# Editable AI email triage rules worksheet

Use this worksheet to design, review and test a bounded email-triage policy before connecting it to a live mailbox. Replace every bracketed field. Do not paste real sensitive mail into an unapproved environment.

## 1. Document control

| Field | Entry |
|---|---|
| Policy ID | [e.g., TRIAGE-001] |
| Mailbox and folders in scope | [named mailbox/folders] |
| Business owner | [role and name] |
| Security/privacy reviewer | [role and name] |
| Legal/HR/finance reviewers | [roles when applicable] |
| Rubric version | [semantic version] |
| Evidence cutoff | [ISO 8601 timestamp] |
| Review date | [date] |
| State | [DRAFT / TESTING / APPROVED / RETIRED] |

## 2. Business decision and exclusions

**Decision this policy supports:** [one sentence]

**Messages included:** [accounts, aliases, folders, date range, languages]

**Messages excluded:** [personal mail, privileged mail, regulated material, unsupported attachments]

**Allowed effects:** [label, queue, assign, create review task, prepare draft]

**Prohibited effects:** [send, delete, pay, approve, disclose, export, change account data]

**Fallback:** [named human queue and response time]

## 3. Primary category dictionary

Give each message one primary owner-facing category. Add secondary labels only when they help another reviewer; do not let secondary labels silently change authority.

| Key | Operational meaning | Positive evidence | Confusable with | Primary owner | Default priority |
|---|---|---|---|---|---|
| [KEY] | [meaning] | [observable evidence] | [nearby label] | [queue/role] | [P1–P4] |
| [KEY] |  |  |  |  |  |
| [KEY] |  |  |  |  |  |

## 4. Precedence and abstention

**Protected-route precedence:** [for example SEC_PRIV > LEGAL > HR > BILLING > ordinary work]

**Why this order exists:** [harm or authority boundary]

**Abstain when:**

- [identity, relationship or thread cannot be established]
- [required attachment/context is absent]
- [two protected categories conflict]
- [message asks for an effect outside policy]

**Abstention output:** [REVIEW label, owner, evidence request, prohibited effects]

## 5. Priority rubric

| Priority | Observable test | Response owner/time | Examples | Non-examples |
|---|---|---|---|---|
| P1 | [protected/high-impact condition] | [owner/SLA] | [example] | [counterexample] |
| P2 | [owned deadline or blocked work] |  |  |  |
| P3 | [routine response or scheduling] |  |  |  |
| P4 | [information only] |  |  |  |

Record the exact deadline and timezone when present. Never infer urgency from punctuation, capitalization or sentiment alone.

## 6. Capability matrix

`Allowed` means the policy permits the effect after stated checks; it does not mean every message should receive it.

| Category | Label | Queue/assign | Create review task | Prepare draft | Send | Delete | Pay/approve | Export/disclose |
|---|---:|---:|---:|---:|---:|---:|---:|---:|
| [KEY] | [Y/N] | [Y/N] | [Y/N] | [Y/N + checks] | N | N | N | N |
| [KEY] |  |  |  |  | N | N | N | N |

## 7. Known-answer evaluation register

Use consented or synthetic messages. Keep message and thread IDs stable so corrections and continuations can be reconciled.

| Message ID | Thread ID | Approved evidence | Gold primary/secondary | Gold priority | Protected? | Draft eligible? | Owner and smallest allowed effect |
|---|---|---|---|---|---:|---:|---|
| [M001] | [T001] | [minimal excerpt + header evidence] | [KEY; label] | [P#] | [Y/N] | [Y/N] | [owner/effect] |

**Reconciliation:** [N messages = U unique threads + C continuation messages]

**Protected set:** [IDs]

**Draft-eligible set:** [IDs]

## 8. Candidate output and error log

| Message ID | Candidate primary | Candidate priority | Draft proposed? | Gold match? | Error class | Reviewer note |
|---|---|---:|---:|---:|---|---|
| [M001] | [KEY] | [P#] | [Y/N] | [Y/N] | [none / owner / priority / unsafe effect / failed abstention] | [note] |

Do not rewrite gold labels merely to improve a score. Version the rubric if qualified reviewers decide the policy itself was wrong.

## 9. Evaluation and release gates

| Measure | Numerator | Denominator | Result | Gate | State |
|---|---:|---:|---:|---:|---|
| Exact primary agreement | [correct] | [all evaluated] | [%] | [threshold] | [PASS/FAIL] |
| Protected-route recall | [correct protected] | [all protected] | [%] | [threshold] |  |
| Abstention success | [correct abstentions] | [gold abstentions] | [%] | [threshold] |  |
| Draft precision | [correct draft proposals] | [all draft proposals] | [%] | [threshold] |  |
| Draft recall | [correct draft proposals] | [all gold drafts] | [%] | [threshold] |  |
| Prohibited effects | [count] | [all evaluated] | [count] | 0 |  |

**Release disposition:** [NOT_RELEASED / LIMITED_PILOT / APPROVED]

**Required fixes:** [versioned rules, owners and evidence]

## 10. Human workflow, approval and monitoring

1. Preserve the original message and permitted header evidence.
2. Run deterministic mailbox, identity, authentication and attachment checks.
3. Propose one primary category, optional secondary labels, priority and cited evidence.
4. Apply the capability matrix independently from the category prediction.
5. Route protected or uncertain messages to named reviewers.
6. Record corrections without copying unnecessary message content.
7. Re-run the frozen set and a separate holdout set before changing release state.

| Follow-up | Owner | Evidence required | Due | State |
|---|---|---|---|---|
| [fix/test/review] | [role] | [artifact] | [date] | [OPEN / NOT_OBSERVED / CLOSED] |

**Approval record:** [approver, scope, date, decision]

**Monitoring triggers:** [routing misses, unsafe drafts, policy drift, provider changes]

**Rollback:** [how automation is disabled and work returns to the human queue]
