Start with value, not novelty

Describe the work before discussing software: its start, owner, steps, good result and material delays or mistakes. The New Zealand Digital government responsible-AI overview recommends clear objectives, risk-and-benefit assessment, testing and checking tool fit. This public-service guidance is not private-sector law or a savings promise.

J2K's screening lens favours frequent work with a repeatable path and measurable result, such as routing an enquiry or updating an internal job status. Frequency alone does not establish suitability: customer impact, exceptions, access and personal information may outweigh convenience.

Score the workflow before choosing tools

Discuss one workflow with its operators and owner. This is J2K editorial triage, not a government score, legal test or total. A promising candidate combines repetition and time cost with limited variability, impact and data exposure. Investigate, control or defer any high-risk row; other rows cannot cancel it out.

The Privacy Commissioner says privacy duties apply when AI handles personal information. Digital.govt.nz's public-service guidance considers tool access, users, external sharing, security and output checks. Those official considerations inform the questions; J2K supplies the low, medium and high interpretation.

J2K workflow scorecard — discuss each row; do not calculate a total
FactorLowMediumHighDecision prompt
FrequencyMonthly or irregularSeveral times a weekDaily or moreIs there enough volume to test?
Time costA few quick stepsNoticeable staff effortSustained handling or reworkWhat will the baseline capture?
VariabilityStable inputs and rulesKnown exceptionsCases change often or rely on judgementCan exceptions be detected and routed to a person?
Impact of errorEasy internal correctionCustomer delay or reworkFinancial, safety, rights or reputation consequencesIs approval required before action?
Data sensitivityLittle or no personal informationRoutine customer detailsSensitive or extensive personal informationCan data be reduced or excluded?

An enquiry follow-up scenario

Illustrative scenario only, not a client result or time-saving claim: an Auckland property-maintenance firm wants consistent website-enquiry follow-up. The workflow captures necessary details, tags the service and drafts from approved information. It neither accepts the job nor sends automatically.

A coordinator checks the recipient, facts, tone, service area and promises, then approves or rewrites. Delivery uses the authorised channel; logging keeps only necessary status. Missing details, unusual requests, complaints and sensitive content go to a person. On failure, staff use the manual template until the owner investigates.

  • Capture — collect only the contact and service details necessary for this enquiry.
  • Assisted draft — use approved business facts; do not invent scope, price or availability.
  • Human approval — verify the recipient and every customer-facing commitment before sending.
  • Delivery — send only after approval through the authorised business account.
  • Logging — record outcome and exceptions without retaining unnecessary message content.

Design the controls first

The Privacy Act principles cover how New Zealand organisations and businesses collect, store, use and share personal information, including necessity, safeguards, accuracy before use and retention limits. The Commissioner's AI guidance recommends understanding the tool, updating privacy risk assessment, testing accuracy and fairness, and protecting prompts and data. This is source guidance, not a compliance assessment or legal advice.

Human approval is one control, not a cure for unnecessary collection or insecure sharing. Rollback can restore a workflow or configuration; it cannot guarantee recovery of information already disclosed. Prevention, minimum access and a fast pause remain essential.

  • Owner — name the person accountable for outcomes, access reviews, incidents and the decision to resume.
  • Minimum access — give the workflow only the accounts, records and actions required for its narrow purpose.
  • Data minimisation — remove unnecessary fields, set justified retention and avoid copying full records into prompts.
  • Approval — identify the person and evidence needed before messages, bookings, payments or record changes proceed.
  • Exceptions — define missing, conflicting, sensitive and high-impact cases that must enter a human queue.
  • Pause and rollback — provide a tested stop control, preserve the manual path and document how to restore configuration and reconcile incomplete work.

Build an honest baseline

J2K recommends observing a representative period before change. Record handling time, errors and rework, required-fact consistency, completion, and a relevant customer outcome such as a reply, booking or resolved request. Define each measure in advance and use the same rules during the pilot.

Record review effort, missed exceptions, complaints and corrections as well as speed. These are J2K measures, not official benchmarks, predicted savings or ROI proof. A small pilot informs one decision; it does not establish performance at every volume or in every scenario.

Run a 30-day pilot

This J2K sequence is not government policy or a day-30 result promise. Digital.govt.nz's public-service guidance recommends iterative testing, validation and monitoring. The Privacy Commissioner recommends reviewing and updating privacy impact assessments as use evolves. Keep the rollout narrow, pausable and comparable.

  • Days 1–5 — map the current process, owner, permissions and data flow; capture the agreed baseline and review privacy risk.
  • Days 6–10 — build the smallest controlled version; test accurate cases, bad inputs, exceptions, access boundaries, approval, pause and rollback.
  • Days 11–20 — release to a limited team or enquiry type; retain the manual path and review every customer-facing output before action.
  • Days 21–27 — compare measures, inspect logs and exceptions, ask operators what work moved rather than disappeared, and note customer effects.
  • Days 28–30 — decide to keep, redesign or stop; document the evidence, unresolved risks, owner and next review date.
  • Stop immediately for wrong recipients, unexpected sensitive-data exposure, unauthorised access, harmful or materially incorrect commitments, or exceptions that bypass review. Contain the issue, use the manual path and investigate before any restart.

What not to automate first

Digital.govt.nz's public-service guidance calls for stronger assurance for higher-risk or higher-impact work. The Privacy Commissioner advises avoiding AI handling of personal information when safe, lawful use is uncertain. This supports caution, not a complete legal prohibition list or private-sector certification.

J2K recommends deferring high-stakes judgement, unstable work, ownerless processes and sensitive-data-heavy tasks. First clarify purpose, simplify the process, reduce data and establish assurance. A human click at the end does not automatically make an unsuitable workflow safe.

Decide whether to keep it

Compare the pilot with the baseline using the same definitions. Include benefit, review time, errors, exceptions, control maintenance and customer impact. This is J2K's ROI method, not an official government calculation. Speed cannot outweigh serious errors, privacy risk or poor customer outcomes.

Keep when evidence and controls support continuation. Redesign data, access, exception routing or approval when needed. Stop or choose another approach when material risk remains or benefit does not justify total effort. Document exceptions, retain an accountable owner and review after changes. The tool never inherits the business's accountability.

Common questions

Can we put customer information into an AI tool?

Privacy duties still apply. Assess necessity, purpose, access, sharing, safeguards, accuracy, retention, the actual tool and its data flow. Where safe and lawful handling is uncertain, the Privacy Commissioner's guidance supports keeping personal information out. This guide is not legal advice.

Does human approval make an automation safe?

No. Reviewers need context, time and authority. Approval does not cure unnecessary collection, excessive access, insecure disclosure or a poor purpose, and accountability remains with the business. Higher-impact work needs stronger assurance and may be unsuitable.

Which automation tool should we buy first?

Choose the workflow and controls first. Compare tools on required access, external sharing, security, permissions, output quality, monitoring, pause and exit options. No tool is best for every business, and selection does not certify compliance or security.

How should we calculate ROI?

J2K compares measured benefit with setup, subscriptions, staff review, exceptions, corrections, control maintenance and customer impact. Use consistent baseline definitions and include quality and risk. A pilot informs a decision; it does not guarantee ROI or future performance.

Primary sources