AI Guardrails SOP: Write Down What Your AI May Never Say
This is a Small Business SOP — a free, do-this-today standard operating procedure pulled from a real operator on the Unscripted Small Business podcast. This one comes from James Ernst of Core Order, who spent eighteen years in marketing and PR before going full time into AI implementation.
It is the step almost every business skips, and the one he puts at the front of every single engagement. Run it this week.
The Play — One Line
Before AI touches anything customer-facing, capture your red lines in the discovery session, write them into an instruction file the system reads every time, and add a second agent whose only job is to check the output against them.
Why this matters
In James’s words: “You have to be very specific. Especially if you’re working in a healthcare space with HIPAA, any of these regulated industries, you have to make sure that it is absolutely accurate and not going off the rails or not hallucinating.”
And it is not only regulated industries. Every business has claims it cannot legally make, and a brand voice that nobody actually follows once people start talking. As James put it, companies write mission statements and brand guidelines — then discover nobody repeats them consistently out in the world. An unconstrained assistant will invent both, confidently, at scale.
The numbers behind the play
The case for doing this before you buy anything is arithmetic, not philosophy. These are the figures James cites in his own writing on why enterprise AI investments fail, alongside the concrete win he described on the show.
95%
of enterprise AI initiatives show no measurable return (MIT)
70%
of AI value sits in people and process, not the model (BCG)
4 hrs
a week per ten employees, the task worth automating
30 min
the same task, once the workflow is right
The 6 Steps
1
Run discovery on yourself
Before choosing any tool, write down what you sell, the claims you are allowed to make, and the ones you are not. Every Core Order engagement opens with what James calls “a really in-depth discovery session” — do the same one on your own business first.
2
Write the red lines down
Regulatory limits and brand guidelines both. The test: if a sentence would need legal or leadership approval in a printed brochure, it needs a written rule here.
3
Define your domains
Core Order defines six domains for every client — the areas the system is permitted to operate in, which then feed everything deployed later. Anything outside them gets escalated to a human, not guessed at.
4
Put the rules in an instruction file
A CLAUDE.md or instruction .md the system reads on every single run — not a policy doc filed somewhere nobody opens. James: “through Claude MD files or instruction MD files, we’re really limiting where the hallucinations could go off.”
5
Add a checking agent
A second pass whose only job is verifying produced artifacts against the approved language — “creating agent systems to always go back and check in.” Never let the agent that wrote the thing be the one that approves it.
6
Lock the data path
Enterprise or business accounts so your inputs are not training the model, a locked-down database for anything financial, and locally hosted open-source models where data genuinely cannot leave the building. His rule: “err on the side of caution before just giving it open access to everything.”
Take the whole SOP with you
One printable page: the play, the six steps, and a fill-in checklist. No email required.