Data Governance¶
WorkDone products handle two kinds of data that deserve deliberate governance: the documents you put into the Copilot knowledge base, and the workforce telemetry that feeds the Vision Dashboard and AI Transformation Accelerator assessments. This guide covers how to decide what goes in, how to handle sensitive material, and how to run workforce analytics in a way your employees can trust.
Governance decisions are yours to make. WorkDone provides the controls; this guide describes how successful deployments use them.
Decide what data enters the knowledge base¶
Before connecting a source, ask three questions about it:
- Is this content appropriate for everyone who can use Copilot? The knowledge base is organization-scoped, but within your organization, Copilot answers from the whole knowledge base. If a document shouldn't be readable by every Copilot user, it shouldn't be in the knowledge base.
- Is it authoritative? Published policies, procedures, specs, and manuals belong. Drafts, opinions, and superseded versions don't; see Knowledge Base Curation.
- Does it contain personal or regulated data? Documents containing employee personal data, customer personal data, health information, or contract-restricted material need a deliberate decision, not a default include.
Write the answers down as a short inclusion policy. Even half a page ("published procedures and product documentation in; HR files, legal matters, and anything with customer personal data out") gives your approval-queue reviewers a standard to apply consistently.
Handle sensitive documents deliberately¶
You have two layers of control over sensitive material:
- Exclusion at the source. The strongest control is scope: keep sensitive libraries and folders out of the connected sources entirely. HR case files, legal matters, M&A material, and payroll data should never be in a synced location.
- The approval queue. Documents flagged by the AI content review wait for human approval before entering the knowledge base. Your reviewer's job is to apply the inclusion policy: reject anything sensitive that slipped into a connected source, then fix the source so it doesn't recur.
If a sensitive document has already made it into the knowledge base, remove it from the connected source (the sync mirrors your sources) and contact support if you need confirmation it is fully purged.
Govern workforce telemetry responsibly¶
The Vision Dashboard and AI Transformation Assessments are built on workforce activity telemetry from your monitoring deployment. This is data about your employees, and how you govern it determines whether the analytics program earns trust or resentment.
Be transparent with employees¶
- Tell people what is collected and why before the telemetry connector goes live, in plain language, through your normal employee-communication channels.
- State what the data is used for (understanding workload, tool adoption, and transformation opportunities) and, just as importantly, what it is not used for.
- Where you have works councils, employee representatives, or local-law consultation duties, involve them early. Retrofitting consent is far harder than obtaining it.
Rely on anonymization by default in assessments¶
AI Transformation Assessment reports anonymize participants by default: findings are presented at the team and pattern level, not as named-individual profiles. Keep it that way:
- Treat the default as your policy, and require a documented, justified decision before any de-anonymized analysis.
- When sharing assessment reports internally, share the anonymized deliverable; don't reconstruct individual attribution from other sources alongside it.
Scope the observation window¶
Telemetry collection for an assessment should cover a defined observation window agreed in advance: long enough to capture representative work patterns, no longer.
- Agree on the window (start and end dates) with WorkDone before collection begins.
- Communicate the window to the affected teams.
- Avoid open-ended collection "just in case"; a bounded window is easier to justify, easier to communicate, and produces a cleaner assessment.
Control identity-key handling¶
Anonymized analysis still requires a mapping between telemetry identities and real people at some stage: the identity key. Keep it under controlled access:
- Restrict the mapping to the smallest possible group (typically the assessment sponsor and one HR or IT owner).
- Store it in an access-controlled location, never in the shared assessment deliverables.
- Dispose of it when the assessment engagement ends, per the terms you agreed with WorkDone.
Transparency is a feature, not a risk
Organizations that announce telemetry programs openly get better data (behavior normalizes quickly) and better outcomes, because employees engage with the resulting findings instead of distrusting them.
Route data-retention questions to support¶
Retention, deletion, and data-processing terms are contractual matters that vary by agreement. Rather than guessing from documentation, route these to support or your account manager:
- How long is our data retained, and what happens at contract end?
- Can we request deletion of a specific document, session, or telemetry window?
- Where exactly is our data processed, and what are your data-processing terms?
- Can we get a copy of our data exported?
Support will answer against your actual agreement. See also Security and Compliance for the platform-side posture.
Related reading¶
- Knowledge Base Curation: day-to-day quality control of what's in the knowledge base
- Security and Access: who can see and administer the data
- AI Transformation Accelerator: how assessment engagements work