checks it before it lands | Accountability | 3 | C = nobody | You | Put a named person between the tool and the result. Even a five-minute read catches most confident-sounding mistakes. |
| ACC-02 | It acts on its own | Accountability | 3 | M = alone | You | Start with approve-first, where the tool proposes and a person confirms. Consider more autonomy after a month of clean results, and keep a simple way to pause it. |
| ACC-03 | Approving turns into a rubber stamp | Accountability | 2 | M = approval OR C = me | You | Once a month, redo a few items by hand and compare. It's the quickest way to see whether the checking is still real. |
| ACC-04 | Nobody owns it after launch | Accountability | 1 | Fallback (see selection rule 7) | You | Your name and the review date are on this page. Put the date on your calendar, and at the review ask whether it's still doing what you set out to do. |
| ACC-05 | There's no clear way to question a result | Accountability | 2 | Affects others AND P = No or informal | HR partner | Name one person people can ask for a second look, and keep a short log of what they raise and how it's resolved. |
| ACC-06 | Corrections aren't tracked, so the same mistakes repeat | Accountability | 1 | W >= 2 | You | Keep a simple running list of what you correct. Patterns tend to show up within a few weeks and tell you what to adjust. |
| TRA-01 | People don't know AI is involved | Transparency | 2 | Affects others AND T = No or not yet | HR partner | Say so in one plain sentence where people will see it, with a name to contact for questions. |
| TRA-02 | The reasoning behind a result can't be explained | Transparency | 2 | W = 3 | You | Keep enough of a record that you could explain, in plain words, why the tool produced what it did. If you couldn't explain it to the person affected, that's a signal to slow down. |
| PRI-01 | Personal details go into a tool that isn't approved | Privacy | 2 | D = personal or sensitive | IT contact | Use only the company-approved tool for this, and keep personal details out of personal accounts and free tools. |
| PRI-02 | More sensitive information goes in than the task needs | Privacy | 3 | D = sensitive | IT contact | Try the task without names, IDs, and identifying details first. If it truly needs them, ask your privacy or security contact before launch. |
| PRI-03 | The tool keeps or learns from what you give it | Privacy | 1 | D = internal, personal, or sensitive | IT contact | Check the tool's settings for retention and for whether your inputs are used for training, and turn off what you can. |
| FAI-01 | Results are better for some groups than others | Fairness | 2 | Affects others | Team lead | Before launch, try a wide spread of realistic examples, including different writing styles, backgrounds, and situations, and look at whether the results feel equally good. Repeat at each review. |
| FAI-02 | Nobody outside the project has looked at it | Fairness | 1 | Affects others AND W >= 2 | Team lead | Ask one person outside the project, ideally someone who would be on the receiving end, to try it and tell you what they notice. |