Campus AI Development Use case scenarios

Use case scenarios 08 of 08

Scenario 08

Student using an AI platform

A student club builds an event sign-up agent in a campus-provided no-code agent builder and shares it with members.

Most governedLeast governed

Questions to consider

Six lenses from the scenario framework. Any answer that raises the stakes moves this scenario toward stricter controls; take your answers to the chooser.

01 Data What it touches and how that data is classified
  1. What personal information does the sign-up collect?
  2. Does any of it connect to institutional systems?
02 Audience Who relies on it, and what happens if it’s wrong
  1. Who outside the club will use it?
  2. Could it be mistaken for an official university service?
03 Lifespan How long it lives and who maintains it
  1. What happens when the officers graduate?
  2. Does it expire automatically?
04 Reach What it can read, write or break
  1. Can the agent send messages on members’ behalf?
  2. Which connectors does the platform allow?
05 Verification How you’ll know it’s right, and keep knowing
  1. Have you tested sign-up, cancellation and full events?
  2. How do members report problems?
06 Accountability Who owns it, approves it and discloses it
  1. Who is the current owner?
  2. How do members know it’s an AI agent?

How the work goes

  1. 01BuildWork in the student environment with club data only.
  2. 02ConnectThe platform limits connectors to approved, non-institutional sources.
  3. 03DiscloseOfficers tell members the sign-up is run by an AI agent.
  4. 04ExpireThe agent expires after inactivity or is transferred when officers change.

Proportionate controls

T2 · Shared

Governance should match the risk: enough to protect people and data, no more. Each control area keeps its own tier on the five-tier scale, and those are the controls to apply. The baseline is a label for the project as a whole, taken from its highest area.

  1. Review T2 A colleague looks it over before others rely on it
  2. Documentation T1 A note on what it does and where it lives
  3. Approval T2 Manager or sponsor is aware
  4. Data T2 Internal data with no restricted fields
  5. Access T2 Team space; no shared credentials
  6. Testing T1 Spot-check the results
  7. Monitoring T2 The owner reviews it each term
Raises the tier
  • It connects to rosters, room booking or other institutional systems
  • It speaks for the university
Legal triggers that raise it →
Over-governing looks like
  • Requiring IT approval for every club tool
  • Disabling the student environment instead of limiting connectors
Excess controls push builders toward unsanctioned tools.
Minimum controls
  • A student environment separate from institutional data
  • Connector limits
  • Disclosure to users
  • Automatic expiry
  • Owner transfer when officers change
Watch for
  • Collecting other students’ personal data
  • Agents that outlive their owners
  • Looking like official university communications
When it moves up

When the club wants the agent to use institutional systems such as rosters or room booking, it needs a staff sponsor and IT review.