AI-Assisted Writing Governance
Sensitive Input Redaction Checklist
Remove or replace confidential, personal, regulated, proprietary, and security-sensitive information before approved external AI processing.
Free editable Markdown · Writers, privacy teams, and security-conscious organizations ·
Accessible HTML preview
Blank template
The downloaded file contains the same fields in editable Markdown.
Task and authorization
- Task ID and permitted output
- [Enter]
- Approved service and use-case card
- [Enter]
- Original source owner
- [Name/team]
- Original data classification
- [Enter]
- Permitted remaining classification
- [Enter]
- Minimum context required
- [Describe]
- Redaction owner and reviewer
- [Names]
- Working-copy location
- [Controlled reference]
Removal inventory
- Names, contact details, usernames, account and government identifiers.
- Health, financial, employment, education, legal, and other regulated details.
- Credentials, access tokens, private keys, security findings, and internal endpoints.
- Customer, employee, partner, and confidential business information.
- Exact locations, dates, rare roles, or event combinations that enable re-identification.
- Copyrighted or licensed material not approved for this processing.
- Comments, track changes, hidden rows, formulas, metadata, filenames, and attachments.
- Images, audio, screenshots, or logs containing overlooked identifiers.
Transformation record
Duplicate for each class or field.
- Source field or passage
- [Describe, do not repeat the value]
- Sensitivity category
- [Enter]
- Action
- [Remove / Generalize / Synthetic replace / Keep with authorization]
- Replacement token or range
- [Enter]
- Relationship that must remain
- [Explain]
- Re-identification concern
- [Describe]
- Reviewer decision
- [Accept / Revise / Stop]
Final review and disposal
- Pattern searches performed
- [List]
- Visual and metadata inspection
- [Result]
- Task still answerable
- [Yes / No and why]
- Residual sensitive context
- [List or None]
- Authorized reviewer approval
- [Name/date]
- Sanitized input version
- [Enter]
- Mapping-key location
- [Restricted reference or None]
- Working-copy deletion or retention
- [Owner/date/policy]
How to use this template
- Confirm that the AI task and vendor are approved for the intended remaining data class.
- Reduce the source to the minimum passages, fields, media, and relationships needed.
- Remove direct identifiers, secrets, protected content, metadata, and re-identifying combinations.
- Replace necessary relationships with safe synthetic tokens and inspect the exported result.
- Have an authorized reviewer approve the sanitized input and record its controlled disposal.
Minimize before attempting redaction
Ask whether the system needs the source at all. Replace a full customer conversation with a short synthetic scenario, extract an approved public passage, or describe a structural problem without the underlying confidential facts. Work from a controlled copy and preserve the original under existing access rules. Define the specific output needed so unnecessary pages, columns, attachments, metadata, and history can be excluded. Data minimization is stronger than trying to spot every secret in a large file, and it gives a reviewer a smaller, more understandable input set.
Look for direct and indirect identifiers
Remove names, usernames, addresses, account numbers, contact details, device IDs, faces, voices, location trails, credentials, tokens, internal URLs, unpublished financial details, legal matters, health data, and other protected fields. Then check combinations. A rare job title, exact date, small town, and unusual event may re-identify a person even after their name is gone. Free text, filenames, comments, track changes, spreadsheet formulas, hidden sheets, image metadata, and document properties can contain details missed in visible paragraphs. Use appropriate approved tools and qualified review; do not paste the original into another unapproved service to redact it.
Preserve task meaning without reversible codes
Replace sensitive values with consistent, non-meaningful tokens such as `[CUSTOMER_A]` only when relationships are needed. Avoid initials, hashed identifiers, or a key kept beside the redacted copy when they make reversal easy. Generalize dates, amounts, locations, and roles only as much as the task permits, then test whether the output question can still be answered. Record what categories were removed, who reviewed the sanitized version, and where the mapping—if legitimately required—is secured. Run a final search for patterns and inspect rendered or exported files before submission.
See the fields in context
Fictional example: support-theme classification
The customer, ticket, product, and identifiers below are invented and do not represent actual data.
- Original need: Classify recurring themes from an imaginary support ticket.
- Minimization: Keep only the two sentences describing a fictional upload error; remove conversation history and attachments.
- Redaction: Replace the customer and product IDs with `[CUSTOMER_A]` and `[PRODUCT_X]`, generalize the exact date, and remove the internal diagnostic URL.
- Residual check: The unusual job title and small location are unnecessary and removed because their combination could identify a person.
- Approval: A fictional privacy reviewer approves only the sanitized two-sentence input.
Frequently asked questions
Is replacing names enough to anonymize text?
Usually not. Context, rare attributes, dates, locations, relationships, and metadata can still identify people.
Can I use an AI service to perform the redaction?
Only if that service is already approved to receive the unredacted data. Otherwise the attempted safeguard creates the exposure it was meant to prevent.
Should a reversible mapping be kept?
Only when the workflow truly requires it and policy permits it. Store it separately with strict access and deletion controls.
What should happen when meaningful redaction is impossible?
Do not submit the material. Use an approved private environment, synthetic data, a human-only workflow, or abandon the task.