Employees at growing companies ask HR the same handful of questions every week, and more of them are taking those questions somewhere else first. BambooHR’s Redesigning Work report finds that 39% of employees now ask AI about issues they would previously have brought to HR or operations, and 19% use AI as their default first call for workplace guidance. Pointing that habit at accurate, current policies sounds simple, but the projects meant to do it often stall before anyone touches the technology. Every corporate function holds sensitive information, and the usual playbook says each department has to agree on scope, governance, and ownership before work begins. At a startup, where nobody has spare weeks for alignment meetings, that sequence can stop a project before it starts.
Tackling one such challenge is Yu Shinjo, Senior HR Manager at dotData, an AI automation company whose technology helps analytics teams find the hidden drivers of business KPIs. With employees in three countries, the company kept its internal policies in four separate document stores. Shinjo helped lead a cross-functional team that consolidated them and launched a company-wide AI policy assistant in beta two and a half weeks after kickoff, while everyone involved kept their regular workload.
“Call it an AI project and everyone pictures prompts and settings. What you are actually answering is ‘who is allowed to know what,’ and AI does not resolve that question. It surfaces it,” says Shinjo. That question cuts across finance, accounting, HR, labor relations, and legal at once. His team found a way to answer it without waiting for every function to sign off first.
Skip the big direction
Seven people worked on the project, one from each corporate function, and none was assigned to it full-time. Rather than seeking company-wide agreement, the team cut the work into pieces small enough for each person to decide their own part. “The usual sequence is: agree on scope, agree on governance, agree on ownership, then start. Every one of those steps needs the same busy people in the same room, and the calendar is what kills you,” Shinjo says.
The team ordered the work by urgency, how often a document was actually used, and how many questions it generated. Policies that prompted weekly questions went first, and compliance documents that nobody reads went last. Putting a beta in front of employees early produced feedback that no planning session could. “Alignment meetings produce opinions about a system nobody has seen. A working beta produces corrections from people using it, far more specific, and they arrive without scheduling anything,” Shinjo notes.
The approach also changed how buy-in works. “Waiting for alignment means everyone says yes before anything exists. Moving in pieces means one person says yes to one small thing, and the next person can see what they’re agreeing to.”
Permissions are the real project
Shinjo estimates that roughly half the project’s time went to permissions. The rest split between merging four document stores into one and building a separate search entry point for each country, covering company-wide policies plus that country’s own. “Configuring the AI was hours, not days,” he says.
The AI search inherits each file’s existing view permissions, so employees who can’t open a document won’t see it in their results. That design brought every deferred access decision to the surface. “The moment search can reach every document, every unresolved ownership question appears at once,” Shinjo adds. Many companies reach that moment without ground rules in place. BambooHR’s research finds that 54% of organizations lack a clear, documented AI usage policy that’s consistently communicated across the business.
Next time, Shinjo says he’d settle the permission split before anything else. His team treated it as a design task partway through the project, even though everything else depended on it. “The folder structure and the per-country entry points were really consequences of that decision,” he says.
Exclude instead of redact
The original plan called for formatting every document by hand before the AI read them. Once Shinjo saw the volume across three countries, he dropped it. The AI now reads documents as they are, the team fixes what it fails to pick up, and each document’s owner updates it when they notice it needs updating.
Keeping sensitive data in check matters more because employees are already improvising. According to the report, 59% of workers use personal AI accounts for work tasks, and 71% of that group have entered client data, proprietary strategy, or other sensitive company information into tools their employer has no visibility into.
Sensitive material was handled at the level of the store rather than the individual document. Payroll and performance data stayed out entirely, and corporate-internal material sits behind restricted access. Each functional owner also reviewed their own area personally. “They are the only ones who know what is actually sensitive there,” Shinjo says. “When you’re moving fast, exclusion is more reliable than redaction.”
Start with one question
For HR teams of one or two people without IT support, Shinjo recommends starting even smaller. “Pick the one question you answer most often, and make that answer findable. Not the whole library,” he says. “For most small teams it’s leave, expenses, or a benefit detail, and you can probably name it without looking.”
From there, he suggests three steps: find every version of that document and decide which one is current, put the current version in a single place, and leave it as it is. There are almost always several versions in circulation, and Shinjo sees the gap between them as where the real risk sits. “Don’t clean it up. That last part is the one people skip, and it’s exactly what stops these projects before they start.”
Early usage at dotData points in the same direction, with questions so far clustering around internal rules and benefits. “What’s striking is that people ask about the everyday things, not the policies we spent the most time drafting,” Shinjo says.






