What not to do

The strict rules that keep AI from leaking your keys, wiping your data or emailing your customers.

3 min read

Ask the questionCan it be done with AI? Usually. Should it be done without you checking? Never.

AI makes the easy jobs easier. It also makes the big mistakes faster. Everything in this guide works better when these rules are in place, and the more complex the project gets, the more they matter. I learned most of them the hard way.

These rules are at the top of every cheat code on this site, so when you paste a page into Claude, the rules go with it.

The rules

  1. Never let it see your secrets. No passwords, API keys or env files (the settings files that hold your keys) pasted into a chat or opened by an AI tool, not even "just to check the names". Anything it reads can end up in a log, a commit or a screenshot. If a key ever lands in git, even for a minute, treat it as stolen and make a new one.
  2. Make it think before it acts. On anything bigger than a quick question, ask for the plan first: what it will change, in which files, and what could go wrong. Read the plan. Only then say go. Most expensive mistakes skip this step.
  3. One step at a time on big projects. Don't hand over a whole project in one message. Break it into steps, check each one works, then move on. The more complex the job, the smaller the steps.
  4. Never let it delete, send, pay or publish without you. Deleting data, emailing a customer, spending money, posting, pushing code live: you say yes to each one, every time. "Clean up the tests" is not permission to delete everything with "test" in the name.
  5. Back up before anything you can't undo. Copy the file, export the spreadsheet, snapshot the database. Then let it work on the copy first.
  6. Never test on real customers or live data. Test emails go to your own address. Test orders go through test mode. A test that emails real people is not a test.
  7. "Done" means you checked it yourself. Green ticks and "it should work now" are not proof. Open the real page, on your phone too, and look. If it says it can't check something, believe it and check it yourself.
  8. Make it read before it answers. Tell it to look at the actual file, page or data before it answers. If it starts guessing, stop it and point it at the source.
  9. Don't run a swarm on the same work. Two AIs editing the same files at once will undo each other's work. One system, one job at a time.
  10. Keep customer details out of chats. Strip names, phone numbers and addresses before you paste in a customer list. Use made-up examples when you're only showing it the shape.
  11. Price first, then yes. Before it switches on anything that costs money, a paid feature, an ad budget, a subscription, ask what it costs and say yes yourself.
  12. Fix the notes, not just the answer. When it gets something wrong, add one line to your standards file so it never makes that mistake again. Otherwise you'll be correcting the same thing every week.

Prompt

Add the rules to my standards

Here are the rules I want you to follow every time you work with me. Turn them into a short standards list I can save in my project instructions, in plain English, one line each. Then tell me which ones you think I'm most likely to break, given what you know about how I work.

[paste the rules from this page]
Checklist0 of 5 done