promptdojo_

The paper trail — legal review, versions, and adverse-action evidence — step 1 of 8

A policy is legal surface with a table of contents

The parental-leave section of your handbook is not "content." It binds the company in every jurisdiction you employ someone — and employment law is a patchwork that moves. Leave accrual differs by state. Monitoring notices differ by state. Pay-transparency rules differ by city. A model will draft you a beautiful, confident leave policy in ninety seconds, correct for a company that exists in no particular place, which is to say wrong for yours in ways only someone who knows your jurisdictions will catch.

That's why AI is genuinely useful here and why the workflow needs a boundary with no gaps in it. The studio pattern:

  • AI drafts — from the current handbook section and your context pack, never from vibes. Drafting is where the leverage is: the model turns "we need to update the remote-equipment policy for the two new states" into a reviewable document fast.
  • The draft marks its own risk. A good policy draft lists its jurisdiction-sensitive sections — leave, pay, monitoring, anything that varies by state — so the reviewer checks a list instead of rebuilding one from scratch. Make the model do this in the same pass; it's the cheapest review-acceleration you'll ever buy.
  • A named reviewer with legal competence approves. A name, not a role. "Someone senior looked at it" is not a review record. Counsel, or whoever your company designates — the point is that "who approved this" has a one-name answer.
  • Approved boilerplate is pasted, never regenerated. At-will language, EEO statements, arbitration clauses — legal approved specific words. A model that "improves" them un-approves them silently.
  • Every version is dated, owned, and summarized — because "which version was in force when" is a question you will be asked, usually by someone with a docket number, and the answer needs to be a lookup, not an archaeology project.

The timing matters more than it used to. Federal AI-in-employment enforcement pulled back in 2025 — guidance withdrawn, disparate-impact theories deprioritized — while states legislated and private plaintiffs organized. When the compliance weather changes that fast, the team whose policy history reads like a changelog is fine either way. The team with a folder of near-duplicate Word docs named final_v2_REAL is betting the company's defense on somebody's memory of a Tuesday.

This lesson builds the boundary as code you can't talk your way around: a state machine where draft → published is not a legal move, a version log that answers the in-force question in one loop, and then — the deep end — the adverse-action evidence trail, where the same discipline gets applied to individual decisions about individual people. That's step six, and it's the part of this chapter most likely to matter in a room with lawyers in it.