Skip to main content
Workforce AI Security

AI guardrails
for employees.

Apply your data policy as people share supported prompts and files with AI.

The moment before sharing
DRAFT FOR AI ASSISTANTAccount follow up

Draft a reply to [CUSTOMER] at [EMAIL] about account [ACCOUNT].

Protected draftCustomer support

Customer support example: identified details are replaced in the draft.

Fictional workplace examples. No content is sent. Actual responses depend on your policy and supported input path.

The employee experience

A clear reason. A clear next step.

For supported prompts and files, show employees why a policy applies and what they can do next.

Prohibited submissions stay blocked.

How policy responses work
  1. A relevant response

    Apply the policy to the information being shared, including a configured block or redaction where supported.

  2. A clear boundary

    A person can revise a prohibited request or use the organisation's approved process. The prohibited submission stays blocked.

  3. Something to learn from

    Use available policy evidence to review repeated issues and improve the policy and employee guidance.

Illustrative scene of a person checking a case note before sharing a draft
Illustrative policy responseCustomer details removed.

Draft a reply to [CUSTOMER] about account [ACCOUNT].

Roll out with a clear scope

Start with the work your team actually does.

Match the control to the tool, input and device. Test a harmless example before expanding.

See covered AI use

Deploy the relevant client and review the AI activity it observes. An AI-tool catalogue alone does not show your employees' use.

Explore discovery

Apply your data policy

Confirm supported prompt and file actions in the actual browser or native app, then test allowed and prohibited inputs.

Review coverage

Review the evidence

Check the recorded response, retention and access. Use the result to improve policy without equating usage with productivity.

Understand event evidence

A useful distinction

Protecting people’s AI use. Reviewing an agent’s actions.

Employee guardrails check how a person uses AI, such as sharing a document or submitting a prompt.

Human oversight puts a person at a decision point, such as approving an agent's external action. It needs its own review and enforcement process.

Explore agent oversight

Compliance and standards

Connect controls to compliance.

See how a practical control contributes to a specific review.

A guardrail supports a control. Compliance also depends on the organisation, its processes, agreements and the full system in scope.

Patient information

HIPAA and employee AI use

Connect supported data protection and recorded policy events to your PHI review. Verify agreements, permitted use and the remaining information.

Configured policySupported responseReview evidence
Explore the control mappingWork through a BAA decision

Questions

Your questions, answered.

What are AI guardrails for employees?
They are controls around the way people use AI at work, including which tools they use and what information they submit. Aona applies configured policies on supported, covered endpoint paths. Depending on the policy and input, a response can include blocking or redaction, with evidence available for the organisation's review.
Are employee guardrails the same as human-in-the-loop approval?
No. Employee guardrails protect a person's use of AI, for example checking a prompt for confidential information. Human-in-the-loop approval is a separate control in which a person authorises an agent's proposed action or reviews an output. Aona's employee protection does not establish an approval-routing product feature.
Does the policy apply to every AI app on every device?
Coverage requires the relevant Aona client or an explicit API integration. The browser plugin supports Chrome, Edge, Firefox and Safari; application, input and file support can differ. Native coverage also depends on the app, action and operating system. Confirm your actual tools and representative tasks during scoping. A catalogue entry alone is not proof of enforcement.
What can our security team review?
Recorded AI usage and policy events can help your team understand covered activity and configured policy responses. Available records depend on the client, supported path, deployment and retention settings. Review access and retention with employee privacy in mind. These records are not a complete account of all work or a measure of employee productivity.
Does redacting a patient note make it HIPAA de-identified?
Removing detected identifiers does not establish HIPAA de-identification. Safe Harbor and Expert Determination have specific requirements, and remaining context can still identify a person. Your organisation must review the information, intended use, applicable agreements and safeguards. Aona's controls can support that process on covered paths.
Aona AI guardrails

Bring a real AI use case.

Map the data, policy and supported coverage with our team.

AI Guardrails for Employees | Protect Workplace AI Use | Aona