The AI-Powered CSM

AI governance

Not a policy doc. A working system.

Everything a CSM needs to use AI professionally and keep customer trust intact: what can go into AI, what cannot, and a tool that strips customer details before you paste.

Open AI Governance →

Can I paste this?

A 20-second check to run before anything customer-related goes near an AI tool. The first question is always the same: is the tool approved by your organisation for customer data? Free tiers and personal accounts count as "no".

The Anonymiser

Paste an email thread, call notes or a ticket export. It swaps names, companies, emails, phone numbers and money for placeholders, so you can paste safely. When the AI answers, paste its reply back and it restores the real names. All of it happens in your browser. It catches the obvious identifiers, so always read the output before you paste, and follow your company's own policy.

What data can go into AI

DataEnterprise, approved for customer dataBusiness planFree or personal
Customer names and contactsOK if policy allowsAnonymise firstNever
Account health and metricsOK if policy allowsCheck the termsNever
Call transcriptsOK if policy allowsAnonymise firstNever
Pricing and strategyOnly with clearanceNeverNever
Anonymised data (CUSTOMER_A)SafeSafeFine
Your process and templatesSafeSafeFine

“OK if policy allows” means your organisation has approved that tool for customer data and its policy covers this kind of data. Send only what the task needs, and anonymise if you are not sure. Your organisation's policy, its data processing agreement with the vendor and your customer contracts always come first.

Six rules that don't change

  1. Approved tools only. Not the free tier of anything, not a personal account, not just this once.
  2. The ten-second check. Would you be comfortable if this text appeared in an email to the customer's legal team?
  3. Anonymise outside the line. If a tool is not approved for customer data, or you are not sure, use placeholders such as CUSTOMER_A and CONTACT_1_IT. The analysis is just as good.
  4. Personal data is processing. Under GDPR, pasting a contact's name or email into AI is processing personal data.
  5. Output accountability. Everything AI drafts goes out under your name, so check every fact and figure.
  6. Strategy needs clearance. Pricing, legal positions and NDA material: approved tool only, and only with clearance from whoever owns them.

Practice and a team policy

Four real scenarios let you test what you would do, such as a champion's replacement copying you on an email chain full of contact details. For managers, there is a short team policy template to copy, fill in and send before anyone uses AI with customer data, plus three questions to ask IT or legal. The full detail is in Foundation Module 04: Data hygiene and AI safety.

Free, no login, and nothing you type leaves your browser.

Open AI Governance →