The sixty-second heuristic
Run every candidate input through four questions. Stop at the first no.- Am I authorized to share this with an outside system?
- Would I be comfortable if this appeared in a shared chat snapshot tomorrow?
- Does Claude need the raw secret, or only a redacted version?
- If the answer is wrong or leaked, who gets hurt?
Share / don’t-share matrix
Press releases, public filings, published docs, your own blog draft.
Still strip anything that is not public yet. “Almost announced” is not public.
Meeting notes without secrets, process docs, draft emails, agenda outlines.
Prefer a project with scoped files over pasting the same context into ten chats.
Names plus contact details, support tickets with private facts, HR notes.
Replace identifiers. Keep the structure Claude needs. Follow your privacy policy, not your impatience.
Passwords, API tokens, private keys, session cookies, recovery codes.
Not in chat. Not in a project file. Not “just this once.” Rotate anything that already slipped.
Health information, payment card data, government IDs, legal hold material.
If your org has an approved path, use that path. Improvised Claude workflows do not count.
Acquisition memos, unreleased earnings, side letters, board packs.
These fail the authorization test for most people. If your role truly allows it, use the enterprise workflow your counsel named.
Proprietary repos, infra diagrams, production configs, incident runbooks.
Many orgs allow Claude on code with guardrails. Strip secrets from configs. Prefer Code or a scoped project over a random chat.
NDA’d vendor docs, partner data rooms, customer contracts marked confidential.
Your permission inside the company is not the same as permission under the NDA. When unsure, ask legal once, then write the answer into team guidance.
Redact instead of abstaining
Most useful work does not need the forbidden field. It needs the shape around it.Ambiguous cases people get wrong
“It’s only in my private chat.” Private means not shared yet. It does not mean authorized. Training settings, thumbs-up feedback, connectors, and future share clicks still matter. See what leaves the session. “I’ll delete it after.” Deletion helps. It is not a substitute for authorization. Do not use delete as a conscience wipe. “The model already knows this kind of thing.” General knowledge is not your company’s document. Proprietary detail is still proprietary when the topic feels familiar. “I’m just asking it to summarize.” Summaries can quote, infer, and get shared later. The input is the risk. The verb is secondary. “Cowork / Chrome / a connector makes it different.” It makes the blast radius larger, not smaller. Inherited access and visible tabs become part of the conversation. Treat wider reach as a reason for tighter inputs.A cleaner daily habit
- Keep a redaction scratchpad: fake names, Client A/B, dollar ranges instead of exacts when exacts are unnecessary.
- Put durable context in a project with curated files, not in whatever chat is open.
- Prefer asking Claude for structure, critique, and drafts over asking it to hold the crown jewels.
- When a request feels borderline, rewrite the prompt so the sensitive fact is unnecessary. If you cannot, escalate to a human channel.