Case Study · Government · AI Governance and Capability
How a Queensland government regional office turned everyday AI use into agreed guardrails and eight documented agent builds, in a single day.
8/8
Completed both pre-work surveys, a 100% response rate
7/8
Already using AI at least weekly before the session
6/8
Asked for clearer guidance on where the lines sit
8
Agents created, one around each person's actual job
The engagement at a glance
The challenge
A regional economic development office inside a state government department. Ministerial briefings, funding assessments, regional profiles, stakeholder records and quarterly reporting into the department’s own operational plan. Every output either informs a government decision or becomes a public record.
The team was not resisting AI. They were already using it, most of them daily, on an approved platform, on department-issued devices. What they did not have was a shared understanding of where the lines sat.
That is a more useful starting point than reluctance. A team that has not started needs convincing. A team already in motion needs the guardrails written down, so the work holds up to scrutiny later.
What the pre-work found
One anonymous pulse and one named build brief ran before the day. Both came back complete, which is not typical, and which shaped everything that followed.
Seven of eight were using AI at least weekly and five of eight most days. Asked how clear they were on what they could and could not do, six of eight put themselves at the midpoint or below. Average confidence in using the tools was 3.0 out of 5. Average clarity on the rules was barely different.
So capability was not the gap. Shared guardrails were.
None of the eight reported using a personal account for work. The approved tools they described were accessed through their department login on a department device.
That matters, because it reframes the risk entirely. Nobody reported working around the system. Approved tools were in use ahead of an agreed local playbook, which is a governance question rather than a compliance one, and it is answered differently.
Asked what they used, all eight named the approved Microsoft platforms first and most consistently. Beyond those, the survey also picked up a light tail of general consumer tools.
In the same survey set, one respondent set out the platform position clearly and correctly. So the room already held the right answer, alongside evidence that it had not yet reached everyone in the same words. Nobody had put those two facts side by side before, which is the ordinary way this gap goes unnoticed rather than anything unusual about this team.
Asked where the sensitivity line sat, one respondent answered that when using an approved platform on a department-issued device, they were not aware of any limits on the information that could be used.
That is a reasonable-sounding position, and it is one of the most common misunderstandings any team carries into this work, because an approved tool feels like a blanket permission. It was answered in the guidebook with a dedicated page, written as a general principle rather than aimed at any individual.
Two blockers, tied
Asked what held them back, privacy and time came back level, four mentions each. One concern was specific and practical: where does Copilot actually store the documents it creates, and who else can see them?
Another was the best question of the whole engagement.
“If the tool already has access to my mailbox, why can I not paste the contents of an email into it?”
That question is the entire guardrails conversation in one sentence, asked by someone who had been using the tool for months.
What Tracy did
Participants supplied their real working documents: a quarterly reporting workbook, a procurement and project opportunity tracker, an ad hoc request register, a ministerial briefing note template, a stakeholder meeting record and the office’s own operational plan.
Nothing in the day was hypothetical. Every person built against the document they would open the next morning.
Reading the source documents together surfaced something that had never been set out in one place. One officer’s ad hoc request register feeds a specific numbered line in the office’s operational plan, which in turn feeds the quarterly report another officer compiles by hand from the team’s calendar entries.
A three-person reporting pipeline, already named in the office’s own planning document and until now carried by hand between desks. That became the anchor for the flagship build and for the unit level of the accountability map.
The day opened on guardrails, the first pillar of the GIST framework, before any agent was touched. The session aligned to the Queensland Government’s AI governance policy and to the organisation’s own four stated AI expectations, and worked to the Queensland privacy and public records regime that applies to a state agency.
Every person received a full build specification, from the most senior role in the office through to the most junior. Administrative inbox and register work was specified to the same depth as the ministerial workflow. In many rooms seniority decides who gets the attention. Here everyone left with a build of their own.
What changed
Why it worked
The pre-work did the heavy lifting.
A 100% response rate across two surveys meant the day was built on evidence rather than assumption.
Real documents, not demonstrations.
Every build used something the participant actually owns.
Guardrails before capability.
In a public sector context that order is not a preference, it is the only defensible sequence.
The right law.
Queensland privacy and public records obligations, matched to the jurisdiction the team works in.
Nobody was singled out.
Anything worth clarifying was handled as a general principle, which is the only way people keep listening.
The program, if you want it for your team
Common questions
The department reviewed the write-up internally and approved an anonymous version only. The organisation, its office and its participants are described in general terms, no response is attributed to any individual or role, and no content from any client document is reproduced. That was their condition and it is honoured here.
The opposite. Seven of the eight were already using AI at least weekly and five were using it most days, on approved platforms and department-issued devices. What was missing was a shared understanding of where the lines sat, which is a governance gap rather than a training one.
No. None of the eight reported using a personal account for work. Everything described ran through their department login on a department device. That reframes the risk: approved tools were in use ahead of an agreed local playbook, which is answered differently from people working around the system.
Eight agents, one per person, each built against a real working document rather than a demonstration. Plus a 111 page participant guidebook, four double-sided tear-out reference sheets, 16 swipe prompts, eight agent build specifications and a gated participant resource page.
Two pre-work surveys, both returned by all eight participants, and the office’s own working documents. Every prompt, worked example and agent specification came out of that material, so nobody built against a hypothetical.
It is designed for one. The day opened on guardrails before any agent was touched, aligned to the Queensland Government’s AI governance policy, the organisation’s own four stated AI expectations, and the Queensland privacy and public records regime that applies to a state agency.
Survey figures are drawn from the two pre-work instruments completed by all eight participants ahead of the session on 4 August 2026. The client organisation and its participants are described in general terms rather than named, no response is attributed to any role or individual, and no content from any client document is reproduced. Published with the department’s written approval.
Next step
If your team is using AI daily on approved platforms and nobody has written down where the lines sit, the gap is governance, not training. That is the work.