Chapter 14 — Reps
Twelve reps to turn this week’s rule into a reflex, then a graded Data Redline lab that becomes a tool you keep. This is a drill week: the reps below are the assignment. Don’t read them — do them, out loud, with a pen.
Ground rules
- Type it yourself. Write your verdicts and reasons in your own words, in your own
reps.txt. Copying my phrasing skips the thinking that is the whole point.- Try everything. Actually classify every snippet, actually redact one, actually draft the policy. A rep you only thought about is a rep you didn’t do.
- Predict before you check. Before you open the classifier widget or reveal an answer, write down your call and why. The gap between your prediction and the truth is the learning.
- AI usage note (this week’s twist): You may discuss these concepts with an AI, but this is the week about what not to paste — so use only fabricated or already-public data in any prompt, never real sensitive data. End every AI-assisted rep with one honest line: what I asked, and how I kept real sensitive data out of it.
- Where to run these (Concordia’s vetted tool): Do the AI-assisted reps in BoodleBox — sign in at
box.boodle.aiwith your CUW account. It’s the FERPA-compliant, SOC 2, doesn’t-train-on-your-data platform the university licensed so your coursework and work content have a vetted home instead of a public chatbot (as of 2026). That’s exactly the point this week: BoodleBox is the right place, not a license to paste needless real PII — keep the twist above and use fabricated or already-public data. No BoodleBox access? Any public assistant runs these fabricated-data drills — but that off-campus gap is precisely what the vetted tool closes.- Keep a
reps.txt. One short written reflection per rep. This is graded thinking, not busywork — and it feeds directly into the lab.
Reps 1–3: Spot the sensitivity
Rep 1 — Redline the snippet stack
Open code/data-snippets.txt. For each of the twelve snippets, write a verdict — SAFE / REDACT / NEVER — and a one-line reason. Predict your split before you start (how many of the twelve do you expect to be NEVER?), then compare.
| # | Verdict | One-line reason |
|---|---------|--------------------------------------------------|
| 1 | SAFE | public marketing copy, no personal/secret data |
| 2 | REDACT | customer PII (name, address, card) — placeholder it |
| 3 | NEVER | confidential unannounced acquisition + layoffs |
| ... |
Reflection: Which snippet was hardest to call, and why? Where did your predicted NEVER-count differ from your actual one — did you over- or under-estimate the risk?
Rep 2 — Name the category
Go back through your twelve verdicts and tag each with the kind of sensitivity: PII, PHI (HIPAA), student record (FERPA), confidential/trade secret, credential/secret, or none. A snippet can carry more than one.
Reflection: Which category showed up most often in a stack meant to look like an ordinary week? What does that tell you about how routine these decisions actually are?
Rep 3 — Catch the re-identification trap
Take Snippet 6 (the patient) or Snippet 7 (the students). Cross out the person’s name only and ask: is what remains still identifiable? List every leftover field (birthdate, MRN, score, IEP status, appointment) that could re-identify the person alone or in combination.
Reflection: Why is “I removed the name” almost never the same as “I de-identified it”? Tie your answer to the ZIP + birthdate + sex finding from §14.3.
Reps 4–5: Redact for real
Rep 4 — Produce a paste-able version
Pick one snippet you marked REDACT. Rewrite it with every specific replaced by a placeholder — [NAME], [ACCOUNT #], [ADDRESS], [AMOUNT] — so that only the shape of the task remains. Then write the prompt you’d actually send — in BoodleBox (box.boodle.ai, Concordia’s vetted tool; a public assistant as fallback) — using the redacted text. Redaction still earns its keep even in the vetted tool: strip the specifics the task doesn’t need, then paste.
BEFORE: "...order #48812 to 4417 Linden Ave, Apt 3B, Columbus OH 43201,
card ending 4092, call (614) 555-0173..."
AFTER: "...order [ORDER #] to [ADDRESS], card ending [LAST4], phone [PHONE]..."
PROMPT: "Write a warm apology reply for a customer whose order arrived in the
wrong size and whose card was double-charged. Use placeholders."
Reflection: Did the redacted version still get you the help you needed? When redaction doesn’t — when the specifics are the whole point — what does that tell you about where the snippet really belongs?
Rep 5 — Find the line that can’t be redacted
Pick one snippet you marked NEVER. Try, honestly, to redact it into something paste-able. Show your attempt — then explain why it either (a) still leaks, or (b) becomes so generic it’s useless.
Reflection: What distinguishes a REDACT snippet from a NEVER snippet? Write the one-sentence test you’ll use in real life to tell them apart.
Reps 6–8: Regulated data and policy
Rep 6 — Make the HIPAA / FERPA call
For Snippet 6 (health) and Snippet 7 (education), name the specific regime (HIPAA / FERPA), what makes the data protected, and what a compliant path would be — a redacted template, an approved BAA-covered or district-approved tool, or doing it by hand.
Reflection: In both cases the intent was kind (a gentle reminder, an encouraging note). Why does good intent not change the classification? What would you tell a well-meaning colleague about to paste one of these?
Rep 7 — Read a policy like a professional
Find your employer’s AI policy (or, if none, use a sample or your school’s acceptable-use policy). Answer the three questions from §14.5 in writing: (1) which tools/tiers are approved, (2) what data may go into them, (3) what must you disclose. If you’re at Concordia, your approved tool is BoodleBox — name it in answer (1), and in answer (2) note what data even a FERPA/SOC-2, no-train tool still shouldn’t get (needless PII, HIPAA PHI). If there is no policy, write “NONE — I am the drafter” and note what you’ll assume instead.
Reflection: Did the policy distinguish tool approval from data approval? Where was it silent or unclear — and who would you ask to resolve it?
Rep 8 — Resolve a shadow-AI dilemma
Scenario: the approved company tool can’t handle a big confidential PDF you need summarized by end of day. Write the three-sentence message you would actually send your manager or IT to raise the gap — before routing around it.
Reflection: Why is “just this once” through a personal account the wrong move even under deadline? What does raising it out loud protect — besides the data?
Reps 9–10: Ownership and responsibility
Rep 9 — Make an ownership judgment
Scenario: you generated a company logo from a one-line prompt in a consumer image tool. In three or four sentences, state what you can and cannot assume about (a) owning it, and (b) it infringing someone else’s work — as of mid-2026 — and what you’d do before using it commercially.
Reflection: Why is “the AI made it, so it’s mine and it’s fine” an open question, not a settled permission? Where does the spine rule (“you own the verdict”) bite here?
Rep 10 — Disclose or don’t
List three real tasks from your own work where AI might help. For each, decide whether you’d disclose the AI assistance, and write the one-line disclosure you’d use (or why none is needed).
Reflection: What’s your personal rule for when AI help crosses from “not worth mentioning” (spell-check) to “must disclose” (AI drafted a document I present as my own analysis)?
Reps 11–12: Build and drill the habit
Rep 11 — Draft your one-page AI-use policy
Fill in code/ai-use-policy-template.txt for your real job. Every bracket filled, one page, specific to you: your NEVER list, your redact rule, your approved-tools table, your disclosure and verification commitments, and your spine rule in your own words.
Reflection: What went on your NEVER list that a generic template wouldn’t have — the data specific to your role that only you would know to name?
Rep 12 — Drill the classifier cold
Use the Can I Paste This? widget below the chapter. Run it once, cold, and record your score. Then run it again and try to explain, out loud, the category for each snippet before revealing the answer. On a third pass, ask a sharper question for each snippet — would this go in a public chatbot, or does it belong in Concordia’s vetted BoodleBox? — and notice which verdicts change with the destination and which are really about minimizing data no matter the tool.
Reflection: Which way do you err — over-trusting “probably fine” snippets, or over-flagging safe ones? Now that you know your bias, what will you double-check before every real paste?
Done? One Last Thing.
A miniature of the lab, start to finish, on your own material. Take one real thing from your actual inbox or files this week — do not copy its sensitive contents anywhere. In reps.txt, write three lines about it:
- What it is (in generic terms — “a client email with an account number”).
- Your verdict — safe / redact / never — and the category.
- What you’d actually do — the redacted prompt you’d send, the approved tool you’d use (for Concordia work, BoodleBox), or “by hand.”
If you can do that for one real item tonight, you can do it for every paste for the rest of your career. That is the whole habit in miniature: pause, classify, protect, then proceed.
Graded Lab — Data Redline (drill lab)
This is the graded assignment for Week 14 (it becomes your Canvas submission). No new project — this lab is the deliverable. Submit one document (.pdf or .docx) with two parts, plus your reflections file.
Part 1 — The Redline (a table)
Classify all twelve snippets in code/data-snippets.txt. For each, provide:
| # | Verdict (SAFE / REDACT / NEVER) | Sensitivity category | One-line reason | If REDACT: the paste-able version |
|---|
- Every snippet gets a verdict, a category, and a reason.
- Each snippet you mark REDACT must include the actual redacted, paste-able rewrite.
- For each snippet you mark NEVER, name the compliant alternative (an approved tool — for Concordia, BoodleBox / a local model / by hand).
Part 2 — Your Personal AI-Use Policy (one page)
Complete code/ai-use-policy-template.txt for your real (or realistic) role — every bracket filled, one page. It must include:
- A NEVER list with at least five entries specific to your work.
- A redact rule with concrete placeholder conventions.
- An approved-tools table mapping kinds of work to where they may go and why. (Concordia readers: BoodleBox should be your vetted row — FERPA/SOC-2, no training on your data — with a note of what data even it doesn’t get.)
- A disclosure rule and a verification checklist.
- Your spine rule in your own words.
Deliverables checklist
- Redline table — all 12 snippets classified, categorized, reasoned.
- Redacted rewrites for every REDACT snippet; compliant alternative named for every NEVER.
- One-page personal AI-use policy, every bracket filled.
-
reps.txtwith your reflections and honest AI-usage notes. - No real sensitive data anywhere in what you submit.
Rubric (out of 100)
| Criterion | Points |
|---|---|
| All 12 snippets classified with a defensible SAFE/REDACT/NEVER verdict | 20 |
| Correct sensitivity category named for each (PII / PHI / FERPA / confidential / secret / none) | 15 |
| REDACT snippets include a genuine paste-able rewrite (specifics → placeholders) | 15 |
| NEVER snippets name a compliant alternative; re-identification trap caught | 10 |
| Personal AI-use policy complete, one page, every bracket filled | 20 |
| NEVER list specific to the reader’s real role (not generic) | 10 |
reps.txt reflections present, honest, with AI-usage notes; no real sensitive data submitted | 10 |
| Total | 100 |
What mastery looks like: I can read your redline and tell you made the calls — you caught the birthdate-plus-MRN that survives a name deletion, you refused to paste the confidential deal even in summary, and your policy names the one kind of data only someone in your job would know to protect. The table is table stakes. The judgment is the grade.
Up next: This is the drill week — the graded Data Redline lab is right above, and it becomes your Week-14 submission. Keep Appendix C as your desk reference. Then on to Chapter 15 — Building Your AI-Enhanced Workflow, and its own drill lab.