DRAFT / LOCAL ONLY — Soft-launch commerce mode: notify (5A). Buy CTAs are waitlist, not live checkout. Not for public publish.

Product · AI Guardrails Kit

A client-ready AI rollout kit with 16 worked examples.

Not another free policy PDF. Discover shadow AI, decide Conditional-first (Approved ≠ unrestricted), roll out employee rules, and keep a light quarterly cadence — with MSP delivery wrappers when you need repeatable client work.

Operational templates only. Not legal, compliance, or security advice.

What you get for $79

Weeks of drafting work, already done and ready to edit.

The Business Pack is a full operating program, not a single template file. Everything is plain-English, editable, and cross-referenced so the policy, the checklist, and the employee guidance actually agree with each other.

46editable documents
6tool rollout playbooks
17CSV + Excel trackers
16completed sample artifacts
Value

The policy set, written once

Acceptable-use policy, data-classification quickstart, approval checklist, exception / temporary-use form, tool register, employee FAQ, do/don’t one-pager, and manager briefing. Change the names and the risk appetite; the structure is done.

Value

Vendor research you don’t have to redo

A data-handling reference covering how major AI vendors treat inputs, retention, and training — plus six playbooks for public AI tools, Microsoft 365 Copilot, meeting bots, writing, research, and AI coding agents.

Value

Trackers that make it stick

Approved-tool register, shadow-AI findings, incident and request logs, and a quarterly review tracker — as CSV and ready-to-open Excel workbooks, not screenshots.

Value

A rollout plan, not just files

Preflight checklist, Day-1 quick start, rollout checklist, and a sample 30-day calendar so the kit turns into an implemented program instead of a download.

Build it in-house

  • Weeks of part-time drafting and review cycles
  • Vendor terms research repeated for every tool
  • Documents that quietly contradict each other
  • Stalls whenever the project loses priority

Start from the kit — $79

  • Editable baseline you can circulate the same day
  • Research and playbooks already assembled
  • Consistent language across policy, FAQ, and checklists
  • One-time cost, no seats, no subscription

$79 is often less than an hour of consulting time — and it covers the whole first draft of your AI program.One-time purchase. Use it across your organization. Edit it however you like.

Where the value lands

Built for the people who get asked first.

SMB IT / security

Hand leadership a finished draft instead of a project estimate. You get enterprise-shaped structure without an enterprise GRC team behind it.

MSPs & consultants

At typical billing rates the $299 pack pays for itself inside one engagement — client intro email, discovery agenda, scope language, and deliverables you can reuse across every account.

Founders / ops leaders

A one-time $79 line item gets you a defensible answer to “what are our AI rules?” without pulling anyone off revenue work for a month.

What's included

Business Pack and MSP Pack.

Both are one-time purchases with no seats, no subscription, and no per-document upsell. Everything listed below is in the download.

Business Pack — $79

One-time · one organization · USD

  • AI Acceptable Use Policy
  • AI Tool Approval Checklist + Risk Scoring Rubric + Approved Tool Register
  • Shadow AI Discovery Survey
  • Data Classification Quickstart
  • AI Vendor Data-Handling Reference
  • Employee FAQ + One-Page Do/Don’t List
  • Rollout checklist, preflight, Day-1 quick start
  • 6 Implementation Playbooks
  • Incident triage + quarterly review tracker
  • Sample completed artifacts + spreadsheet/XLSX templates

Notify me — Business $79

Get launch notice

Local stub → thank-you page. Live email delivery when Gate 2 / 5B is wired (form-backend-wiring-notes-v1.md).

We collect email + role + pack interest only. No ad pixels on this draft.

What the output looks like

Conditional-first decision in one pass — not a committee process.

Each tool review produces a clear verdict, a risk rating, and an owner so nothing sits in limbo. Prefer Conditional for first intake; standing Approved is a later Promote (Approved ≠ unrestricted). This is the shape of the approved-tool register that ships with both packs.

Tool Use case Data types Risk Controls needed Decision
ChatGPT Team Drafts, outlines, non-sensitive summaries Public + non-sensitive Internal only Medium Business workspace; MFA; no connectors/uploads; human review Approved
Microsoft 365 Copilot Email, documents, consented meeting summary Public + authorized internal (caution) High Permission audit; labels; meeting consent; no extra connectors Conditional
Otter.ai Business Meeting transcription Customer calls (consented) High All-party consent; prohibited meeting types; retention ≤90d Conditional
Fireflies.ai Second meeting bot (rejected) None for company work High Point to Otter Conditional; cancel unmanaged invites Not approved
GitHub Copilot Business Code assist in company repos Source code (no secrets) High Business seats; secret scan; PR review; no agent modes Conditional
Perplexity Pro Team Public-web research notes Public + non-sensitive Internal Medium Named users; no uploads; citation + human rewrite Conditional
Google Gemini Business Drafts / non-sensitive summaries (Workspace) Public + non-sensitive Internal Medium Workspace Gemini; MFA; named OU; consumer Gemini banned Conditional
Canva Magic Studio Campaign concepts / social variations Public + approved brand assets Low Brand kit only; human review before publish Conditional
Personal / free AI accounts Any company work None High Employee notice; point to approved tools Not approved

Fictional ExampleCo register shape matching the worked sample approvals (Conditional-first: ChatGPT Conditional→Approved, Low→Conditional Canva, Conditional pilots, and Not approved; Gemini closes Under review). Risk ratings, controls, and verdicts are editable. Full register + sample completed artifacts ship in the download. Ungated sample gallery →

Fit check

Good fit if you need

  • First practical AI rules for an SMB
  • A repeatable MSP client deliverable
  • Clear guidance on what data should not go into AI tools

Not a fit if you need

  • Legal advice or compliance certification
  • A fully custom enterprise AI governance program
  • One-click enforcement across every SaaS tool
FAQ

Clear boundaries. No magic compliance dust.

Is this legal advice or a compliance certification?

No. It is an operational starter kit — templates and workflows only. It does not certify SOC 2, HIPAA, ISO, GDPR, or any other framework. Review with legal, privacy, HR, security, and compliance stakeholders before adopting.

How is this different from a free policy template?

Free and high-authority templates usually give you one document. This kit sells the operating program: discovery, Conditional-first decisions, rollout, quarterly review, six tool playbooks, sixteen worked ExampleCo samples, and an MSP reuse pack. Preview three ungated sample excerpts →

Should Low-risk tools start as Approved?

Usually no. The kit is Conditional-first: prefer Conditionally approved for first intake / pilots — including Low band. Standing Approved is a later Promote when scope is stable and controls are live. Approved ≠ unrestricted. Low ≠ auto-Approve.

How much time does rollout take?

The Day-1 Quick-Start Guide is built for one first session: manager briefing, shadow-AI survey, and employee FAQ. A practical rollout can be underway within a week. The sample 30-day calendar is there if you want a fuller path.

Do I need both packs?

Business Pack ($79) is complete for one organization. MSP / Consultant Pack ($299) adds client pitch and delivery materials for practitioners who reuse the kit across accounts. Internal-only buyers do not need the MSP pack.

Can MSPs use it with clients?

Yes — that is what the MSP pack is for. It includes a client readiness questionnaire, pitch one-pager, QBR slide outline, follow-on opportunity map, intro email, discovery agenda, scope language, handoff checklist, quarterly review prompts, and a practitioner license for client engagements (not for reselling the source kit as a product).

Does this work for regulated industries?

The templates are a starting point, not a substitute for sector-specific compliance review. They are aimed at SMBs and IT teams that need practical guardrails, not an enterprise GRC program.

Is this anti-AI?

No. It helps teams enable AI with clear rules instead of pretending shadow AI is not already happening.