Campus AI Development Use case scenarios

Use case scenarios 05 of 08

Scenario 05

Business user

An office administrator uses the campus AI assistant to write a spreadsheet macro that cleans event registrations, then a small web form for the office.

Most governedLeast governed

Questions to consider

Six lenses from the scenario framework. Any answer that raises the stakes moves this scenario toward stricter controls; take your answers to the chooser.

01 Data What it touches and how that data is classified
  1. Does the spreadsheet contain names, IDs or other restricted data?
  2. Is the AI tool campus-licensed and approved for that data?
02 Audience Who relies on it, and what happens if it’s wrong
  1. Is it just for you, or will colleagues rely on it?
  2. What happens if it stops working in a busy week?
03 Lifespan How long it lives and who maintains it
  1. Will you still need it next term?
  2. Could someone else fix it while you’re away?
04 Reach What it can read, write or break
  1. Does it only change your files, or does it send email or update shared systems?
  2. Can you undo what it did?
05 Verification How you’ll know it’s right, and keep knowing
  1. Did you compare its output with a few records checked by hand?
  2. Would you notice if it silently skipped rows?
06 Accountability Who owns it, approves it and discloses it
  1. At what point should you register it?
  2. Who would you ask for a review?

How the work goes

  1. 01DescribeExplain the task to the assistant, with sample data that has names removed.
  2. 02CheckRun the result and spot-check it against the original.
  3. 03Keep it localStore it in personal or team space.
  4. 04RegisterOnce colleagues rely on it, register it and ask for a light review.

Proportionate controls

T2 · Shared

Governance should match the risk: enough to protect people and data, no more. Each control area keeps its own tier on the five-tier scale, and those are the controls to apply. The baseline is a label for the project as a whole, taken from its highest area.

  1. Review T1 Self-check against a few hand-verified cases
  2. Documentation T1 A note on what it does and where it lives
  3. Approval T1 None needed
  4. Data T2 Internal data with no restricted fields
  5. Access T1 Personal account in a campus-licensed tool
  6. Testing T1 Spot-check the results
  7. Monitoring T1 None needed
Raises the tier
  • Colleagues rely on it to get work done
  • It touches student or employee records
Legal triggers that raise it →
Over-governing looks like
  • Requiring registration and review for a personal macro
  • Banning the campus assistant for routine office work
Excess controls push builders toward unsanctioned tools.
Minimum controls
  • Campus-licensed tools, not personal accounts
  • No restricted or confidential data
  • Personal or team use only
  • Registration once others depend on it
Watch for
  • Prototypes becoming production without notice
  • Data pasted into the wrong tool
  • Nobody else able to fix it
When it moves up

When the tool handles student data or the whole office depends on it, move it to the platform track or to IT.