Skip to main content

The Aona playbook library

AI security, one control
at a time.

Prepare a document. Test a control. Make a policy decision. Start with the job in front of your team.

52 practical playbooks/3 security collections
Inside a playbook

Prepare a contract for AI review

Step 1 / 4

Write down the exact clauses and question before preparing the upload.

Read the full playbook

Practical guidance. Human review. Clear next steps.

Find your next step

What are you working on?

Specific scenarios, practical steps
and checks before you proceed.

Showing 52 of 52 playbooks

Document workflows

18 playbooks
01

Prepare a contract for AI review

Legal operations and contract reviewers

02

Prepare payroll workbooks for AI

Payroll, finance operations and IT teams

03

Prepare invoices for AI processing

Accounts payable and finance systems teams

04

Prepare sales pipeline data for AI

Revenue operations and sales analytics teams

05

Prepare support tickets for AI

Support operations and customer service leads

06

Prepare HR investigation notes for AI

HR operations and authorized investigation teams

07

Prepare resumes for AI summarization

Recruitment operations and hiring coordinators

08

Prepare incident reports for AI review

Incident responders and security operations teams

09

Prepare M&A documents for AI review

Transaction teams and corporate development operations

10

Prepare insurance claim files for AI

Claims operations and insurance technology teams

11

Prepare board papers for an AI summary

Company secretariat and executive operations teams

12

Prepare pricing models for AI analysis

Commercial finance and pricing operations teams

13

Prepare audit working papers for AI

Audit operations and assurance teams

14

Prepare property documents for AI

Property operations and real-estate administration teams

15

Prepare participant research data for AI

Research operations and authorized study teams

16

Prepare procurement bids for AI comparison

Procurement operations and evaluation teams

17

Prepare meeting transcripts for AI

Team operations and meeting organizers

18

Prepare healthcare administration files for AI

Healthcare administration and information governance teams

Control evaluation

17 playbooks
01

Test typed and pasted AI prompts separately

Security engineers running an employee AI pilot

02

Evaluate every in-scope AI file upload path

Endpoint and security teams evaluating document sharing

03

Verify DOCX redaction without losing document structure

Security evaluators and document owners

04

Test spreadsheet redaction beyond visible cells

Finance operations, data owners and security evaluators

05

Evaluate text PDFs and scanned PDFs separately

Document security owners and technical evaluators

06

Measure false positives against an agreed task set

Security operations and pilot policy owners

07

Measure the delay employees experience when submitting to AI

IT performance owners and security pilot leads

08

Distinguish a hard block from a user override

Security policy owners and technical evaluators

09

Verify AI policy decisions for different teams and roles

Identity administrators and AI policy owners

10

Recheck AI DLP after a browser update

Browser management and endpoint operations teams

11

Test AI DLP when managed devices leave the office

Endpoint security teams supporting hybrid work

12

Compare browser and native AI workflows using matching tests

Security architects and endpoint pilot teams

13

Verify that an AI security alert reaches its intended owner

Security operations and integration owners

14

Evaluate AI DLP failure and recovery before rollout

Security engineering and IT operations leads

15

Validate what an AI security event needs to contain

Privacy, security operations and data governance teams

16

Define AI security acceptance criteria before the demo

Security buyers, procurement and pilot sponsors

17

Verify discovery and enforcement as separate AI capabilities

Security evaluators and AI inventory owners

Policy in practice

17 playbooks
01

Review an AI policy exception before a client deadline

Security leads, delivery managers and client account owners

02

Turn a discovered AI tool into a reviewed decision

IT owners, security reviewers and application sponsors

03

Retire an AI tool while preserving business work

Application owners, IT administrators and team managers

04

Set AI access boundaries for a new contractor

IT administrators, engagement managers and security teams

05

Hand over AI policy ownership without losing decisions

Outgoing policy owners, incoming security leads and IT managers

06

Prepare AI usage evidence for a board decision

CISOs, risk leaders and executive reporting owners

07

Triage a sensitive-data submission to AI

Security operations, IT support and incident coordinators

08

Resolve AI account and plan mismatches

IT service owners, procurement and security reviewers

09

Roll out AI guardrails with a clear employee notice

IT rollout owners, security teams and employee communications leads

10

Choose a useful sample for an AI security pilot

Security evaluators, IT deployment leads and pilot sponsors

11

Review AI use when two organizations combine

Integration leaders, CISOs and application portfolio owners

12

Close AI access when an employee leaves

IT offboarding teams, managers and application administrators

13

Resolve the risks of a shared AI account

Application owners, team managers and security administrators

14

Recheck an AI tool after a vendor change

Vendor risk reviewers, application owners and procurement teams

15

Separate AI training terms from data-sharing decisions

Privacy reviewers, security teams and application sponsors

16

Turn MCP inventory findings into a scoped review

Developer security teams, endpoint owners and engineering leads

17

Resolve an AI DLP policy dispute with evidence

DLP administrators, service desks and business data owners

Technical evaluation

Bring a real AI use case.
Let’s define the test.

Your AI tools, devices and data-handling requirements. A focused conversation about what success needs to look like.

Discuss a technical evaluation
Start with three questions
  1. 01What should the control do?
  2. 02Where is the AI tool used?
  3. 03What evidence will confirm the result?
AI Security Playbooks: Documents, DLP Tests & Policy | Aona AI