Operating ProcedureExecution layer

Assistant Context Intake and Scope Lock (Onboarding)

A checklist with 7 steps: Inventory every system the assistant will read from before granting a single connection.

By InnovaAI ResearchPublished

What are the steps?

checklist

Assistant Context Intake and Scope Lock (Onboarding)

  1. 01

    Inventory every system the assistant will read from before granting a single connection

    List the client's inbox, calendar, Slack or Teams workspace, CRM, and project board, then mark which ones hold personally identifiable client data. MyHandler-style assistants that capture screen content, transcripts, files, and messages into an encrypted on-device database will ingest all of it, so the inventory is the boundary of your exposure.

  2. 02

    Classify each data source as billable-work context or client-confidential

    Retainer work usually needs pipeline notes and meeting history; it rarely needs the client's HR channel or legal threads. Write the classification down and get the client to initial it.

  3. 03

    Set a retention window and a deletion owner for captured context

    Pick a number of days (30, 90, or end-of-engagement) and name the person who executes deletion. On-device tools such as PHNTM One keep data local, which simplifies the story but does not remove the obligation to delete on schedule.

  4. 04

    Define the three to five recurring tasks the assistant is allowed to execute unattended

    Typical starting set: meeting recap distribution, follow-up email drafts, calendar triage, and status-note capture. Anything outside the list routes to a human for the first 30 days.

  5. 05

    Write the escalation rule for relationship-sensitive messages

    Flag any thread involving pricing disputes, scope changes, or named client stakeholders so a human drafts the reply. Automated context misses tone and history that a delivery lead carries in their head.

  6. 06

    Confirm the client's written consent covers AI processing of their data

    Check the master services agreement for an AI-processing clause and add an amendment if it is missing. Data-privacy exposure on a retainer is a contract problem before it is a technology problem.

  7. 07

    Log the configuration in a one-page internal register with the review date

    Record connected sources, retention window, permitted tasks, and the next audit date. Forrester's 2027 predictions point to compute and infrastructure constraints feeding directly into tool pricing, so a register that tracks dependencies also protects retainer margins.