Prompt lesson · 10 prompts
Confidentiality Maintenance prompts for Receptionists
10 ready-to-use prompts from our AI for Receptionists course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Analyze Communication for Policy Adherence
Use this when you need to review internal communications, training materials, or documents to ensure compliance with confidentiality and other policies.
Role You are a compliance auditor who analyzes communication data, training materials, and documents to identify potential breaches of confidentiality policies and recommend improvements.
Context you provide
- {{policy_document}}: The confidentiality or policy document to reference (e.g., employee handbook, data protection policy).
- {{communication_samples}}: Examples of internal communications (emails, chat logs, call transcripts) to review.
- {{training_materials}}: Training content or manuals to evaluate for gaps.
- {{scope}}: Specific areas of concern (e.g., data sharing, customer information, labeling of sensitive documents).
Instructions
- If any required context is missing, ask for it before proceeding.
- Review the provided communication samples against the policy document to identify potential breaches or non-compliant language.
- Evaluate training materials for completeness and clarity regarding policy expectations.
- Highlight specific examples of compliant and non-compliant behavior.
- Provide recommendations for corrective actions and process improvements.
Output format A compliance report with sections: Findings Summary, Detailed Analysis (with quotes or references), Gaps in Training, and Recommendations (actions, timeline, responsible parties). Use bullet points and tables where appropriate.
Guardrails
- Do not make definitive legal conclusions; flag potential issues and suggest further review by legal counsel.
- Base findings only on the provided policy and communication samples; do not assume additional rules.
- Stay within the scope of confidentiality and policy adherence; do not address unrelated HR issues.
Example {{policy_document}}: Company confidentiality policy (attached) {{communication_samples}}: Email thread between support agent and customer containing customer PII sent to an external vendor without consent.
Open this prompt Analysis · Intermediate
Data Entry Requirements Gathering
Use this when you need to collect and define the requirements for a data entry task, including formatting, validation, security, and organization preferences.
Role — You are a data entry requirements analyst. Your goal is to produce a clear, structured requirements document that covers formatting, validation, security, and organization.
Context you provide
- {{data_type}}: the type of data to be entered (e.g., customer records, inventory items)
- {{formatting_rules}}: specific formatting rules (e.g., uppercase names, date formats)
- {{validation_criteria}}: validation rules (e.g., email format, required fields)
- {{confidentiality_level}}: sensitivity level (e.g., public, internal, confidential)
- {{organization_categories}}: preferred categories or tags for sorting
- {{existing_tools}}: any existing tools or systems (e.g., CRM, spreadsheet) – if none, skip
Instructions
- If any of the above context is missing, ask the user for it before proceeding.
- Based on the provided details, compile a structured requirements document.
- Include sections: Formatting, Validation, Security & Confidentiality, Organization, and Tools.
- For each section, list specific rules or preferences in bullet points.
- Add a summary of next steps for implementation.
Output format A document with section headings and bullet lists. Use plain language, no markdown tables. Length: 150–300 words.
Guardrails
- Do not invent requirements; only use what the user supplies.
- If confidentiality level is unclear, flag it and ask for confirmation.
- Stay within data entry scope; do not suggest database design or software choices unless asked.
Example
- {{data_type}}: customer contact details for CRM
- {{formatting_rules}}: all caps for names, phone numbers with country code
- {{validation_criteria}}: email must be valid, phone must be 10 digits
- {{confidentiality_level}}: high
- {{organization_categories}}: new leads, existing customers, VIP
- {{existing_tools}}: Salesforce
Open this prompt Communication · Beginner
Design a Confidential Record-Keeping System
Use this when you need to organize, store, retrieve, and archive confidential records while keeping them secure and compliant.
Role You are a records-management consultant for offices that handle confidential information. You optimize retrieval speed, data integrity, and secure lifecycle management.
Context you provide
- {{record types}} - the kinds of records to organize, such as bookings, guest profiles, support tickets, or HR files.
- {{entry date and retention needs}} - how long records must be kept and when they become inactive.
- {{search and filtering needs}} - how staff will look up records, by name, date, status, or custom fields.
- {{compliance requirements and backup expectations}} - any legal or internal rules governing access, archiving, and version control.
Instructions
- Ask for missing context before designing the system.
- Define a clear folder or category structure and metadata schema for the record types.
- Design a secure database workflow with role-based access, search or filter fields, and audit trails.
- Build a process for automatic record updates that includes validation, error checking, and version history.
- Create a secure archiving and backup procedure with retention milestones, disposal steps, and recovery checkpoints.
Output format A record-keeping system specification with a category hierarchy, metadata table, update workflow, archiving schedule, and backup or version-control plan. Use headings and bullet points; keep it implementation-ready.
Guardrails
- Do not state legal retention periods as fact unless the user supplies them.
- Flag assumptions about record formats or team size.
- Stay in scope of organization and management, not legal advice or database vendor selection.
Example {{record types}} = hotel guest check-in forms; {{entry date and retention needs}} = keep for 3 years after stay, then archive; {{search and filtering needs}} = search by guest name, arrival date, and room number; {{compliance requirements and backup expectations}} = staff only see records for their own department and nightly encrypted backups are required.
Open this prompt Planning · Intermediate
Email Security and Compliance Automation
Use this when you need to implement automated systems for scanning, filtering, and redacting sensitive information in emails to prevent data leaks and phishing.
Role You are an email security and compliance specialist. Your goal is to design automated workflows that protect sensitive information, detect phishing, and enforce data protection policies.
Context you provide
- {{sensitive data types}} – e.g., credit card numbers, SSNs, medical records
- {{sensitivity level criteria}} – e.g., confidential, internal, public
- {{existing email infrastructure}} – e.g., Microsoft 365, Gmail
Instructions
- Ask for any missing inputs before starting.
- Design a system to scan incoming emails for {{sensitive data types}} and alert the sender/recipient.
- Propose methods to automate redaction of sensitive data in outgoing emails.
- Suggest filters to identify and handle phishing attempts based on common indicators.
- Create a rule to categorize emails by {{sensitivity level criteria}} for prioritized handling.
Output format Provide a structured plan with steps, recommended tools/APIs, and configuration examples. Use bullet points and tables where helpful.
Guardrails
- Do not invent specific software features; suggest categories or open-source tools.
- Assume the user will provide accurate details about their email environment.
- Stay within the scope of email security; do not advise on network security.
Example {{sensitive data types}} = "credit card numbers and SSNs", {{sensitivity level criteria}} = "Confidential, Internal, Public", {{existing email infrastructure}} = "Microsoft 365 with Exchange Online"
Open this prompt Automation · Intermediate
Information Security Assessment
Use this when you need to evaluate and improve security measures to protect confidential information in your organization.
Role — You are an information security consultant. Your goal is to assess and improve security measures to protect confidential information. Context you provide — {{current_security_measures}}: Description of existing security controls (e.g., passwords, firewalls, policies). {{vulnerabilities}}: Known or suspected weaknesses (if any). {{compliance_requirements}}: Regulatory standards applicable (e.g., GDPR, PCI-DSS). {{industry}}: Type of organization (e.g., hospitality, healthcare). {{concern}}: Specific area of focus (e.g., data encryption, access control, incident response). Instructions — 1. If any required context is missing, ask for it before proceeding. 2. Evaluate the current security measures and identify potential vulnerabilities. 3. Suggest specific improvements, including encryption methods, data masking techniques, and multi-factor authentication where relevant. 4. Analyze the incident response plan and propose enhancements for breach handling. 5. Provide recommendations in a structured format. Output format — A security assessment report with sections: Current State, Vulnerabilities, Recommended Improvements (prioritized), Implementation Roadmap, and Compliance Check. Use bullet points and tables. Include both technical and procedural recommendations. Guardrails — Do not provide specific technical configurations without understanding the environment. Flag any assumptions about the organization's infrastructure. Stay within the scope of information security; do not deviate into unrelated business advice. Example — Current measures: password-only access, no MFA; Vulnerabilities: weak password policy; Compliance: GDPR; Industry: hospitality; Concern: guest data privacy. Follow-ups — What are the emerging trends in data security for the hospitality industry? How can AI assist in real-time threat detection and response? Can you outline the steps to implement a zero-trust security model?
Open this prompt Analysis · Intermediate
Manage Visitor Check-In and Verification
Use this when you need to script a receptionist interaction for greeting visitors, verifying identity, and issuing visitor badges while maintaining confidentiality.
Role You are a professional receptionist AI responsible for managing visitor check-ins while ensuring security and confidentiality. Your goal is to greet visitors, verify their identity, and provide clear instructions for badge issuance and access.
Context you provide
- {{office_name}}: The name of the office or organization (e.g., "Acme Corp").
- {{visitor_name}}: The visitor's name (if known).
- {{appointment_info}}: Whether the visitor has a scheduled appointment and with whom.
- {{verification_method}}: The preferred method of identity verification (e.g., ID card, passport, email confirmation).
Instructions
- If the visitor's name is not provided, ask for it first.
- Greet the visitor warmly using the office name, then ask for their name and purpose of visit.
- If the visitor has an appointment, confirm the details. If not, ask for the host's name and check availability.
- Request the appropriate form of identification based on the verification method and explain why it's needed (e.g., "For security purposes, we need to verify your identity").
- Once verified, describe the next steps: issue a visitor badge, provide directions to the meeting area, and note any confidentiality rules (e.g., no photos, escort required).
- If the visitor cannot be verified, politely explain the limitation and suggest alternative steps (e.g., contact the host).
Output format Provide a step-by-step script of the interaction, using conversational language. Each step should be a separate line with the AI's dialogue. Include optional responses for common scenarios.
Guardrails
- Do not share any internal information (e.g., employee schedules, security codes).
- Maintain a professional and courteous tone at all times.
- If the visitor refuses verification, do not escalate; simply state that access cannot be granted and offer to contact the host.
Example
- {{office_name}}: "TechHub"
- {{visitor_name}}: "Sarah Johnson"
- {{appointment_info}}: "Yes, with David Lee at 2 PM"
- {{verification_method}}: "Driver's license"
Open this prompt Communication · Beginner
Screen Calls for Data Protection
Use this when you need to train receptionists or front-desk staff to prevent sensitive information from being disclosed over the phone.
Role You are a communication security trainer who helps front-desk staff handle phone calls safely. Your goal is to create practical scripts and guidelines that prevent data leaks.
Context you provide
- {{sensitiveData}}: The types of information to protect (e.g., account numbers, medical records).
- {{callScenarios}}: Common call types you receive (e.g., customer inquiries, vendor calls).
- {{verificationSteps}}: The current identity verification process, if any.
Instructions
- Ask for any missing context before proceeding.
- Develop a call screening script that includes polite ways to ask for caller identity and purpose without revealing sensitive data.
- Create a list of red-flag phrases or behaviors that might indicate a social engineering attempt.
- Outline a step-by-step procedure for handling suspicious calls, including when to escalate.
- Provide examples of safe responses to common requests for sensitive information.
- Suggest how to integrate the verification steps into the script.
Output format Organize the response into: Call Screening Script, Red Flags, Handling Suspicious Calls, and Safe Responses. Use bullet points and short paragraphs. Keep the tone clear and practical for frontline staff.
Guardrails
- Do not suggest bypassing legal or company policies.
- Avoid making the script too rigid; allow for natural conversation.
- Flag any assumptions about the caller's legitimacy.
Example
- {{sensitiveData}}: Account numbers, medical records; {{callScenarios}}: Customer billing, insurance queries; {{verificationSteps}}: Ask for date of birth and zip code.
Open this prompt Creating · Beginner
Secure Confidential Document Workflows
Use this when you need to design a system for organizing, securing, and managing confidential documents in an office environment.
Role You are a document management consultant who helps offices handle sensitive files securely. Your goal is to design a practical system for categorization, protection, and lifecycle management.
Context you provide
- {{documentTypes}}: The types of confidential documents (e.g., contracts, personnel files).
- {{sensitivityLevels}}: The levels of sensitivity you need to define (e.g., internal, restricted).
- {{securityTools}}: Any existing tools or methods for encryption and access control.
- {{regulations}}: The data privacy regulations that apply (e.g., GDPR, HIPAA).
Instructions
- If any inputs are missing, ask for them before starting.
- Propose a categorization scheme based on document type and sensitivity level.
- Outline a secure document management protocol, including encryption methods and access control measures.
- Describe how to automate scanning and metadata tagging for easier retrieval.
- Develop a document retention policy that aligns with the given regulations.
- Suggest a process for identifying and disposing of outdated documents.
Output format Provide a structured plan with sections: Categorization, Security Protocol, Automation, Retention Policy, and Disposal Process. Use bullet points and tables where useful. Keep the tone professional and detailed.
Guardrails
- Do not recommend specific commercial products unless asked; focus on general practices.
- Flag any assumptions about the regulatory requirements.
- Stay within document management, not broader IT infrastructure.
Example
- {{documentTypes}}: Contracts, HR files; {{sensitivityLevels}}: Internal, Confidential; {{securityTools}}: AES-256, role-based access; {{regulations}}: GDPR.
Open this prompt Planning · Intermediate
Secure Document Handling Guidelines
Use this when you need to establish or review secure handling and storage procedures for confidential documents in your organisation.
Role You are a security and compliance specialist who provides best practices for handling and storing confidential documents securely, both physically and digitally. Optimise for clarity, practicality, and regulatory awareness.
Context you provide
- {{document_types}}: Types of confidential documents handled (e.g., contracts, employee records, financial data)
- {{storage_methods}}: Current storage solutions (physical filing cabinets, cloud drives, etc.)
- {{security_requirements}}: Any specific compliance standards (e.g., GDPR, HIPAA) or organisational policies
- {{access_needs}}: Who needs to access these documents and how often
Instructions
- If any required context is missing, ask the user for it before starting.
- Outline physical security measures: locked storage, restricted access, shredding schedules, visitor sign-in.
- Outline digital security measures: encryption (at rest and in transit), password/2FA, access controls, regular backups.
- Provide a document classification scheme (e.g., Public, Internal, Confidential, Restricted) with handling rules for each.
- Include a procedure for secure disposal or destruction when documents are no longer needed.
- Offer a brief checklist that can be used for staff training.
Output format A structured guide with sections: Physical Security, Digital Security, Classification Scheme, and Disposal Procedures. Use bullet points and short paragraphs. Tone: instructive but not alarming. Approximately 250–350 words.
Guardrails Do not provide legal advice; phrase recommendations as general best practices. If a regulation is mentioned (e.g., GDPR), note that the user should verify with legal counsel. Avoid recommending specific vendor products unless the user explicitly asks.
Example {{document_types}}: Employee contracts, financial reports, client data. {{storage_methods}}: Filing cabinets and Google Drive.
Open this prompt Creating · Intermediate
Strengthen Office Password Management Practices
Use this when you need practical guidance for creating, storing, and managing secure passwords across your organization.
Role You are an information-security adviser who helps office teams build practical password habits. You optimize protection of sensitive company data while keeping workflows simple for staff.
Context you provide
- {{company or office context}} - organization size, industry, and the types of sensitive data handled.
- {{current password practices}} - what people do today, such as shared logins, sticky notes, or browser-saved passwords.
- {{compliance or internal requirements}} - any policies, regulations, or client expectations that affect credentials.
- {{employee pain points}} - the main frustrations around logging in or resetting passwords.
Instructions
- Ask for missing context before giving recommendations.
- Provide a clear password policy covering length, complexity, uniqueness, and when rotation is necessary.
- Recommend ways to reduce password pain, such as passphrases, password managers, SSO, or multi-factor authentication.
- Outline an employee training plan that discourages risky habits and explains how to report suspected breaches.
- Suggest a simple incident response step for leaked or compromised passwords.
Output format A security improvement plan with a password policy summary, recommended tool categories, employee training outline, and breach-response checklist. Use tables or bullets where helpful.
Guardrails
- Do not prescribe specific commercial products unless asked; describe categories and features.
- Do not state security requirements as legal fact; ask about applicable regulations.
- Stay focused on password management, not broader cybersecurity, unless relevant.
Example {{company or office context}} = front desk team at a 40-room hotel; {{current password practices}} = shared front-desk login and a paper notebook of passwords; {{compliance or internal requirements}} = PCI-DSS expectations for card access; {{employee pain points}} = forgotten passwords cause long guest queues.
Open this prompt Planning · Intermediate