Day 05 Personal Playbook

Building a Personal AI Playbook Your CIO Will Sign

An approval is not a meeting. It is a single page on someone’s desk that answers their five questions before they have to ask. Today you write that page — the document that turns this week’s habits into something your CIO, supervisor, or OGC can read in five minutes and sign without rewriting.

~45 min Hands-on By Bo Peng

Today's Objective

Produce a one-page Personal AI Playbook that documents the tools you use, the data you put into them, the controls you apply, and the citations that authorize the workflow — written so a busy reviewer can approve it without follow-up questions.

Four days of habit-building only matter if the habits stick. The way they stick in a federal environment is not by talking about them — it is by writing them down in a form a reviewer can read, mark up, and sign. A Personal AI Playbook is one page. It names the tools, the data classes, the controls, the human-in-the-loop steps, and the authorities. It is not a policy document. It is the operator’s manual for how you use AI inside the rules your agency has already adopted.

The reason this lesson is last is that you now have something to write down. You scoped the approved tools (Day 1), you wrote with citations (Day 2), you summarized FOIA-sensitive material (Day 3), and you produced 508-compliant output (Day 4). The playbook is the artifact that makes those habits visible, transferable, and reviewable.

What you'll learn

The five questions a reviewer is asking

Whether the reviewer is your CIO, your supervisor, your privacy officer, or general counsel, they are reading your playbook with the same five questions in mind. Answer them on the page and the conversation gets short.

  1. Is this on the approved list? If the tool is not on your agency’s authorized list (the one you assembled in Day 1), nothing else matters. Lead with the authorization.
  2. What data goes in? Public, FOUO, CUI, PII, classified. Reviewers want one line per data class, with a yes/no on whether it is permitted to enter the tool.
  3. Who is accountable for the output? AI does not sign documents. A human does. Name the human-in-the-loop step explicitly.
  4. What law or policy authorizes this? OMB M-24-10, M-25-21, agency CIO directive, FedRAMP authorization letter, Section 508 standards, FOIA exemptions referenced. Citations make this look like a federal document, not a hobby.
  5. What is the failure mode? When does the reviewer get called? What gets escalated? Saying nothing here is the fastest way to fail review.

The seven required sections of a one-page playbook

Every section is short. The whole document fits on one page in 11-point type. Brevity is not a stylistic choice — it is the reason this gets signed.

Section 1 — Identification

Your name, title, office, and the date. The version number. The signature blocks for you, your supervisor, and the CIO/CISO/privacy officer as appropriate. Skipping this is how a draft becomes a permanent draft.

Section 2 — Approved tools and authorization

The exact tools you will use, with their authorization basis. For example: Claude.gov via Anthropic’s FedRAMP High authorization, or ChatGPT Enterprise via the agency master enterprise license dated YYYY-MM-DD. Cite the actual authorization letter or contract reference number.

Section 3 — Data classes and what may be entered

A small table or short list. One row per data class. For each: yes/no on whether it is permitted in the tool, and any pre-conditions (redaction, anonymization, environment).

Section 4 — Use cases in scope

A short bulleted list of the tasks you intend to use AI for: drafting memos, summarizing FOIA-released material, generating Section 508 alt text, drafting plain-language conversions. If a use case is not on the list, you do not do it under this playbook — you go back and amend.

Section 5 — Human-in-the-loop and verification

For each use case, the verification step. Citation check, factual verification, supervisor review, OGC review for legal language, 508 check before publication. This is the section that earns trust, because it shows you are not treating AI output as truth.

Section 6 — Authorities and references

The citation list. OMB M-24-10, OMB M-25-21, agency AI use-case inventory entry number, FedRAMP marketplace reference, Section 508 (29 USC §794d), FOIA (5 USC §552), Privacy Act (5 USC §552a), and any agency-specific instructions or directives.

Section 7 — Failure modes and escalation

What happens if the model produces a hallucinated citation? If a colleague pastes CUI into a public tool? If a journalist files a FOIA request for your prompt history? Two or three lines per scenario, plus the named contact. This is the section that actually gets read carefully.

Drafting the playbook with Claude

The first draft writes itself if you fed Claude the right inputs from this week. Open a fresh conversation in your authorized tool and use this prompt structure.

Personal AI Playbook draft prompt
PROMPT
I am a [job title] in [office/agency]. Draft a one-page Personal AI Playbook
for my use of AI tools at work. Output as Markdown that I will paste into Word
and reformat to one page (11pt).

CONTEXT:
- Approved tool(s) at my agency: [list from Day 1 inventory]
- My typical tasks: [drafting memos, FOIA summarization, alt text, plain
  language, etc.]
- Data classes I handle: [public, FOUO, CUI, PII; specify which]
- My agency’s AI policy citation: [agency AI directive/instruction number]

REQUIRED SECTIONS (label each one and keep it tight):
1. Identification (name, title, office, version, date, signature blocks)
2. Approved tools and authorization basis
3. Data classes and what may be entered (small table)
4. Use cases in scope (short bulleted list)
5. Human-in-the-loop and verification per use case
6. Authorities and references (cite OMB M-24-10, OMB M-25-21, FedRAMP,
   Section 508 / 29 USC 794d, FOIA / 5 USC 552, Privacy Act / 5 USC 552a,
   plus agency-specific)
7. Failure modes and escalation (3-5 scenarios, named contact each)

CONSTRAINTS:
- Use plain language; no marketing tone
- Cite every authority verbatim with section number
- Do not invent FedRAMP statuses, authorization letter numbers, or policy
  citations — if I have not given you a specific reference, leave a
  bracketed [VERIFY] placeholder for me to fill in
- Total length: target 450-550 words so it fits on one page

Claude will produce something close to final on the first pass. Read it through twice. Replace every [VERIFY] placeholder with a real citation that you have looked at with your own eyes. If you cannot find the citation, the sentence does not stay.

The tells of a good playbook. It names a real authorization. It uses your agency’s exact policy citation. It admits something AI cannot do. It names a human for every output. It has a failure-mode section that is not blank.

Routing it for signature

A signed playbook is the goal. Unread playbooks pile up. The route that moves fastest, in most agencies:

  1. Send the draft to your direct supervisor first, with a one-paragraph email that summarizes what it is and asks for fifteen minutes to walk through it.
  2. Incorporate their edits the same day. Their signature is your social proof for the next reviewer.
  3. Forward the supervisor-signed draft to your privacy officer or CIO/CISO designee, depending on whose authority covers AI tool use at your agency. Ask which other reviewer they want included.
  4. If the tool involves CUI or sensitive PII, loop in your information security officer. If it produces public-facing content, loop in your Section 508 coordinator and plain-language officer.
  5. Once signed, save it in your records system with a version number and a calendar reminder to refresh it quarterly.

Federal compliance pitfalls

Pitfall 1 — Inventing FedRAMP authorizations. Tools claim “FedRAMP-ready” or “FedRAMP in process” status that is not the same as authorized. Verify the marketplace listing before citing it. If a tool is not on FedRAMP Marketplace with a current ATO covering your data class, do not assert it is.

Pitfall 2 — Leaving the failure-modes section vague. “Escalate to supervisor” with no scenario list reads like avoidance. Reviewers prefer three concrete scenarios with named contacts to ten generic ones.

Pitfall 3 — Citing OMB memos without the section number. “OMB M-24-10” alone is weak. Reference the specific section that authorizes your use case. The same applies to FOIA, the Privacy Act, and Section 508.

Pitfall 4 — Treating CUI as if it were public. Controlled Unclassified Information (32 CFR Part 2002) does not get pasted into a tool that is not authorized for it, even if the tool is on the agency’s general approved list. Your data-class table must reflect this distinction.

Pitfall 5 — Letting the playbook go stale. Tool authorizations change. Policies update. A signed playbook from a year ago that references a deprecated tool or a superseded memo is worse than no playbook. Quarterly refresh is the minimum.

Always check with your CIO, CISO, privacy officer, OGC, or IG before relying on this playbook in a high-stakes workflow. The playbook documents your practice; the reviewers authorize it. The signature matters more than the draft.

Homework — the one assignment that ties the week together

  1. Open a blank document. Title it Personal AI Playbook — [Your Name] — v0.1 — [Date].
  2. Run the prompt above against an authorized tool, using your Day 1 tool inventory and your day-by-day notes from this week.
  3. Replace every [VERIFY] placeholder with a real citation. If you cannot verify, delete the sentence rather than guess.
  4. Reformat to one page in 11-point type. Read it aloud. If a section sounds vague, tighten it.
  5. Send it to your supervisor today, not next week. Speed of routing is the variable you control; speed of signature is theirs.
  6. Calendar a quarterly refresh and a yearly full rewrite.

Day 5 Checkpoint — and the course

Before you close out the course, make sure you can answer:

Course wrap. You came in with a question about whether AI was even allowed at your agency. You leave with an inventory of approved tools, a method for drafting with citations, a FOIA-safe summarization workflow, accessibility-by-default habits, and a one-page playbook that turns all of it into a document a reviewer can sign. The work from here is not learning more — it is using what you have on a real document next week.

← Day 4 Course index Next course: Federal AI →