Highly-Sensitive Info. We do NOT allow any use of Claude for things like passkeys, passwords, recovery phrases, API keys, sensitive personal data, etc. We NEVER paste these into a chat with Claude. The moment you do that, it goes into the AI ether somewhere and lives in a log. We set up separate storage for these items that are safe.
06 /
Plan Mode. Claude has a 'Plan Mode' we use to run high-risk prompts or requests first, so Claude has to show us the output before it executes it outside of Plan Mode. We run the prompts, review, audit, and analyze outputs, and then we re-run the prompt outside of Plan Mode if we are satisfied with the outputs.
05 /
Back It Up. We use version control on all documents, so if Claude decides to modify something, the original is not gone forever.
04 /
Dedicated Identity. We give Claude its own email and Chrome profile. This way, 1) Claude connects to Google as Claude (not you), 2) Claude doesn't gain access to the full workspace, and 3) Claude only sees shared files.
03 /
Bypassing Permissions Mode. We do NOT enable the bypass permissions setting mode, which lets Claude "work uninterrupted." Translation: "Let Claude run actions without asking." This is not allowed in our workflows.
02 /
The Sandbox. We set up ONE folder for each client within the AI client and ONLY grant access to THAT folder. If the AI client decides to move folders around one day without permission, it can still only do it within this one folder.
01 /
AI GUARDRAILS
We use Claude by Anthropic for all of our client work. As such, we have deployed a strict set of guardrails that govern our use of Claude. Our firm also runs our entire business on Claude and adheres to these same guardrails. Please let us know if you have any questions about these guardrails before signing on with us.
Blind Execution Avoidance. We do not allow Claude to execute without review when reviewing a document or set of documents. If we don't write it, permission is required to execute on the document. AI doesn't have human integrity, so we force it with this guardrail. It doesn't know to NOT read hidden instructions that could be harmful.
07 /
Memory Cleanup. Claude, by default, memorizes how you work with it and regenerates a summary each night. Chats, conversations, details about our clients and our own business, how you like to work, etc. We have an internal once monthly task required where we go in and audit the memory stored to clean out anything unpublished or not needed.
08 /
Project-Level Instructions. We use basic instructions by project for all of our projects. Examples: "Never publish without my approval", "Never send an email without showing me the draft", "Always show differences before saving". This is a double safety to the other guardrails, so even if Claude can do it, the rules prevent it.
09 /
Connector Sweep. Connectors (Anthropic + Partners) accumulate in Claude. We have a standard quarterly task that requires us to go in and clean up any unused connectors or connectors we stopped using along the way.
10 /
Guardrails Make Scale Possible