05 — How it fits together
The guide uses four scales. Each answers a different question, and they work best in order: understand the work, classify the data, set the controls, then choose how to build.
The sequence
Each step narrows the next. Skipping ahead to pick a tool first is how projects end up over- or under-governed.
Crosswalk
Typical pairings, not rules. A project’s baseline tier points to the data it can hold and the approaches that can produce the evidence that tier needs.
| Baseline tier | Typical data level | Approaches that fit | Scenarios here |
|---|---|---|---|
| T1 Personal | 1 Public | 01 Vibe coding, 02 AI-assisted | None at this baseline; a personal macro that stays personal |
| T2 Shared | 1–2 Public, internal | 01–02, Track A low-code | Business user, Student on a platform |
| T3 Managed | 2–3 Internal, confidential | 02–03, Track A low-code | Faculty member, Student with an API |
| T4 Institutional | 3 Confidential | 03–04, Tracks A and B with review | Research software engineer, Platform maker, Functional analyst |
| T5 Critical | 3–4, or consequential decisions | 04–05 Spec-driven, multi-agent | Enterprise team |
| Question | Control areas it informs | Chooser factor |
|---|---|---|
| Data | Data, access | Audit and traceability |
| Audience | Review, approval | Stakes |
| Lifespan | Documentation, monitoring | Lifespan |
| Reach | Access, testing | Risk of silent drift |
| Verification | Testing, review | Requirements clarity |
| Accountability | Approval, documentation, monitoring | Team size |
One rule, three times
With the Strategic Compass
The AI Strategic Compass in the Campus AI Framework screens, scores and selects AI initiatives and sets how much institutional review each one gets. This guide picks up once an initiative is approved, and decides how it gets built.
Use it when the work is an institutional initiative: it needs funding or staff time beyond one person, serves others, touches confidential data or affects decisions about students or staff. A personal macro or a throwaway prototype (T1–T2) doesn’t need a portfolio decision; go straight to the six questions. If a small tool grows past that point, it enters the Compass then.
The Compass review band says who approves the initiative and how closely. This guide’s control tiers say how the software is built and verified. They usually line up, but they aren’t the same scale. When they disagree, the stricter one wins.
| Compass review band | Usual control baseline here | Why they might differ |
|---|---|---|
| Low (6–12) | T1–T2 | A low-risk initiative can still include one area, such as access to institutional data, that needs a higher tier. |
| Moderate (13–18) | T2–T3 | A moderate score may hide a long-lived tool that other people will rely on. |
| High (19–24) | T3–T4 | Strategic stakes can be high while the build itself stays simple. |
| Critical (25–30) | T4–T5 | Ask the Compass’s first question: does a lower-risk alternative meet the goal? |
The mapping is a starting point, not a conversion. A low Compass score on Efficacy is a warning sign whatever the total: for consequential decisions, it means more verification here, not less.