Paul Ducey
StartThree bucketsCannabisFour questionsStrip the whoTeam rulelead time 00:00

Lean toolkit · AI in Lean · data safety · free

Strip the who. Keep the what.

Almost everything a Lean practitioner wants an assistant to help with works without knowing who anyone is. It needs the steps, the times, the counts and the problem. It doesn't need names, customers, formulas or passwords. This is the rule I use, and a one-page version your team can adopt.

The rule in one line

Paste what the work is, not who it belongs to

Sort anything you're about to paste into one of three buckets. If you can't tell, it's yellow until you've checked.

  • GGreen: paste freely. Process steps you wrote from watching the work. Counts, times and rates with no names attached. A blank template, or the text of a skill. Anything already public.
  • YYellow: strip first, then paste. Shift logs, with names swapped for roles. Downtime exports and order lists, with customers and brands swapped for codes. Photos with no faces, screens, badges, whiteboards, reflections or readable labels, and with location data removed. Supplier quotes and price sheets, with whatever you'd not want a competitor to read taken out. Anything you connect to the assistant: connectors, browser extensions, meeting recorders and share links, which can reach more than the chat in front of you, so get IT's sign-off first.
  • RRed: don't paste. Anything about a person: employees, patients or customers, including names, contact details, health information, ID numbers and purchase history. Passwords, keys and tokens. Formulas, recipes and anything under an NDA. Privileged legal documents. Anything your company or a contract says stays inside. Treat all of it as red unless your compliance lead has approved a tool for it.

If you work in cannabis

Treat these as red

Cannabis adds a few things to the red bucket. Unless your compliance lead tells you otherwise:

  • RPatient and customer records. That includes anything from a point of sale that ties a purchase to a person.
  • RSecurity details. Camera locations, vault and alarm specifics, security plans and access codes.
  • RBank details, cash-handling procedures, and unpublished license conditions or inspection findings.
  • RUnreleased formulas and extraction recipes.
  • REmployee records.

A package tag or batch number alone doesn't identify a person. Next to a customer, patient or employee identifier, a time or an address, it does: treat it as red. It can also be commercially sensitive: your sell-through by strain is something a competitor would like to see. I treat tracking exports as yellow. I'm not your lawyer, so if you're not sure whether something is regulated, ask before you paste.

Before every paste

Four questions

  • 1Could this identify a person? A name, a face, a badge number, a purchase history.
  • 2Would I be comfortable if a competitor read it? Prices, formulas, volumes, customers.
  • 3Am I allowed? Check your company's policy, your contracts and your license conditions.
  • 4Can I get the same help with the who taken out? Usually, yes.

If any answer makes you pause, strip it or don't paste it.

How to do it

Strip the who

  • 1Swap names for roles or random codes, not initials. "Trimmer A," "Packaging lead." The assistant needs to know there are two people, not who they are. A role with one person in it still points to them.
  • 2Swap customers and brands for codes. "Customer 1," "Brand B." Keep the key that says which is which in your own file, never in the chat.
  • 3Delete the columns you don't need. If the analysis doesn't use a column, don't paste it.
  • 4Start with a handful of rows. Check what you pasted before you paste the full export.
  • 5Put the names back yourself. Read what the assistant gives you, and add the real names and numbers back on your own side.

The account matters too

For anything work-related, use an account your company has approved, not a personal one. Read what your plan does with your data: how long chats are kept, who can see them (including your own admins), and whether they train models. It changes by plan. Approved is not private: on a company account, your own administrators can often see your chats. On a personal plan, including a free one, turn off the setting that lets chats train the model if your plan has one, and paste only green. If you can't find the answer, ask your IT or compliance lead before you paste anything yellow.

Plans and settings change, so read the vendor's own page for the plan you use: Claude, ChatGPT, Gemini, Copilot. Checked October 1, 2026.

Safe is half of it

The other half is not believing it. Every number an assistant gives you should say where it came from, and anything it can't know should be marked for someone to go and see. That's what the skills in the toolkit are built to do, and it's the idea behind my talk, Gemba Before Algorithms.

Free · one page · print it

The one-page team rule

The three buckets and the four questions on one printed page, with blanks for your site: which tools are approved, who to ask, and who reviewed it. Fill it in, put it where people open the assistant, and make it the team's rule instead of mine.

Get the team rule

Leave your email and the page opens right here.