Campus AI Development How it fits together

05 — How it fits together

Four scales, one decision

The guide uses four scales. Each answers a different question, and they work best in order: understand the work, classify the data, set the controls, then choose how to build.

01Six questionsWhat is this, really?Data, audience, lifespan, reach, verification and accountability, asked of every project.The framework →02Four data levelsHow sensitive is what it touches?Public, internal, confidential and restricted. The data sets the ceiling on tools and approach.Data classification →03Five control tiersHow much governance does each area need?Personal to critical, set separately for review, documentation, approval, data, access, testing and monitoring.Proportionality →04Five approaches, two tracksHow should it be built?Bands 01–05 from vibe coding to multi-agent work, plus governed low-code and enterprise configuration.The continuum →

The sequence

Six steps, in order

Each step narrows the next. Skipping ahead to pick a tool first is how projects end up over- or under-governed.

  1. 01 →AskAnswer the six questions for the project in front of you.
  2. 02 →ClassifyFind the most sensitive data it touches, including prompts and outputs.
  3. 03 →Set tiersGive each control area the lowest tier that covers its real risk; the highest becomes the baseline.
  4. 04 →ChoosePick an approach or platform track that can produce the evidence that tier requires.
  5. 05 →Check triggersConfirm which laws and policies apply, and raise any tier they set a floor for.
  6. 06 ↺Re-checkRepeat when users, data or reach change, up or down.

Crosswalk

Tiers, data and approaches side by side

Typical pairings, not rules. A project’s baseline tier points to the data it can hold and the approaches that can produce the evidence that tier needs.

Baseline tierTypical data levelApproaches that fitScenarios here
T1 Personal1 Public01 Vibe coding, 02 AI-assistedNone at this baseline; a personal macro that stays personal
T2 Shared1–2 Public, internal01–02, Track A low-codeBusiness user, Student on a platform
T3 Managed2–3 Internal, confidential02–03, Track A low-codeFaculty member, Student with an API
T4 Institutional3 Confidential03–04, Tracks A and B with reviewResearch software engineer, Platform maker, Functional analyst
T5 Critical3–4, or consequential decisions04–05 Spec-driven, multi-agentEnterprise team

Each question feeds a control area and a chooser factor

QuestionControl areas it informsChooser factor
DataData, accessAudit and traceability
AudienceReview, approvalStakes
LifespanDocumentation, monitoringLifespan
ReachAccess, testingRisk of silent drift
VerificationTesting, reviewRequirements clarity
AccountabilityApproval, documentation, monitoringTeam size

One rule, three times

The strictest answer wins

  1. In the dataThe most sensitive element sets the level for the whole dataset.
  2. In the controlsThe highest-tier control area sets the project’s baseline.
  3. In the chooserThe strictest factor sets the approach and its minimum controls.

With the Strategic Compass

Decide whether, then decide how

The AI Strategic Compass in the Campus AI Framework screens, scores and selects AI initiatives and sets how much institutional review each one gets. This guide picks up once an initiative is approved, and decides how it gets built.

When to run the Compass first

Use it when the work is an institutional initiative: it needs funding or staff time beyond one person, serves others, touches confidential data or affects decisions about students or staff. A personal macro or a throwaway prototype (T1–T2) doesn’t need a portfolio decision; go straight to the six questions. If a small tool grows past that point, it enters the Compass then.

  1. 1ScreenCompassIs it worth considering at all?
  2. 2ScoreCompassRate six dimensions, including efficacy and stakeholder impact.
  3. 3SelectCompassChoose what to pursue and set the review band.
  4. →BuildThis guideSix questions, data level, control tiers, approach.
  5. 4PlanBothCompass sets success measures; this guide sets controls and exit criteria.
  6. 5TrackBothWatch the measures and the signals to move along the continuum.
  7. 6ReflectCompassScale, change or stop, and feed lessons back.

Two scales, two jobs

The Compass review band says who approves the initiative and how closely. This guide’s control tiers say how the software is built and verified. They usually line up, but they aren’t the same scale. When they disagree, the stricter one wins.

Compass review bandUsual control baseline hereWhy they might differ
Low (6–12)T1–T2A low-risk initiative can still include one area, such as access to institutional data, that needs a higher tier.
Moderate (13–18)T2–T3A moderate score may hide a long-lived tool that other people will rely on.
High (19–24)T3–T4Strategic stakes can be high while the build itself stays simple.
Critical (25–30)T4–T5Ask the Compass’s first question: does a lower-risk alternative meet the goal?

The mapping is a starting point, not a conversion. A low Compass score on Efficacy is a warning sign whatever the total: for consequential decisions, it means more verification here, not less.