A developer adds a useful feature: paste a document, remove the names, ask an artificial intelligence (AI) service to produce a shorter version. The names disappear. The screen says the text is ready to send.
That last step is a different decision. Removing names does not establish that nobody can be identified from the remaining information. It also does not establish that this service, account or use has been approved for work.
The Information Commissioner's Office (ICO), the UK data protection regulator, explains that combinations of details can identify someone. Removing names and other obvious identifying details alone is insufficient. Its guidance is under review, so use the current version and appropriate advice for a real decision.
Rather than building a fictional privacy detector, this article builds a much smaller thing: a Pascal check of a written permission record for a general, made-up request. It preserves missing decisions. It never inspects a document or decides that private work is safe to send.
The case that a name-removal button cannot settle
Imagine a made-up staff note about Alex, the only night-shift supervisor at the fictional Cedar Repair shop, after an incident on 12 September. It has attached health notes. Remove Alex's name. The role, place, date and attachments remain.
In a real workplace, those details might still identify the person to someone with other information. Asking an unapproved AI service whether the real note is private enough would already share it. Do not use that as the review method.
When the task is only an outline, invent a request from scratch instead:
Create a neutral outline for a routine staff meeting. Use no personal information. Leave placeholders for facts and review by the responsible person. Do not decide what action should be taken.
That asks for structure without uploading a staff record. It still needs review before becoming work and does not approve a staff decision or provide legal advice.
Keep the permission record narrower than the product name
A service name alone cannot describe permission. The record in this example names the service, the work account and one approved task. It also records whether the approval is still current. The proposed request has the same fields plus its content category, whether attachments were reviewed and whether it connects a work folder.
The fictional permission covers only a generic meeting outline with no private work. It does not cover sensitive work through any service. A real business may approve a particular controlled use of sensitive information, but this demonstration cannot establish that approval or make the risk assessment.
The person entering GeneralOutline is making a claim about the content. The program does not read the question or files. If the content is unresolved, it asks the responsible person instead of inferring safety from a missing name.
The folder rule is also deliberately conservative: connecting any work folder requires review outside this example. It does not say every folder connection is prohibited. It says this narrow record does not authorise it.
Run the complete fictional check
Install Free Pascal through the supported route for your computer. Save this as WorkSharingReview.pas. In a command window opened in that folder, compile it with fpc -Cr -Co -Ci WorkSharingReview.pas. The switches enable additional range, arithmetic-overflow and input/output checks. On Linux, run ./WorkSharingReview.
There are no comments inside the code. It has no document entry, network connection, file upload or service integration.
program WorkSharingReview;
type
TWorkKind = (GeneralOutline, PrivateRecord, UnknownContent);
TSharingResult = (DoNotSend, AskResponsiblePerson, ReadyForReview);
TPermissionRecord = record
ServiceName: String;
AccountName: String;
ApprovedTask: String;
IsCurrent: Boolean;
end;
TRequestRecord = record
ServiceName: String;
AccountName: String;
ProposedTask: String;
WorkKind: TWorkKind;
AttachmentsReviewed: Boolean;
HasConnectedWorkFolder: Boolean;
end;
var
Permission: TPermissionRecord;
Request: TRequestRecord;
Checks: Integer;
Failures: Integer;
function ReviewRequest(Rule: TPermissionRecord;
Proposed: TRequestRecord): TSharingResult;
begin
if Proposed.WorkKind = PrivateRecord then
ReviewRequest := DoNotSend
else if (Proposed.WorkKind = UnknownContent)
or not Proposed.AttachmentsReviewed
or Proposed.HasConnectedWorkFolder then
ReviewRequest := AskResponsiblePerson
else if not Rule.IsCurrent
or (Rule.ServiceName = '') or (Rule.AccountName = '')
or (Rule.ApprovedTask = '')
or (Rule.ServiceName <> Proposed.ServiceName)
or (Rule.AccountName <> Proposed.AccountName)
or (Rule.ApprovedTask <> Proposed.ProposedTask) then
ReviewRequest := AskResponsiblePerson
else
ReviewRequest := ReadyForReview;
end;
procedure Expect(LabelText: String; Wanted: TSharingResult);
var
Actual: TSharingResult;
begin
Actual := ReviewRequest(Permission, Request);
Checks := Checks + 1;
if Actual <> Wanted then
begin
Failures := Failures + 1;
WriteLn('FAIL: ', LabelText);
end;
Write(LabelText, ': ');
case Actual of
DoNotSend: WriteLn('do not send through this example');
AskResponsiblePerson: WriteLn('ask the responsible person');
ReadyForReview: WriteLn('record ready for review');
end;
end;
begin
Checks := 0;
Failures := 0;
Permission.ServiceName := 'Fictional Outline Service';
Permission.AccountName := 'Fictional Work Account';
Permission.ApprovedTask := 'generic meeting outline';
Permission.IsCurrent := True;
Request.ServiceName := Permission.ServiceName;
Request.AccountName := Permission.AccountName;
Request.ProposedTask := Permission.ApprovedTask;
Request.WorkKind := PrivateRecord;
Request.AttachmentsReviewed := True;
Request.HasConnectedWorkFolder := False;
Expect('Private staff record', DoNotSend);
Request.WorkKind := UnknownContent;
Expect('Names removed but content unresolved', AskResponsiblePerson);
Request.WorkKind := GeneralOutline;
Request.AccountName := 'Fictional Personal Account';
Expect('Different account', AskResponsiblePerson);
Request.AccountName := Permission.AccountName;
Request.ProposedTask := 'staff decision';
Expect('Different task', AskResponsiblePerson);
Request.ProposedTask := Permission.ApprovedTask;
Request.AttachmentsReviewed := False;
Expect('Attachments not reviewed', AskResponsiblePerson);
Request.AttachmentsReviewed := True;
Request.HasConnectedWorkFolder := True;
Expect('Connected work folder', AskResponsiblePerson);
Request.HasConnectedWorkFolder := False;
Permission.IsCurrent := False;
Expect('Approval no longer current', AskResponsiblePerson);
Permission.IsCurrent := True;
Permission.ServiceName := '';
Expect('Missing service in permission record', AskResponsiblePerson);
Permission.ServiceName := Request.ServiceName;
Permission.AccountName := '';
Expect('Missing account in permission record', AskResponsiblePerson);
Permission.AccountName := Request.AccountName;
Permission.ApprovedTask := '';
Expect('Missing task in permission record', AskResponsiblePerson);
Permission.ApprovedTask := Request.ProposedTask;
Request.ServiceName := 'Different Fictional Service';
Expect('Different service', AskResponsiblePerson);
Request.ServiceName := Permission.ServiceName;
Expect('Made-up outline within recorded scope', ReadyForReview);
WriteLn('Checks: ', Checks, '; failures: ', Failures);
if Failures > 0 then
Halt(1);
end.
What the run demonstrated
Actual output:
Private staff record: do not send through this example
Names removed but content unresolved: ask the responsible person
Different account: ask the responsible person
Different task: ask the responsible person
Attachments not reviewed: ask the responsible person
Connected work folder: ask the responsible person
Approval no longer current: ask the responsible person
Missing service in permission record: ask the responsible person
Missing account in permission record: ask the responsible person
Missing task in permission record: ask the responsible person
Different service: ask the responsible person
Made-up outline within recorded scope: record ready for review
Checks: 12; failures: 0
The twelve checks cover private content, unresolved content, a different account, a different task, unreviewed attachments, a connected folder, outdated approval, each missing permission field, a different service and the complete made-up outline record.
The last result is still ReadyForReview, not permission to send. The program only found matching entries under its narrow fictional rule. It did not verify that the recorded permission was genuinely approved, that the approval remains current, that the content category is truthful, or that the service's settings and terms satisfy the business's needs.
Exact string matching here is intentional. A slightly different service name or account remains unresolved rather than being guessed into a match. A production system would need stable account identifiers and a real permission source. Do not fix a failed comparison by making it accept anything that looks similar.
Both programs in this batch were compiled using Free Pascal 3.2.2 extracted from Ubuntu packages into a local Linux test folder. Compiler version and successful execution were recorded, with additional checks enabled. This is a computer test of invented entries, not a staff trial, a privacy assessment or testing of an AI provider. Windows and macOS were not tested.
Where the human review belongs
Keep approval with the person responsible for the business's information and tools. They need to consider the actual service, account, settings, type of work, current provider terms and relevant contracts. A work licence or a setting that stops training on submitted text is not a complete permission record by itself.
Attachments, screenshots and connected sources are part of sharing too. The interface should make them visible before any send step. Do not show a green "safe" badge merely because the question has no recognised names. A feature may help with one narrow editing task without having authority to approve the wider sharing decision.
If work has already been shared by mistake, stop sending more and tell the responsible person promptly through the approved route. Use the business's incident process. Deleting a chat is not proof that every copy is gone.
Use the free card for the discussion
Read Before you paste work into an AI tool. Its four checks cover the approved service/account, private work, made-up examples and review of the answer.
The card has no data-entry fields, scripts or saved answers. It cannot inspect a request, remove private information or approve a service. Use it to prepare a discussion about the actual rule, without copying private work into another service to ask for help.
Sources and limits
- ICO: ensuring people cannot be identified.
- National Cyber Security Centre (NCSC): AI and cyber security.
- Free Pascal documentation.
General guidance, not legal or professional advice. Check current rules, contracts and provider terms for the exact service and use.
Top comments (0)