Automation & AI

Practical AI assistants for a co-op

Choose bounded tasks, restrict connected access and test whether an assistant saves useful time after human checking.

In this guide

An AI assistant can help a co-op find information, prepare drafts or organise routine work. The strongest starting point is a bounded task with clear source material and a person who can check the result. Connecting every inbox and document library at once makes it harder to understand both the benefit and the exposure.

Choose a task people already do and define what the assistant may read, what it may produce and what it may change. These are separate permissions. An assistant that drafts an answer from approved public guidance does not need permission to send email or edit membership records.

Choose a bounded use case

  • Public information assistant: find the relevant approved page and draft a response to a common question.
  • Document preparation: turn an agreed outline into a first draft for an editor to review.
  • Internal procedure search: retrieve instructions from a restricted, maintained collection appropriate to the user.
  • Task preparation: suggest a checklist from a confirmed decision, leaving assignment and publication to a person.

Avoid beginning with membership eligibility decisions, complaints, personnel judgements or unsupervised payment actions. These combine sensitive information, consequential decisions and difficult verification. A co-op can choose narrower uses while developing the capability to assess more complex ones.

For an illustrative community workshop, the first assistant might answer questions about opening hours and induction using three approved public pages. If it cannot find an answer, it should direct the question to a person instead of inventing workshop rules.

Control data and actions outside the prompt

Fix the underlying file permissions before connecting a search tool. A broad service account can make material available beyond the intended audience unless the system enforces the correct permissions. Ask the supplier to demonstrate an ordinary member's view and a restricted staff view.

The NCSC's prompt-injection guidance explains why malicious instructions in material read by an AI system remain a concern. Treat emails, webpages and uploaded documents as untrusted input. Limit the consequences through restricted tool permissions and controlled actions; a sentence telling the assistant to “be safe” is not an access-control system.

Start read-only. If you later add actions, require review of the specific recipient, content and change before sending, publishing or updating an external record. Keep approval close to the action, and ensure the system cannot quietly expand the scope after approval.

Test results against a small evaluation set

  1. Collect a dozen representative questions or tasks, using fictional or approved public information.
  2. Write down what a correct result must include and which source supports it.
  3. Include an unanswerable question and an out-of-scope request.
  4. Check citations by opening the actual source, not by trusting the generated link label.
  5. Test a document containing irrelevant instructions and confirm the assistant cannot perform unauthorised actions.
  6. Measure review time, corrections, useful completions and support effort.

An answer that sounds confident but cites an outdated joining policy is a failure even if its grammar is excellent. Record who maintains the source collection and how superseded documents are removed or marked. Repeat the relevant checks when sources, models or connected tools change.

Review the provider's current terms for retention, model training, access, subprocessors and deletion. The ICO AI resources explain the data-protection considerations when personal information is involved. Do not infer a provider's business-account protections from a consumer product description.

Give the pilot an owner and a stop rule

Set a trial budget, named operator, support route and review date. Count subscriptions, usage charges, preparation and checking time. Define when the assistant should be paused, such as unexpected disclosure, repeated unsupported answers or actions outside the agreed scope.

Adopt a practical AI use policy through the co-op's agreed decision process. Explain the purpose to the people affected and retain a human route for questions and decisions.

Discuss one bounded assistant through technology support when you can name the task, approved information and person responsible for checking it.

Suggest a correction or improvement →