Working with AI

The sanctioned AI path

Most workers guess at the AI rule, and the guess is usually either too loose or too fearful. This course draws the real map: the three lanes where these tools are open to you, the one thing that never moves, and how to get help without ever sending a client's data anywhere. You will finish knowing exactly what you are allowed to do, and able to prove it.

8
lessons
~61
minutes
12
exam questions

Free · No paid tier · No certificate fee

After this course

Everything, and what is in it.

Why the rule exists at all

~7 min

A client handed over data on a promise

Before any rule makes sense, hold the scene in your head. A client uploads a spreadsheet with 2,400 customer rows: names, phone numbers, what each person bought and when. They do not know you. They never will. They handed that file over because we told them it stays inside the task, seen only by the person doing the work and the operator reviewing it. That sentence is the product. Everything you are about to read is the machinery that keeps it true. The rule is not a judgement about your character, and it is not a fear of new tools. It is a promise somebody else made in your name, and you are the one holding it.

The data moves, the skill does not

The mistake almost everyone makes is to read the rule as a ban on tools. It is not. Read the promise again and notice what it protects: the data. A language model is a piece of software you can become genuinely good at using, and being good at it makes you faster, clearer and more employable. We want that. These courses exist to teach it. What we do not want is that client's 2,400 rows sitting on some company's servers in another country because it saved you forty minutes. Separate the two ideas and the policy becomes easy to hold in your head. Your skill goes wherever you go. Their data stays where they put it.

Pasting is sending

It helps to stop thinking of a paste as a keystroke. When you paste a customer list into a website, you have transferred that file to a company you have no contract with. It may be stored. It may be read by staff reviewing quality. On free tiers it is often used to improve the product. None of that requires anyone to behave badly, and none of it appears on your screen. The breach happened at the moment of transfer, not at the moment something visibly goes wrong. This is why the question is never whether the tool seems trustworthy or how careful its marketing sounds. The question is whether the data was yours to move. It was not.

What the review layer does not cover

An operator reads every delivery before the client sees it, and that catches a great many mistakes: a wrong total, a missing column, a paragraph that reads badly, a formula that broke on row 400. It cannot catch this one. Once a file has left your machine for a third-party service, no review reverses it. There is nothing in the delivery for the operator to see, and nothing anyone can undo afterwards. That asymmetry is why this is one of the few rules on the platform with no gradient and no second chance. Almost everything else here is a skill you build over months. This is a line you simply do not cross, from your first task onward.

Trusted, not watched

We are not scanning your screen and we are not going to. This policy works because you understand it, not because anyone is checking. That is a deliberate choice, and it puts the weight on you. A worker who understands why the line sits where it does will make the right call on the one strange task at four in the morning where no written rule quite fits. A worker following a list of banned websites will not. So the aim of this course is not compliance. It is that you could explain the whole policy to another worker in your own words, including the large parts of it that let you use these tools freely.

Remember

  • The client handed over data on a promise. You hold that promise.
  • The rule protects the data, not your skill. AI skill is welcome here.
  • Pasting into a website is a transfer. The transfer is the breach.
  • Review catches wrong totals. It cannot reverse a file that already left.
  • Nobody watches your screen. That is why understanding beats memorising rules.

The three lanes that are open

~8 min

Lane one is your own material

The first lane is everything that contains nothing of the client's. General questions about method. Your own writing. Practice files you invented. A formula problem built from fake rows. How does a lookup across two sheets work, what is a polite way to phrase a chase, explain what this function actually does. Use whatever tool you like, as often as you like, on your own account and in your own time. Nothing in this lane needs permission, because there is no client data in it to protect. This is also the lane where you build the skill, and the workers who get fast are the ones who practise here deliberately instead of only reaching for a tool when a deadline is burning.

Lane two is the assistant on a claimed task

The second lane is our own assistant, available inside a task you have claimed. It is sanctioned: you do not need anything in the brief to use it. It works because of what it does not have. It cannot see the task record, who the client is, the files you downloaded, or the payout. It sees only what you type into it, and what you type is scrubbed for personal data before it is stored. So it is a method assistant, not a work assistant. Ask it how to approach a 45-vendor chase, what a formula does line by line, how to structure a long report. The next lesson covers exactly what it is good for and where it stops.

Lane three is written permission in a brief

The third lane is a brief that names an outside tool for a named purpose. This happens, and it is real permission. A client may hold their own account with a transcription service and want you to use it. A brief may say the audio file may be uploaded to a named service to produce a transcript. That sentence is scoped: that tool, that file, that purpose. It does not extend to a different tool, a different file, or a different task next week. Read what was granted and stay inside it exactly. Permission written for one thing does not stretch to cover the thing beside it, however similar the two look at two in the morning.

Silence is not a fourth lane

Most briefs say nothing at all about AI. That is not a gap for you to fill with your own judgement, and it is not tacit approval because nobody objected. A brief that is silent has granted nothing, so the default holds: no client data in a third-party tool. Workers talk themselves past this in a predictable way. The task is dull, the tool would take ten minutes instead of two hours, and nobody would ever know. All of that can be true and the answer does not change. The default is no. If you genuinely believe the brief intended to allow something and failed to say so, that is a question for the operator, not a decision for you.

One question decides which lane you are in

You do not need to memorise a policy document. You need one question, asked before you type. Does what I am about to send contain anything of the client's? If the answer is no, you are in lane one and any tool is open to you. If the answer is yes and you are inside a claimed task, our own assistant is there, and you still type method rather than material. If the answer is yes and you want an outside tool, the brief must name it in writing. There is no fourth answer. Asking that question takes two seconds and it resolves every situation in this course, including the ones nobody thought to write down.

Remember

  • Lane one: nothing of the client's in it. Any tool, freely.
  • Lane two: our assistant on a claimed task. Sanctioned without a brief.
  • Lane three: a brief naming a tool for a named purpose.
  • Silence in a brief grants nothing at all. The default is no.
  • One question before typing: does this contain anything of the client's.

What the in-product assistant sees

~8 min

It only sees what you type

The assistant sits inside a task you have claimed, which leads people to assume it can read the task. It cannot. It has no access to the brief, the client's identity, the files you downloaded, or the payout on the task. The window is empty until you fill it. That design is deliberate, and it is what makes the assistant sanctioned: there is nothing for it to leak, because nothing was handed to it. The practical consequence surprises people. You cannot ask it what does this brief mean, because it has never seen the brief. You have to describe your situation yourself, in your own words, without the client's details, and that constraint is the whole point.

What you type is scrubbed before storage

Anything you type is checked for personal data before it is stored, so names, email addresses, phone numbers and similar identifiers are removed. This is a safety net, not a licence. It exists to catch the ordinary human slip at the end of a long shift, when a real surname comes out of your fingers because you have been staring at it for two hours. It is not a reason to paste a customer list and let the system clean up behind you. A scrubber removes identifiers. It cannot remove the fact that one business has 2,400 customers across three provinces, because that is not a name, it is a shape. You type method, not material.

Use it for method, not for the work

The assistant earns its place on questions that begin with how. How do I approach a reconciliation when two date formats are mixed in one column. What does this formula do, step by step. What is a sensible order for checking a 40-page document. Is there a faster way to compare two lists on partial names. What should a delivery note contain when three rows could not be resolved. These are questions about the craft, and the answers hold regardless of whose file you happen to be holding. You take the method back to the real file and do the work yourself. That loop is available on every task you have claimed, at three in the morning, with nobody else awake to ask.

Never paste the deliverable in

One hard edge inside a sanctioned tool. Do not paste your finished deliverable in to have it checked. The deliverable is built out of the client's information, and putting it into any tool, ours included, moves client material somewhere it does not belong. This catches careful people, because it feels harmless: the work is your own writing, you built it, and you only want a second read before upload. It is still their data wearing your sentences. Check your delivery the way the rest of these courses teach. Reread the brief line by line, open the file cold in a fresh window, read the numbers aloud. If a phrasing problem is nagging at you, rebuild the sentence with invented names first.

It is not the operator

The assistant answers questions about method. It does not answer questions about this task. It cannot tell you whether the brief permits something, whether a missing file will arrive, whether a two-hour overrun is acceptable, or what the operator expects in an ambiguous case. It has no standing to grant permission and no view of the task at all, so any answer it produces about the rules is a guess wearing the clothes of an answer. Those questions go to the operator through the task, where a person who can actually see what you are looking at will answer them. Keep the two straight. Craft questions to the assistant, task questions to the operator, always.

Remember

  • It sees only what you type. Not the brief, files, client or payout.
  • Scrubbing is a safety net for slips, never a licence to paste.
  • Ask how, not what. Method transfers. Material stays inside the task.
  • Never paste your finished deliverable in for a check, even here.
  • It cannot grant permission. Task questions go to the operator.

Rebuild the problem with fake rows

~9 min

You need the method, not the material

Almost every question you want to ask has nothing to do with whose data it is. If you are stuck matching two lists where the names do not align exactly, the difficulty is the partial match, not the client. Strip the client out and the question survives intact. This is the technique that makes the whole policy livable, because it means you are never choosing between getting help and protecting data. You rebuild the shape of the problem out of material you invented, ask about the shape, and apply the answer to the real file yourself. It costs about three minutes. It removes the risk completely, and the answer is usually better, because a small clean example is easier to reason about.

Rename the headers, invent the rows

Start with structure. Write out the column headers, renamed if a header itself gives something away, so Client Deal Value becomes Amount and Q3 Pipeline becomes Stage. Note the data type of each column and the row count in round terms: about 900 rows, not 912. Then invent four to six rows using obviously fake content. Acme Trading, Northwind Foods, Bright Path Clinic, with figures you made up on the spot. Never lightly edit real rows, because a changed surname sitting beside a real address is still a real address. Build the sample from nothing. The test to hold is this: if what you typed leaked tomorrow, the client would not appear in it, and neither would any real person.

Carry the quirks across, not the content

This is the step people skip, and it is the step that makes the technique work. What makes your real file hard is never the clean rows. It is the trailing spaces, the two date formats mixed in one column, the region spelled three different ways, the blank cell in the middle, the number stored as text. Put every one of those quirks into your invented sample. If the real file has a name with an apostrophe and a suffix, invent one. If two rows are duplicates except for capitalisation, duplicate two. A fake sample made only of tidy rows produces an answer that collapses the moment you run it on the real 912 rows, and the three minutes bought you nothing.

A worked example, start to finish

You have a client file of 612 donation records and you must flag every row where the donor email contains no part of the donor surname. You do not paste it. You type this instead: two columns, Full Name and Email, about 600 rows, Google Sheets. Then six invented rows. Maria Santos with maria.s at an example address, Juan Dela Cruz with jdc1988 at another, a surname with an apostrophe against a blank email, one row with a trailing space after the surname, one duplicate differing only in capitals. Ask for a formula that flags non-matches and handles blanks. Test it against your six rows, where you already know every correct verdict. Then run it on the real file yourself.

The same trick works for writing

Text problems rebuild just as cleanly. Say you need a firm paragraph telling a supplier that two deadlines were missed while keeping the relationship warm. Do not paste the client's email chain. Describe the situation in generic terms instead: a supplier has missed two deadlines, the tone must stay warm, ninety words maximum, one clear request, no apology. Ask for three versions of that paragraph, then write the real one yourself using whichever structure works best. The same approach covers a bad-news message, a summary structure, or eight subject line options. What you are borrowing is shape and register. What you never borrow is a sentence carrying a real name, a real figure or a real complaint.

Remember

  • Strip the client out. The difficulty is the shape, not the data.
  • Rename headers and invent rows. Never lightly edit real ones.
  • Carry the quirks across: mixed dates, blanks, trailing spaces, duplicates.
  • Test the answer on your fake rows before touching the real file.
  • Writing problems rebuild too. Borrow structure, never real sentences.

Reading a brief for permission

~7 min

What real permission looks like

Written permission names three things: the tool, the material, and the purpose. The audio file may be uploaded to a named transcription service to produce a transcript. The product photographs may be processed in a named image tool for background removal. The draft may be run through a named grammar service before delivery. Each of those sentences tells you exactly what may leave the task and where it may go. Notice what they are not. They are not enthusiasm about technology, they are not a client who sounds modern, and they are not a line asking for the work to be efficient. If you cannot point at the sentence and read it aloud to somebody else, you do not have permission.

Permission is scoped, not general

A grant covers what it says and nothing standing beside it. If the brief permits uploading the audio file for transcription, that does not cover uploading the interview notes to a summariser afterwards. If it names one tool, a different tool doing the same job is not covered, even when it is clearly better. If it was granted on last week's task from the same client, it does not carry over, because the client agreed to it once, for that piece of work. This feels pedantic until you picture the conversation where a client asks which of their files went where. A narrow answer you can point to is a short conversation. A broad answer you reasoned your way into is not.

Silence means the default

Most briefs will say nothing at all. Silence is not permission. It is also not an oversight for you to correct with your own judgement, because a client who was never asked cannot be assumed to have agreed. This matters most on the tasks where an outside tool would obviously help: sixty receipt photos to type, a two-hour recording to transcribe, a scanned document to convert. Those are exactly where the temptation is strongest, and exactly where a client would most want to have been asked first. Do the work by hand inside the task, or raise it with the operator before you start. The slow path is always available. The unauthorised one is not, however tired you are.

When the brief is ambiguous, ask

Some briefs sit in between. Use any tools you like to speed this up. The client is comfortable with modern software. Feel free to automate where it helps. None of those names a tool or names the material, so none of them is the permission this course describes, and none of them is obviously a refusal either. Guessing in either direction wastes something. Ask the operator through the task, in one specific message: I would like to upload the audio file to a named transcription service, may I, or should I transcribe it by hand. Specific questions come back in minutes. A vague question about whether AI is allowed comes back slowly, because the operator has to work out what you meant.

Do not guess while the clock runs

The dangerous moment is not when you read an ambiguous brief. It is three hours later, with two hours left, when no answer has come back and the manual path no longer fits inside the time. Which is why the question goes in first, before you build a plan around an answer you do not have. Read the brief for permission at the same time you read it for the deliverable, in the first ten minutes after claiming. If the answer arrives and it is no, you still have the whole night to do it the slow way. Ask at the last hour and you have quietly built a situation where the wrong choice is the only one left.

Remember

  • Real permission names the tool, the material and the purpose.
  • A grant is scoped. It does not carry to another tool or task.
  • Silence means the default holds, especially where a tool would obviously help.
  • Ambiguous brief: ask the operator one specific question through the task.
  • Ask in the first ten minutes, not with two hours left.

What counts as client data

~8 min

Names are the easy half

Start with the obvious list, then keep walking outward. Client data includes names, email addresses, phone numbers, home addresses, invoices, bank details, salaries, customer lists, internal documents, contracts, and anything pulled out of their systems. Most workers get all of that right. The failures happen further out, in material that does not look like personal data at all: a company name paired with a problem, an unreleased product, prices never published, a row count, a file name, a screenshot with something visible in the corner. Those are the cases this lesson exists for. If you only remember the obvious list, you will be careful with the customer file and careless with everything sitting around it.

A company name is data

The client's own identity is confidential, and it is confidential in combination with everything else you happen to know. Typing which supplier keeps missing deadlines for a named company is a disclosure even though no person appears in it, because you have told a third party that this business has a supplier problem. The same holds for a company behind on receivables, one restructuring a team, one whose product is late. Businesses are entitled to have problems privately, and that privacy is part of what they are paying for. So describe the situation, never the party. A supplier missing deadlines is a method question. A named company missing deadlines is that company's business, told to someone who was never asked.

Numbers can identify as surely as names

Detail identifies without naming. A dental clinic in Cebu with 2,400 active patients across two locations is a small enough set that anybody motivated could narrow it down in an afternoon. So is a family business exporting one product to three countries. This is why removing names is not anonymising: the shape of a data set can be as identifying as any field inside it. When you rebuild a problem for a question, round and blur on purpose. About 600 rows rather than 612. A clinic rather than a dental clinic in Cebu. Three regions rather than the three real ones. You lose nothing useful, because that specificity was never what made the question hard.

Check the edges of every screenshot

Screenshots leak far more than the thing you meant to show. A browser tab title carrying the client's company name. A bookmarks bar with their portal on it. An open window behind. An email preview sliding in at the corner. A file path along the bottom of a spreadsheet showing which folder the file lives in. A taskbar revealing which of their systems you have open. Before any screenshot goes anywhere at all, look at every edge of it rather than the middle where your problem sits. Better still, do not screenshot the real file. Reproduce the situation in a blank sheet with six invented rows and screenshot that, and the question of what leaked stops existing.

File names travel further than files

A file name is content. Something like AcmeTrading_Q3_Layoffs_FINAL tells a stranger the company, the period and the decision, and it keeps telling them from inside a folder listing, a chat message, a support ticket or a screenshot, long after everyone stopped thinking about the file itself. So when you refer to a file in any question, rename it or describe it generically: the spreadsheet, the source file, the export. The same care applies to sheet tab names, header rows and any email subject line you quote. Then ask the test that settles all of this. If the client read a transcript of everything I typed today, would they be comfortable? If you have to think, the answer is no.

Remember

  • The obvious list is the easy half. Failures happen further out.
  • A company name plus a problem is a disclosure, with nobody named.
  • Round and blur: about 600 rows, a clinic, three regions.
  • Check every edge of a screenshot. Better still, screenshot an invented file.
  • File names carry the company, the period and the decision. Rename them.

Record what you used

~6 min

Tell the reviewer where to look hardest

When a brief permitted a tool and you used it, say so in the delivery note. The reason is practical rather than ceremonial. An operator reviewing your work has limited time and must decide where to spend it. Telling them the transcript came from the permitted service and that you corrected forty timestamps by hand aims their attention exactly where errors are most likely to be sitting. That makes the review faster and any correction smaller, which is good for both of you. A note that hides the tool does the opposite: attention spreads evenly, the risky part is missed, and the client finds it. Nobody wins that. Point at the soft spot yourself.

What a good record contains

Three parts, two sentences, no apology. What you used the tool for, what you did yourself afterwards, and how you checked it. For example: the audio was transcribed with the service named in the brief, I corrected the speaker labels and every figure against the recording, and the two passages I could not hear clearly are marked in yellow. That gives the reviewer the tool, the scope, your work, and the exact rows to open first. Compare it with a general line saying AI was used somewhere in the work. That sentence hands nobody anything to act on, and it makes a careful worker sound vague. Specific is shorter, and it reads as confidence, because it is.

Record the gaps as carefully as the tool

The same note carries whatever did not resolve. Six addresses you could not verify. Three rows where the source was unreadable. A formula you tested against twenty hand-checked rows that still fails on one shape you have described. Leave those cells blank rather than filled, and list them plainly: which item, what you tried, what you could not confirm. An honest gap costs the operator a few minutes. A confident invention costs the client, and it costs the trust behind every delivery you make after it. That is true whether a tool was involved or not, and it is doubly true when one was, because that is the first place an experienced reviewer looks.

Never blame the tool afterwards

When a task comes back with two wrong dates that came out of a draft you never checked, there is one answer that protects you, and it is not that the tool produced them. You chose to use it. You read the output. You decided it was good enough and you delivered it under your own name. So the revision note says the dates were wrong, here they are corrected against the source documents, and I failed to verify them before delivery. That sentence costs you nothing you had not already lost, and it buys back the thing that matters, which is that your account of your own work can be believed. The record exists to make you trustworthy, not to spread blame.

Remember

  • Disclose a permitted tool so the reviewer knows where to look hardest.
  • Three parts: what the tool did, what you did, how you checked.
  • List unresolved items plainly. A blank cell beats an invented one.
  • Own the miss. The tool delivered nothing. You did.

Your own clients and AI

~8 min

Outside AfterDesk, the client sets the rule

Work you take directly is governed by whatever you and that client agree, and many of them will actively want AI in the process. For some, that is the reason they hired you. Nothing in this course tells you to refuse. What it does tell you is that the agreement has to exist, has to be written, and has to be specific, because you are now doing the job the operator does for you here. You decide what may leave, on the client's behalf, with nobody standing behind you to check. The habits you build inside a task are the ones that keep you out of trouble outside it. The lanes are the same. Only the person granting permission changes.

Get it in writing, and get it specific

A verbal yes on a call is not nothing, but it is not something you can point to eight months later when a question comes up. Send an email after the call and ask them to confirm it. Cover four points. Which tools may be used. Which material may go into them, and which never may, such as customer lists or financial records. Whether the output may be reused for other clients or belongs to them alone. Whether they want AI use disclosed on the work itself. Their answers will surprise you in both directions: some permit far more than you expected, some draw a harder line than we do. Either way, you now know, and so do they.

Ask what their own clients were promised

A client can only give away what is theirs. If they run an agency, their own customers may have signed something that forbids exactly what you are about to do, and your client may not have read it recently. One question handles this. Do any of your customers have confidentiality terms that would cover this material? Asking it marks you as the professional in the conversation, and it moves the decision to the person entitled to make it. The same applies to anything covered by health, legal or financial confidentiality rules in their country. When the answer comes back uncertain, take the path you already know: work on invented material and move nothing of theirs.

Disclose where the answer would matter

Two separate questions live inside disclosure, and people muddle them constantly. First, were you allowed. That is settled by the agreement and by nothing else. Second, having been allowed, should you say where you used it. Say it where a reasonable client's decision would change if they knew: anything published under their own name, anything they sign, original research they are paying for, anything touching money, law or health. Say it less for the mechanics. Nobody needs to be told you reformatted dates or drafted a formula you then tested on twenty rows. And if anyone asks you directly, the answer is the truth, plainly, even when it is awkward and even when you suspect it costs you the work.

One paragraph you can say out loud

Here is the whole policy in something you could tell a stranger. I am good with these tools and I use them for drafting, reformatting and working out method. Confidential material does not go into any tool that has not been approved in writing for that purpose, and inside a marketplace task it does not go into an outside tool at all. When I need help, I rebuild the problem with invented data and ask about that. Every fact I deliver is checked against a real source, and I say where a tool was involved whenever that would matter to you. Say that, mean it, and you will be trusted with better work than the person who says nothing.

Remember

  • Outside AfterDesk you decide what leaves. That is the operator's job, alone.
  • Get four things in writing: tools, material, reuse, disclosure.
  • Ask whether their own customers signed terms covering this material.
  • Permission and disclosure are separate questions. Answer them in that order.
  • A direct question about AI gets a direct answer. Always.

Sit the exam

The courses are free. The work is real.

Twelve scenario questions. Pass at ten. Three attempts a day. The bar is the point.

No paid tier. No certificate fee. No upsell. Not now, not later.

Create a free account

You can start the first course tonight.

The curriculum

Everything, and what is in it.