An "AI-assist" button drafts your DPDP response letter. It's structurally incapable of sending one
Every employee has DPDP rights over the monitoring data a company holds on them - to access it, correct it, have it erased, name a nominee, or raise a grievance. Answering those requests well takes time a small compliance team doesn't always have. So the admin queue has an AI-assist button. What it's allowed to do is deliberately narrow.
A data-principal request lands in an admin queue with a type, a subject line, and whatever details the employee gave. An admin can draft a response by hand, or click AI-assist to get a starting point. The button calls a specific endpoint that does one thing: return a draft string. It cannot change the request's status, cannot save a response, and cannot notify anyone - only the existing update action, called explicitly by a human, does any of that.
What actually gets sent to the model
Record counts, not raw content. Before drafting anything, the endpoint builds an inventory of what monitoring data exists for the requesting employee - counts only, across categories like application sessions, website visits, file transfer events, DLP policy events, USB device events, screenshots, risk signal events, and client-record access events. The model is told those counts, the request's own type and subject line, and is explicitly instructed not to claim data categories that aren't in the list and not to invent facts beyond what it was given.
That mirrors the same principle behind how our agent handles file content on the endpoint itself - counts and classifications travel, not the underlying material.
The draft is shaped by the request type
Describes what will be provided and how - not the data itself.
Describes the next procedural step, deliberately framed as a step and not a final decision the AI has made on the company's behalf.
Confirms the nominee will be recorded.
Ends with a placeholder for the compliance officer's name and the response deadline - a human has to fill that in before it means anything.
The safeguard is structural, not a warning label
The draft is returned to the admin's screen with an explicit disclaimer attached: AI-drafted, review and edit before sending, a suggestion rather than an approved response. But the more important protection isn't the wording - it's that the endpoint that generates a draft is a completely different code path from the one that saves a response and changes a request's status. Generating ten drafts changes nothing about any actual request; only a human calling the existing update action does.
Every draft generation is itself logged in the audit trail - so even though nothing was sent, the fact that a draft was requested for a given case is on the record.
What happens if AI drafting isn't available: if the underlying AI service is unreachable, or the specific drafting capability isn't enabled for a workspace yet, the admin gets a clean, immediate error telling them to respond manually below - not a blank draft, not a retry loop, and never a fabricated letter standing in for a real failure.
Related reading
- The DPDP 72-hour breach clock, explained
- The 20-point DPDP vendor checklist
- "We log file activity" isn't the same as "we have a client-data audit trail"
See the data-requests queue live
No credit card to start. Intrusive features stay off until your own DPIA is recorded.
Try for free