Skip to main content
Framework

The Heirloom Shield

Seven domains of sovereignty, with the questions worth asking in each, and a scanner built on them for the moment you are holding one decision rather than reviewing a whole practice. Published in full so any organisation can use it without us — including organisations that would never hire a consultant.

Human Sovereignty

Which decisions stay with people?

The decisions in your operation that a machine may never make alone, and the named humans accountable for the ones it assists with.

The documented failure point in AI adoption is not tool quality — it is that nobody owns the outcome. When no person is accountable, errors become nobody's fault and quietly persist.

The questions

  • Have you written down which decisions in your work must always be made by a person?

    Strong practice: A short written list — hiring, discipline, eligibility, safety, anything affecting someone's money or standing — that staff have actually read.

  • Is there a named person accountable for each place AI is used in your operation?

    Strong practice: A specific human name against each use, not a department and not 'everyone'.

  • Can the people affected by an AI-assisted decision reach a human and get it reconsidered?

    Strong practice: A stated route to a person, and at least one instance where a decision was actually reversed.

  • Do the staff using these tools know concretely how they fail, not just how they help?

    Strong practice: Your team can name the failure modes they have personally seen, and check for them by habit.

Policies worth adopting

  • A one-page 'decisions that stay human' list, adopted and posted
  • Named accountability for every AI-assisted workflow
  • A written appeal route for anyone affected by an assisted decision

Where a framework stops

  • Employment, lending, housing, insurance or benefits decisions — these carry legal duties and need counsel
  • Anything touching safety, clinical judgement, or a regulated profession

Aligns with

  • NIST AI RMF — Govern and Manage functions (human oversight)

Data Sovereignty

Where does your information go, and who can get it back?

What information leaves your control, which third parties receive it, how long anyone keeps it, and whether you can get it out or have it deleted.

Information is easy to send and nearly impossible to recall. The moment sensitive material is pasted into a third-party tool, your options narrow permanently.

The questions

  • Do you know which AI vendors currently receive data from your organisation?

    Strong practice: A written list of tools in use — including the ones staff adopted without asking — and what each one receives.

  • Have you told staff, in writing, what must never be pasted into an AI tool?

    Strong practice: A specific list: client identifiers, health details, financial account numbers, immigration status, anything told to you in confidence.

  • Do you know whether your vendors train their models on your inputs?

    Strong practice: You have checked the actual terms for each tool, know which offer an opt-out, and have taken it.

  • Could you export everything you hold and delete a person's record if they asked today?

    Strong practice: A route that works and has been tested — not a theory about which button probably does it.

Policies worth adopting

  • A vendor register listing every tool, what it receives, and its training terms
  • A 'never paste this' list distributed to all staff and contractors
  • A written retention and deletion schedule
  • Data-processing agreements with any vendor touching client information

Where a framework stops

  • Health, education, financial or immigration records — sector regulation applies and counsel is required
  • Any cross-border data transfer
  • Breach response planning

Aligns with

  • CARE Principles for Indigenous Data Governance — Authority to control (Global Indigenous Data Alliance)
  • NIST AI RMF — Map and Measure functions

Cultural Sovereignty

Who holds authority over community knowledge?

Whether knowledge belonging to a community — stories, language, practice, imagery, ceremony — can be entered into systems that will reproduce it without permission.

Cultural material that enters a model does not come back out under your control. Consent given once, casually, cannot be withdrawn from a trained system.

The questions

  • Is there knowledge in your organisation that should never be entered into an external AI system?

    Strong practice: You can name it specifically — elders' recordings, sacred or restricted practice, language material, community histories — and it is written down.

  • When community knowledge is recorded, does the community decide how it may be used?

    Strong practice: Consent is specific, revocable, recorded, and given by the people with standing to give it — not implied by participation.

  • If you use AI to generate cultural imagery or language, is it reviewed by someone with standing?

    Strong practice: A named reviewer with genuine community standing signs off before anything is published.

  • Do you distinguish between knowledge that is public, restricted, and closed?

    Strong practice: Three named tiers with different handling rules, understood by everyone who touches the material.

Policies worth adopting

  • A cultural knowledge classification: public, restricted, closed
  • Specific, revocable, recorded consent for anything community-held
  • A named review step before publishing generated cultural material

Where a framework stops

  • Anything involving tribal data governance, which carries its own sovereign authority
  • Ceremonial, sacred or restricted knowledge — this needs community authority, not a consultant
  • Traditional knowledge with existing protocols attached

Aligns with

  • CARE Principles — Collective benefit and Authority to control (Global Indigenous Data Alliance)

Economic Sovereignty

Who captures the value this creates?

Whether the efficiency you gain accrues to you, and whether you could leave a vendor without losing your operation.

A system you cannot leave is a system that will eventually set your price. Lock-in is a cost that arrives later, at the worst moment.

The questions

  • Do you know what you spend per month across all AI tools?

    Strong practice: One number you could say out loud, covering every subscription including the ones on personal cards.

  • If a vendor tripled its price tomorrow, could you move without losing your work?

    Strong practice: Your data exports in an open format and someone has actually tested the export.

  • Are the accounts and keys in your organisation's name?

    Strong practice: Everything is under organisational accounts, not a staff member's or contractor's personal login.

  • Has the time saved actually been redirected to something you chose?

    Strong practice: You can name what the recovered hours went to — and it was a decision, not absorption.

Policies worth adopting

  • A single register of AI spend, reviewed quarterly
  • Ownership of all accounts, keys and domains in the organisation's name
  • An export test performed at least annually on every critical tool

Where a framework stops

  • Vendor contracts with auto-renewal, IP assignment or data-ownership terms
  • Anything where a vendor claims rights over your outputs

Aligns with

  • NIST AI RMF — Govern function (accountability and risk management)

Creative Sovereignty

Who owns what gets made?

Rights, attribution, likeness and consent in anything produced with these systems — yours and other people's.

Copyright in generated material is genuinely unsettled, and likeness misuse is not. Both need decisions in advance rather than after publication.

The questions

  • Do your contracts say who owns work produced with AI assistance?

    Strong practice: An explicit clause covering both directions — what your contractors produce, and what you deliver to clients.

  • Do you disclose when published material was AI-assisted?

    Strong practice: A consistent, stated practice your audience could describe back to you.

  • Have you obtained consent for any real person's voice, face or likeness you reproduce?

    Strong practice: Written, specific, revocable consent — including for people who are no longer living, obtained from those with standing.

  • Do you know which of your published work has been scraped for training?

    Strong practice: You have checked, and you have taken whatever opt-out mechanisms exist for your platforms.

Policies worth adopting

  • AI ownership and assistance clauses in every contract, both directions
  • A published disclosure practice
  • Written likeness and voice consent, specific and revocable

Where a framework stops

  • Copyright and licensing questions — genuinely unsettled law, get counsel
  • Any commercial use of a real person's likeness or voice
  • Publishing agreements with AI training clauses buried in them

Community Sovereignty

Who is affected, and did they get a say?

Whether the people your work touches had any voice in how these systems are used on them.

Systems introduced without the affected community produce resistance later, and they usually deserve it.

The questions

  • Have the people served by your organisation been told where AI is used on their information?

    Strong practice: Plain-language disclosure at the point it matters, not paragraph 34 of a privacy policy.

  • Can someone decline AI-assisted handling and still receive your service?

    Strong practice: A real alternative path that does not punish the person who takes it.

  • Did anyone from the affected community help decide how these tools would be used?

    Strong practice: Named people from the community were in the decision, early, with the ability to say no.

  • Is there a route to raise a concern that reaches a decision-maker?

    Strong practice: A stated route, and evidence that something was actually changed because someone used it.

Policies worth adopting

  • Plain-language disclosure at the point of contact
  • A genuine opt-out path that does not degrade service
  • Community representation in the decision, not the announcement

Where a framework stops

  • Anything affecting benefits, eligibility, housing or legal status
  • Work with minors or with people under guardianship

Aligns with

  • CARE Principles — Collective benefit and Responsibility (Global Indigenous Data Alliance)

Ecological Sovereignty

What does this cost the ground it stands on?

The material footprint of the computation you commission, and whether the scale of use matches the scale of the problem.

These systems run on real electricity, real water and real hardware, in real places — often places that look like the ones our communities already live downwind of.

The questions

  • Do you know roughly how much AI computation your organisation commissions?

    Strong practice: A rough but honest sense of volume, and awareness that heavy generation costs more than light text work.

  • Do you reach for the smallest tool that solves the problem?

    Strong practice: A habit of asking whether a template, a checklist or a phone call would do it.

  • Have you considered where your vendors' data centres are sited?

    Strong practice: You have looked, and you know it is a real question with environmental-justice weight.

  • Does your organisation's environmental commitment mention digital operations at all?

    Strong practice: Computation appears in the same policy as travel and paper, rather than being invisible.

Policies worth adopting

  • Prefer the smallest sufficient tool as a stated default
  • Include digital operations in any environmental commitment
  • Ask vendors about siting and energy sourcing before committing

Where a framework stops

  • Public environmental claims — greenwashing carries regulatory exposure
The scanner

Green, amber, red — and how it decides

The assessment above reviews a practice. The scanner answers one question at the moment somebody is asking it: should this particular information go into this particular AI. It is a rules engine, published here so it can be argued with.

Green

Generally appropriate

Ordinary use, with ordinary care. The risk here is being confidently told something false, not disclosure — so the advice is to verify, not to withhold.

Amber

Proceed with care

It may well be fine, but the details decide: what you remove first, whose permission you need, which account it goes through, and who reviews the output before it reaches anyone.

Red

Protect this information

Not through an ordinary public or consumer service. That is not the same as saying it can never be done — it means the path runs through a specialised, local, enterprise or community-governed system, and getting there is a professional review rather than a settings change.

What it weighs

Five factors, not a lookup table. A category alone is too blunt: a general health question and somebody’s medical record are not the same thing, and treating them alike would make the whole framework easy to dismiss.

  • The material

    What is actually involved, at the level of detail that distinguishes a question from a record.

  • The task

    Helping a person decide is a different act from deciding about a person. The second needs governance, not a setting.

  • Whose it is

    Ownership and authority are not the same. Possession of knowledge does not confer the right to digitise it.

  • Whether you may

    Permission, and from whom — which for collectively held knowledge is rarely one individual.

  • Where it would go

    A public chatbot, a contract-backed enterprise system, a machine you own. This adjusts the answer; it never launders it.

Two rules that decide most results

The most sensitive thing wins. A harmless-sounding task never downgrades sensitive material — “just summarising” a medical record is still a medical record.

Unknown is not green. Where the scanner does not have enough to rate something responsibly it asks a question instead of guessing.

What it cannot determine

  • Whether you are compliant with any particular law. It is not a legal, medical, cybersecurity or regulatory opinion, and no result is a clearance.
  • The governance protocols of any specific community or nation. Where knowledge is collectively held it says so and stops — the authority sits with that community, not with a framework written elsewhere.
  • What a provider’s terms say today. Policies change, and a result is only as current as the answers you gave it.
  • Anything about material it has not seen — which is all of it. The scanner takes categories, never documents.

Framework version

Every result is stamped with the version that produced it, and the history is published. A framework that revises itself silently is asking for the same faith it tells people not to extend to anything else.

v1.0 · 2026-08-20 · current
First public framework. Multi-factor classification across material, task, ownership, authority and environment, with highest-risk-wins escalation and an explicit unknown state.