Campus AI Development Use case scenarios

Use case scenarios 04 of 08

Scenario 04

Functional analyst

A finance analyst needs a budget-variance report by department. They ask the enterprise system’s built-in AI to generate the report definition and calculated fields.

Most governedLeast governed

Questions to consider

Six lenses from the scenario framework. Any answer that raises the stakes moves this scenario toward stricter controls; take your answers to the chooser.

01 Data What it touches and how that data is classified
  1. Which security roles can see the report, and do they match the underlying data?
  2. Are the definitions the official ones?
02 Audience Who relies on it, and what happens if it’s wrong
  1. Who acts on the numbers, and how big are the decisions?
  2. Will it be shared beyond the unit or reported externally?
03 Lifespan How long it lives and who maintains it
  1. Is it a one-time analysis or a standing report?
  2. Who re-checks it after each vendor release?
04 Reach What it can read, write or break
  1. Is the AI only reading, or can it change configuration?
  2. Does the vendor agent act with your access or a broader integration account?
05 Verification How you’ll know it’s right, and keep knowing
  1. What trusted figure did you reconcile against?
  2. Would a data steward reach the same total?
06 Accountability Who owns it, approves it and discloses it
  1. Who signs off on the definitions?
  2. Do the vendor’s AI terms match the main contract?

How the work goes

  1. 01GenerateBuild the report in a non-production tenant.
  2. 02ReconcileCheck totals against a figure finance already trusts.
  3. 03Confirm definitionsThe data steward confirms terms such as encumbrance and fiscal period.
  4. 04PromoteMove it through the vendor’s configuration migration.
  5. 05Re-checkRe-run the reconciliation after each vendor release.

Proportionate controls

T4 · Institutional

Governance should match the risk: enough to protect people and data, no more. Each control area keeps its own tier on the five-tier scale, and those are the controls to apply. The baseline is a label for the project as a whole, taken from its highest area.

  1. Review T3 Platform or center-of-excellence review before production
  2. Documentation T3 Registered in the inventory with an owner and backup
  3. Approval T3 The system or data owner approves
  4. Data T4 Confidential records at scale (Level 3, such as FERPA and GLBA data) with steward approval and minimization
  5. Access T3 Managed environment with role-based access
  6. Testing T3 Every path tested, including failures; accessibility check; re-test when the model or prompt changes
  7. Monitoring T2 The owner reviews it each term
Raises the tier
  • Figures go to external reporting, accreditors or the board
  • The vendor agent can change configuration, not just read
Legal triggers that raise it →
Over-governing looks like
  • Re-approving every ad hoc query
  • Blocking vendor AI features wholesale instead of reviewing their terms
Excess controls push builders toward unsanctioned tools.
Minimum controls
  • Non-production first
  • Reconciliation against a known figure
  • Steward sign-off on definitions
  • Vendor migration tools, never direct database writes
  • Regression checks after each release
Watch for
  • Queries that run but return the wrong number
  • Vendor AI terms that differ from the main contract
  • Report access wider than the underlying security roles
When it moves up

When the report feeds decisions outside the unit, or external reporting, add formal review by institutional research.