By Cody Saunders, LMSW · October 11, 2026
Make a decision people can follow
Governance means deciding who may use a tool, for which work, under which limits, and who answers when something changes. A useful decision is more than a yes or no. It records the evidence, owners, missing facts, and next review.
This free workshop helps a behavioral health team practice that process. Participants use the existing five-domain framework to review one fictional proposal. They leave with a draft decision record and a plan for handling changes. The workshop teaches a method; it does not approve an actual service or certify a team’s rules.
Audience, objectives, and preparation
Plan 90 minutes with clinical, privacy, security, operations, and leadership staff. Include someone who does the proposed work each day. Invite legal or other reviewers where the setting requires their role. A facilitator should know the host’s current approval and incident processes. They should be comfortable keeping unresolved questions open rather than forcing a decision.
By the end, participants should be able to describe a use clearly, identify evidence for each domain, assign an owner to missing facts, write a bounded decision, and explain how a change can trigger another review.
Bring the fictional proposal below, a copy of the Behavioral Health Responsible AI Framework, and the existing data-handling worksheet. Use paper or an approved shared workspace with no client information. Live AI use is not needed. Do not upload private vendor contracts or real care records for the exercise.
Timed workshop plan
0–10 minutes: Agree on the scope. Read the proposal. State what the group knows and what is missing. Explain that this is a fictional learning exercise, not an approval meeting for a real product.
10–20 minutes: Assign review roles. Give each group member a domain or role. The frontline role describes the task; the facilitator records facts and questions. The decision-maker listens to the review before selecting a state.
20–45 minutes: Review the five domains. Use Activity 1. Allow five minutes per domain. Ask for specific evidence rather than a general statement that a product is safe.
45–60 minutes: Write the decision record. Use Activity 2. Name missing facts, owners, conditions, and the next review. Do not turn a list of domains into an automatic approval score.
60–75 minutes: Respond to new information. Use Activity 3. Show how an approval can change when a feature or data practice changes.
75–85 minutes: Test the message to staff. Use Activity 4. Ask someone outside the review group to explain what is allowed and what to do when it fails.
85–90 minutes: Check learning and close. Each participant states one unresolved item and its owner. Name the host’s next step and the limit of what this workshop established.
The proposal: a fictional note-drafting trial
A fictional outpatient clinic wants to test an AI tool that drafts visit notes from clinician-entered text. The team hopes to reduce after-hours documentation. It proposes two trained clinicians and a four-week trial. No audio recording is included.
The vendor provides a written description of storage and deletion. The clinic has not confirmed every outside recipient or completed the agreement review. One made-up test note looked accurate. No broader testing has been done. Clinicians would review drafts, but backup coverage and protected review time are not settled. The vendor may update its model during the trial.
The clinic has a usual manual note process. A proposed trial lead will gather feedback, but the final approval role and review date have not been recorded. No real client data has been sent to the proposed tool.
These facts are intentionally incomplete. Learners should not fill gaps with assumptions. A vendor statement can be a starting point for review; it is not proof that every duty has been met.
Activity 1: Review the five domains
Use the same domains as the master framework. For each one, write a known fact, a missing fact, the evidence needed, and an owner. Explain why that evidence matters to this use.
Clinical Appropriateness: What exactly will the draft do? What will it never decide? Who can judge whether it preserves the clinician’s meaning and fits the care record?
Privacy & Security: What information enters the tool? Which services receive it? What agreements, access rules, storage, and deletion practices apply?
Reliability & Safety: How will the team test added facts, missed details, and failures across varied made-up cases? What happens if the tool is unavailable or the draft is unusable?
Human Oversight: Who checks the draft before it becomes a record? Do they have enough time, skill, authority, and source material? Who covers an absence?
Governance & Accountability: Who owns the use and the final decision? What changes require review? How will staff report an error? When does the trial end or return for review?
Answer and debrief: The proposal lacks enough evidence for a live-data trial. Privacy questions remain, one simple note is not broad reliability testing, and review coverage is unclear. The group should define the task’s limits, finish data and agreement review, plan varied tests, assign reviewers and backups, and record decision ownership. Exact legal duties depend on the setting and service; the exercise does not determine compliance.
HHS explains responsibilities for covered organizations and business associates handling protected health information in its cloud guidance. Required agreements are only part of the review. A team must also address applicable safeguards and permitted uses.
Activity 2: Choose and record a decision
Use the master framework’s four states: Hold, Pilot with limits, Approved with conditions, and Paused or ended. These are decision labels, not scores or certifications.
Ask the group to write a record using these headings: proposed use; known evidence; unresolved facts; decision and reason; allowed users, tasks, and data; required controls; owners and due dates; stop conditions; fallback; and next review.
Answer and debrief: For the original case, Hold is supported because important data, testing, and oversight details are missing. Record that no live-data use may start under this proposal. Assign owners to resolve the gaps. The team can continue approved testing with made-up data if its actual process permits it.
Do not choose Pilot with limits just because the trial is small. Limits need to be real and supported. Nor should a completed exercise be described as Approved with conditions for a real service. The group has reviewed a fictional case, not the service evidence.
A clear record might say: “Hold the proposed visit-note trial. Data recipients and agreement review are incomplete. Reliability tests, reviewer time, backup coverage, and the final approval role need to be recorded. The privacy lead, clinical lead, and workflow owner will return with those items. Staff will use the current manual note process.” Add real owner names and dates only in the host’s actual review, not this fictional example.
Activity 3: Conditions change
Now suppose the fictional team later resolves the gaps and approves a bounded trial through its process. During the trial, the vendor adds an audio feature and changes an outside recipient. A staff member wants to turn on recording before the next visit.
Ask: Does the original decision cover this? Which roles must review it? What message should staff receive now?
Answer and debrief: The original scope did not include audio or the new data recipient. Hold the new use and send the changes through review. Confirm whether the existing use can still meet its conditions. If it cannot, pause it and use the fallback. Clinical, privacy, security, and other required roles should review the affected parts. Patient explanation and consent need attention under the actual rules for the setting; the workshop does not determine those rules.
Record the change and response. A decision should remain traceable after a new feature appears. Do not assume a product update is harmless because the brand is unchanged.
Activity 4: Can staff follow the decision?
Give another group this vague message: “The tool is approved. Use good judgment and review the work.” Ask them to explain which tasks, data, and accounts are allowed and what to do when the reviewer is absent.
Then have the review group write a clearer message based on a fictional approved scope. Include a help contact and fallback. Keep it brief enough to use during a busy day.
Answer and debrief: The vague message omits the essential limits. A clearer message names the exact feature and account, allowed information, assigned reviewer, final approval step, stop conditions, and alternative process. The staff reader should be able to explain the next action without guessing. If they cannot, revise the message. This checks clarity, not legal sufficiency.
Monitoring and the next decision
Before a real trial begins, agree on what will be measured. Count drafting, review, correction, and filing time. Track important errors and whether the final record meets the same quality expectations as usual work. Listen to clinicians and patients where relevant. Do not claim better care from time savings alone.
At the review date, compare results with the planned scope. Record what remains uncertain. Decide whether to continue within limits, expand only after the needed review, hold, or pause. Include a way to end use and handle stored information through the approved process.
NIST’s AI Risk Management Framework offers voluntary guidance on roles and ongoing risk management. It is not law or product approval. This workshop uses those general principles alongside Cody’s existing framework; it does not create a new validated model.
Completion check and follow-up
Ask participants to explain the chosen state, one missing piece of evidence, its owner, and a change that would trigger review. Listen for specific facts rather than confidence in a vendor or an informal approval.
For follow-up, take the draft process to the host’s actual responsible team. Use the purchasing checklist to gather evidence and the data worksheet to map recipients. Keep decisions dated and owned. These learning activities are not a competence test, certification, or continuing education award.
Sources and scope
Sources checked October 11, 2026. The proposal, decisions, messages, and changes are fictional. No savings, care benefit, billing improvement, validation, or compliance guarantee is claimed.
NIST AI Risk Management Framework: voluntary guidance first released in January 2023; NIST notes that version 1.0 is being revised.
HHS guidance on HIPAA and cloud computing: responsibilities for covered organizations and business associates; no specific AI product is approved by this guidance.
Use the existing master framework and its companion governance article together. To discuss free training, visit Work With Me.