Answer first
Treat AI as a blank-form preparation assistant, not a support technician.
Computer User Support Specialists commonly assist users, address technical questions, maintain records, refer major problems, and train users. Those responsibilities require real context and authorized judgment. This manual limits AI to organizing supplied labels, preserving what is unknown, and drafting questions for the humans who may verify, diagnose, decide, communicate, or act.
Educational workflow design only. Organization policy, contracts, sector rules, security requirements, accessibility obligations, and professional judgment control. Nothing here authorizes access or action.
Mission outcome
Leave with one useful packet
Source register
Keep source label, owner, time/version, purpose, and access state attached to every supplied item.
Unknowns ledger
Mark missing authority, identity-verification status, policy, source version, and next owner. Never fill gaps by guesswork.
Review receipt
Create a local needs_review result that names questions and stops before any support action.
Field map
The five-step safe route
Set the boundary
Write a fictional or approved scope label, the stated purpose, and an explicit “no access/no action” rule.
Output: scope + purpose label
Register supplied context
Record only labels: source, owner, version/time, issue family, and allowed data state. Do not paste ticket text, credentials, screenshots, logs, names, or device details.
Output: source register
Expose uncertainty
Mark authorization, identity-verification, data classification, and required policy as known, unknown, or conflicting.
Output: unknown/conflict log
Map human authority
Name the owner who may verify identity, access a system, diagnose, decide urgency, change an account, communicate, or update a ticket.
Output: authority map
Ask neutral questions
Prepare questions for the authorized owner. The terminal state is always needs_review, never “resolved.”
Output: review handoff
Safety check
The hard boundary is the product
Safe to prepare locally
AI may organize labels and questions.
- Format an approved or fictional scope label.
- Preserve source, owner, version/time, and stated purpose.
- Mark supplied facts as known, unknown, or conflicting.
- Draft neutral questions for named reviewers.
- Create a local, non-networked
needs_reviewreceipt.
Approval + authorized human action required
AI may not become the support operator.
- Access a device, account, ticket, log, screen, system, network, file, or identity data.
- Diagnose, validate, classify, prioritize, or determine severity/impact.
- Reset credentials, change configuration, remote in, install software, or update records.
- Send, publish, notify, open/update/close a ticket, or contact anyone.
- Purchase, procure, accept terms, deploy, or take any external action.
needs_review. “Likely” is not evidence and an incomplete label is not permission.Roles
A narrow job card for each actor
| Actor | May prepare | Must not decide or do |
|---|---|---|
| Local preparation agent | Organize supplied labels, flag missing fields, and draft neutral questions. | Access, infer, diagnose, ticket, message, reset, change, or retain private material. |
| Intake/service owner | Verify channel, authorization, and minimum-necessary context under local policy. | Delegate identity/access decisions outside their authority. |
| Identity / endpoint / security / privacy / records owners | Review within their own authorized scope. | Assume a local worksheet is evidence, approval, or a system record. |
| Action owner | Approve any downstream change or communication using approved systems. | Treat this guide as authorization for a new payload, recipient, account, or action. |
Failure modes
Four mistakes that turn prep into unsafe support
Runnable artifact
Build a fictional review receipt
Use labels only. This form runs entirely in the page and makes no network request or storage write. It always returns needs_review.
Primary sources
Evidence, not borrowed authority
- O*NET OnLine — Computer User Support Specialists (15-1232.00) (role context; Updated 2026).
- NIST AI 600-1 — Generative AI Profile (risk-aware AI framing; updated 2026-04-08).
- NIST AI RMF 1.0 (voluntary, context-specific governance framework).
- NIST SP 800-53 Rev. 5 Update 1 (access/control context).
- CISA Secure by Design (security-design context).
All source URLs were public and returned HTTP 200 on 2026-08-06. This page is original StackPilot workflow synthesis, not a mandated government procedure.