Products
SCRS — the AI data firewall Other Me — the workspace Compare both products
Solutions
All solutions AI Assistants Email + Projects CRM Live Chat Ticketing Flows HR-lite Control Center
By industry
Accountancy Legal Mortgage & IFA Healthcare
Company
Custom Solutions Pricing Blog About Us
Log in
SCRS login Other Me — Business Other Me — Family Get started with SCRS
Governance · · 6 min read

Staff AI Use Guidelines: A Template for Your Firm's Handbook

AS

Founder & CEO, Pop Hasta Labs

From my perspective, the staff AI use guidelines sit alongside the firm-level AI policy but speak a different language. The firm-level policy is the compliance document the COLP or DPO signs. The staff guidelines are the practical rules every team member reads at induction. Both need to exist; only one needs to be 4 pages long, and it isn’t the staff one.

Template

Here’s the structure I’d use for staff AI guidelines. One page. Plain English. Signed at induction and re-acknowledged annually.

Why this matters. “AI tools are part of how [Firm] works. Used correctly, they save time. Used incorrectly, they leak client data, breach confidentiality and can create legal exposure for you and for the firm. This page tells you what’s OK and what isn’t.”

What you can do. “Use [governed AI tool] for client-facing work — drafting, research, summarisation, admin. The tool keeps client data inside the firm’s systems and every interaction is logged. This is the fast, approved way.”

What you can’t do. “Do not paste client data, client documents, client financial information, client personal data, case details, medical records or any identifiable client information into any other AI tool. This includes ChatGPT, Claude, Gemini, Grok, Copilot (unless within the firm-approved Microsoft 365 governed deployment), and any AI-powered browser extension.”

What to do in an emergency. “If you think client data has accidentally been entered into a non-approved tool, tell [Managing Partner / DPO] within 24 hours. We’re more concerned about speed than blame — the response matters more than the mistake.”

Your signature. “I have read and understood these guidelines. I will use AI tools in line with them.”

How to roll it out

Specially in small practices, the rollout matters more than the document. Three practical tips. One, brief the team verbally before circulating the written policy. Five minutes at a team meeting, explaining the why. Two, tie it to the governed tool — “we’re adopting [tool] because the current approach creates client risk, and this tool is faster anyway.” Three, make the approved tool actually faster than ChatGPT. If the approved tool is slower, the policy will be worked around within a month.

Pair with the firm-level AI policy

The staff guidelines sit alongside the firm-level policy. We’ve published a free AI policy template for UK SMEs that covers the governance document. Together, the two documents are what your COLP, DPO or regulator expects to see.

Other Me

Our flagship is SCRS — the Secure Context Retrieval System, a patent-pending AI data firewall that keeps client data inside your systems and logs every interaction. Other Me is the per-seat governed workspace we build on top of it, designed to make staff guidelines like these easy to follow. See how SCRS works or view the plans.

AS

Abhishek Sharma

Founder & CEO of Pop Hasta Labs. Building SCRS — the patent-pending AI data firewall — and Other Me, the governed workspace built on it. Based in London.

Govern the AI your team already uses.

SCRS keeps client data out of the model — and Other Me is the whole governed workspace, built on it. No sales calls; set yourself up in minutes.