The Aona playbook library
AI security, one control
at a time.
Prepare a document. Test a control. Make a policy decision. Start with the job in front of your team.
Prepare a contract for AI review
Write down the exact clauses and question before preparing the upload.
Practical guidance. Human review. Clear next steps.
Find your next step
What are you working on?
Specific scenarios, practical steps
and checks before you proceed.
Showing 52 of 52 playbooks
Document workflows
18 playbooksPrepare a contract for AI review
Legal operations and contract reviewers
Prepare payroll workbooks for AI
Payroll, finance operations and IT teams
Prepare invoices for AI processing
Accounts payable and finance systems teams
Prepare sales pipeline data for AI
Revenue operations and sales analytics teams
Prepare support tickets for AI
Support operations and customer service leads
Prepare HR investigation notes for AI
HR operations and authorized investigation teams
Prepare resumes for AI summarization
Recruitment operations and hiring coordinators
Prepare incident reports for AI review
Incident responders and security operations teams
Prepare M&A documents for AI review
Transaction teams and corporate development operations
Prepare insurance claim files for AI
Claims operations and insurance technology teams
Prepare board papers for an AI summary
Company secretariat and executive operations teams
Prepare pricing models for AI analysis
Commercial finance and pricing operations teams
Prepare audit working papers for AI
Audit operations and assurance teams
Prepare property documents for AI
Property operations and real-estate administration teams
Prepare participant research data for AI
Research operations and authorized study teams
Prepare procurement bids for AI comparison
Procurement operations and evaluation teams
Prepare meeting transcripts for AI
Team operations and meeting organizers
Prepare healthcare administration files for AI
Healthcare administration and information governance teams
Control evaluation
17 playbooksTest typed and pasted AI prompts separately
Security engineers running an employee AI pilot
Evaluate every in-scope AI file upload path
Endpoint and security teams evaluating document sharing
Verify DOCX redaction without losing document structure
Security evaluators and document owners
Test spreadsheet redaction beyond visible cells
Finance operations, data owners and security evaluators
Evaluate text PDFs and scanned PDFs separately
Document security owners and technical evaluators
Measure false positives against an agreed task set
Security operations and pilot policy owners
Measure the delay employees experience when submitting to AI
IT performance owners and security pilot leads
Distinguish a hard block from a user override
Security policy owners and technical evaluators
Verify AI policy decisions for different teams and roles
Identity administrators and AI policy owners
Recheck AI DLP after a browser update
Browser management and endpoint operations teams
Test AI DLP when managed devices leave the office
Endpoint security teams supporting hybrid work
Compare browser and native AI workflows using matching tests
Security architects and endpoint pilot teams
Verify that an AI security alert reaches its intended owner
Security operations and integration owners
Evaluate AI DLP failure and recovery before rollout
Security engineering and IT operations leads
Validate what an AI security event needs to contain
Privacy, security operations and data governance teams
Define AI security acceptance criteria before the demo
Security buyers, procurement and pilot sponsors
Verify discovery and enforcement as separate AI capabilities
Security evaluators and AI inventory owners
Policy in practice
17 playbooksReview an AI policy exception before a client deadline
Security leads, delivery managers and client account owners
Turn a discovered AI tool into a reviewed decision
IT owners, security reviewers and application sponsors
Retire an AI tool while preserving business work
Application owners, IT administrators and team managers
Set AI access boundaries for a new contractor
IT administrators, engagement managers and security teams
Hand over AI policy ownership without losing decisions
Outgoing policy owners, incoming security leads and IT managers
Prepare AI usage evidence for a board decision
CISOs, risk leaders and executive reporting owners
Triage a sensitive-data submission to AI
Security operations, IT support and incident coordinators
Resolve AI account and plan mismatches
IT service owners, procurement and security reviewers
Roll out AI guardrails with a clear employee notice
IT rollout owners, security teams and employee communications leads
Choose a useful sample for an AI security pilot
Security evaluators, IT deployment leads and pilot sponsors
Review AI use when two organizations combine
Integration leaders, CISOs and application portfolio owners
Close AI access when an employee leaves
IT offboarding teams, managers and application administrators
Resolve the risks of a shared AI account
Application owners, team managers and security administrators
Recheck an AI tool after a vendor change
Vendor risk reviewers, application owners and procurement teams
Separate AI training terms from data-sharing decisions
Privacy reviewers, security teams and application sponsors
Turn MCP inventory findings into a scoped review
Developer security teams, endpoint owners and engineering leads
Resolve an AI DLP policy dispute with evidence
DLP administrators, service desks and business data owners
Build on your next step
The context. The working document.
Technical evaluation
Bring a real AI use case.
Let’s define the test.
Your AI tools, devices and data-handling requirements. A focused conversation about what success needs to look like.
Discuss a technical evaluation- 01What should the control do?
- 02Where is the AI tool used?
- 03What evidence will confirm the result?