Foundry Academy · AI Workflow Training · Lesson 3 of 6

Data boundaries and approved tools

Map data entering and leaving an AI workflow and enforce approved-purpose, access, retention, vendor, and deletion boundaries.

Start the lesson

Your learning work, on this device

No signup, cloud storage, cross-device sync or verified completion. Saving is optional. This browser profile is shared with anyone who can use it; private mode, browser cleanup or storage limits may remove work. Use only fictional or non-sensitive material. Export a copy before relying on this device.

Not saved. Worksheets, answers and practice notes currently last only in this tab.

Practice markers are self-reported, never credentials.

01 · Explanation

Data boundaries and approved tools

Objective: Map data entering and leaving an AI workflow and enforce approved-purpose, access, retention, vendor, and deletion boundaries.

Inventory the information a workflow receives, retrieves, generates, logs, exports, and shares. Classify each element under the organization's data rules and ask whether it is needed. Names, contact details, financial records, health information, credentials, source code, contracts, trade secrets, client files, export-controlled material, and regulated records can create distinct obligations. Redaction is not automatically anonymization; combinations of details may re-identify a person or reveal a business. Use synthetic or de-identified test data when possible, and never paste sensitive material into a personal or unapproved service.

Tool approval should cover more than a brand name. Record the specific service and plan, administrator, authentication, access roles, data-use terms, training-use settings, region, retention, connectors, subprocessors, logging, deletion method, incident path, and exit plan. Confirm which outputs may be stored or reused. A browser extension or integrated assistant can move data even when the user does not intend it, so approved workflows should specify where the tool may operate. Privacy, security, procurement, legal, and records specialists must review questions within their authority. The operator documents and follows the boundary; the operator does not invent one.

Before you begin

  • Confirm F02, F03, F05, F06, and F11; record that vendor contract, data-location, deletion, subprocessors, lawful basis, and approved architecture are absent.
  • STOP. If the vendor contract, data location, deletion control, subprocessor record, lawful basis, or architecture is missing or conflicts with F02/F03/F05/F06/F11, route the flow to authorized privacy, security, legal, and procurement reviewers; do not claim architecture approval or execute transmission, retention, or partner sharing.

Original overview module anchor →

02 · Compare the artifacts

Supported work. Visible uncertainty.

This is a fictional, sanitized AI-governance training case. All records are fabricated, and the exercise provides no legal, privacy, employment, medical, financial, security, or model-performance guarantee.

Redwood Assist governed intake workflow

Redwood Assist is a fictional services company considering an AI workflow to summarize new client intake and draft a routing recommendation. The current form receives about 420 submissions each month. It includes name, business email, phone, company, project description, budget range, requested timing, and an optional attachment. In a sample of 60 fabricated records, seven attachments contain government identifiers, four contain medical details unrelated to the service, nine include third-party personal information, and 16 lack enough context for reliable routing. The proposed model vendor offers a standard account with model-improvement use enabled by default and a 30-day content retention statement. No security, privacy, contract, data-location, deletion, or subprocessors review has been completed. A pilot prompt tells the model to identify serious founders and reject low-quality leads. The output labels applicants high, medium, or low potential, but neither potential nor serious is defined. In a 40-record test, the model routes 31 correctly according to one manager, while a second manager disagrees on 11 of those decisions. Two Spanish-language submissions are summarized with missing budget conditions. The team proposes automatically rejecting low-rated applicants and sending their attachment to a funding partner. There is no consent for partner disclosure, no human-review standard, no protected exception path, and no versioned evaluation set. Leadership wants the automation live next week to save eight hours of staff time. Learners must classify risk, constrain instructions and sources, establish data boundaries, design meaningful human review, build an evaluation set, and control exceptions and changes. The exercise cannot establish vendor suitability, lawful processing, fairness, or permission to automate decisions.

Supported example — reference only

Element
Vendor-transmission gate
From or trigger
Attachment intake
To or outcome
Quarantine or approved vendor-processing path only after classification/minimization review.
Evidence and source ID
F02, F03, F05
Owner
AI workflow owner with privacy/security reviewers
Open question
Vendor purpose, contract, data location, deletion, subprocessors, and model-improvement controls are not supplied.
Status
Blocked - vendor review pending

A well-handled evidence gap

Element
Funding-partner handoff
From or trigger
Generated summary or attachment
To or outcome
No transfer until an approved purpose and consent or other lawful basis is documented.
Evidence and source ID
F11
Owner
Privacy/legal owner
Open question
Approved disclosure basis and minimum-data specification are not supplied.
Status
Blocked

Flawed approach — do not copy

Marking this ai data-flow map “approved and complete” without the required evidence or reviewer is a flawed submission. Stop transmission, model-improvement use, retention, or partner sharing when purpose, authority, minimization, contract, and deletion controls are unresolved.

Repair: Rework the ai data-flow map as an evidence-backed draft, not an approved result. Inventory each attachment-data class and its source before drawing a flow. Map intake, preprocessing, vendor transmission, retention, model-improvement use, human review, partner handoff, deletion, and exception nodes. Put a classification and minimization gate before vendor access. Check the revision against this requirement: Collection-to-deletion and partner-transfer paths are visible. If the required evidence is still absent, keep the decision blocked and identify the missing input or authorized reviewer.

Full case record, ambiguities and all assignments →

03 · Bounded practice

Build the ai data-flow map.

Design minimization, redaction, attachment handling, vendor review, retention, access, and disclosure controls.

Deliverable: A data-flow map, prohibited-data table, and vendor-review question set.

Complete a bounded starter and gap analysis using only CB01, F02, F03, F05, F06, F11, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.

Exact supplied inputs for this assignment
  • M03-I01 · F02 — Seven of sixty fabricated attachments contain government identifiers.
  • M03-I02 · F03 — Four contain unrelated medical details and nine contain third-party personal information.
  • M03-I03 · F05 — Vendor model-improvement use is enabled by default and content retention is stated as thirty days.
  • M03-I04 · F06 — Security, privacy, contract, data location, deletion, and subprocessors have not been reviewed.
  • M03-I05 · F11 — No consent supports sending attachments to the proposed funding partner.
  • M03-B01 · CB01 — Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment.
  • M03-S01 · F02, F03, F05, F06, F11 — Build a starter version of “A data-flow map, prohibited-data table, and vendor-review question set.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it.

Operating procedure

  1. Inventory each attachment-data class and its source before drawing a flow.
  2. Map intake, preprocessing, vendor transmission, retention, model-improvement use, human review, partner handoff, deletion, and exception nodes.
  3. Put a classification and minimization gate before vendor access.
  4. Use F05/F06 to mark vendor retention and improvement use as unresolved control points.
  5. Use F11 to block partner transfer where consent or another approved basis is absent.
  6. Assign owners and review questions to privacy, security, legal, and operations.
  7. Final-QC every edge for purpose, evidence ID, retention/deletion state, owner, and no implied approval.
Field-by-field guidance
Element
Name the process node, asset, state, or transition. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
From or trigger
State the observable event that activates the path. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
To or outcome
State the proposed next state without implying execution. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
Evidence and source ID
Pair the observation with its exact supplied source ID. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
Owner
Name the authorized operating or specialist role. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
Open question
Record the unanswered question that prevents a final decision. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
Status
Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the map to expose where sensitive attachments could move, persist, train a model, or reach a partner before controls are approved.
AI data-flow map · learning draft
ElementFrom or triggerTo or outcomeEvidence and source IDOwnerOpen questionStatus

Start with 6 rows; the complete workbook specifies 10 stable rows for this artifact. Add rows here or use the full download. No action is saved until you explicitly choose saving above.

Download complete six-module workbook (.md) · Structured case packet (.json)

Keep private client data, unpublished inventions, personal identifiers and credentials out of these public learning tools.

Module 3 · 2-item formative check

Data boundaries and approved tools

Choose an answer and request feedback. Read why each option does or does not fit the evidence. Answers stay in this tab unless you choose device-only saving; they are never submitted.

Question 1 of 2 · MODULE 3 · knowledgeBefore customer records enter a new AI tool, which review is necessary?
Question 2 of 2 · MODULE 3 · scenarioF02 and F03 confirm unnecessary sensitive data, F05 confirms model-improvement use and thirty-day retention, F06 is unknown for vendor controls, and F11 confirms no partner-disclosure consent. Which data-use gate is supported?

Answer either question to review its reasoning.

Inspect the artifact, not just your quiz answers

  • Collection-to-deletion and partner-transfer paths are visible.
  • Sensitive classes, unresolved vendor controls, and consent gap are cited.
  • No live transfer or deletion result is claimed.

Stop: Stop transmission, model-improvement use, retention, or partner sharing when purpose, authority, minimization, contract, and deletion controls are unresolved.

Go: Proceed only to an architecture review using sanitized representations.

Escalate: Escalate vendor and partner flows to privacy, security, legal, procurement, and the accountable process owner.

04 · Evidence to keep

Leave with usable work.

Submit the before-and-after data map, data inventory, approved tool profile, retention and deletion rule, access roles, and unresolved specialist questions.

Download your artifact CSV and, if wanted, export the learning-work JSON above. Neither export is a reviewed submission or certificate. Device-only saving is optional; you must press Save my work now after edits.

When all six artifacts are ready, compare the full packet against the track rubric. Qualified human review is still required before real-world decisions.

Technology team discussing an AI-assisted workflow and its controls.
Learn the standard. Practice the work.
Professional reviewing an AI-assisted output on a laptop before approval.
Leave with evidence you can inspect.

Sources, scope and review boundaries

Curriculum 2026.10.08-learning-paths-1. External source dates below are record checks, not continuing guarantees. Verify current requirements before consequential use.

nist-ai-rmf · Official guidance

NIST Artificial Intelligence Risk Management Framework

Primary NIST resource for governing, mapping, measuring, and managing AI risk across the lifecycle.

Open reviewed external source ↗

nist-privacy-framework · Official guidance

NIST Privacy Framework

A voluntary primary framework for identifying and managing privacy risks created by products, services, and data processing.

Open reviewed external source ↗

ws-ai-workflow-operating-standard · Academy internal operating standard

Wealth Synergy AI workflow internal operating standard

Academy-selected task classification, prompt, evidence, human-review, evaluation, exception, and change controls. This is an internal operating standard selected by Foundry Academy; it is not law, accreditation, licensure, or an external-standard requirement.

Version 1.0 · reviewed 2026-09-01 · owner: Foundry Academy curriculum owner

A future Wealth Synergy private professional-development certificate would be issued only after its assessment, capstone, identity, reviewer, retention, access, deletion, appeal, and issuance controls pass quality review. No credential is currently issued. Any future certificate would not be an accredited academic qualification, professional license, or government certification.