Green, Yellow, Red: A Data Classification Framework for AI

Green, yellow, and red data classification gives an AI team one clear rule for every file: what is shareable, what stays internal, and what never moves off. Published July 20, 2026.

A data classification framework for AI sorts every piece of information into three tiers before it touches an AI tool: green is non-sensitive and shareable, yellow is internal and handled with care, red is confidential client and personal data that is referenced but never moved without a documented decision. The tag on each item then drives every downstream rule about where it can go and who can act on it.

Most AI risk does not come from the model. It comes from a person pasting the wrong file into a chat window because no one ever told them which files are safe to paste. A data classification framework fixes that at the source. Before any information enters an AI tool, it gets a label, and the label decides what happens next.

This page explains the green, yellow, red system that anchors an AI Operating System. It is the base layer of governance, the control that every other control depends on. Get the labels right and the connector rules, the access rules, and the review rules all follow from them. Get the labels wrong and nothing downstream can compensate.

What is a data classification framework for AI?

A data classification framework for AI is a fixed set of tiers that every piece of information gets sorted into before it touches an AI tool, and each tier carries its own handling rules. We use three tiers: green, yellow, and red. The point is not to describe data for its own sake. The point is to make one decision, once, per item, so that every later decision about that item is already made.

Without this layer, safety depends on individual judgment in the moment. A team member looks at a spreadsheet, guesses whether it is fine to paste into a chat, and moves on. Multiply that guess across a whole team and a whole year, and the odds of a bad paste approach certainty. Classification replaces the guess with a rule. The rule is plain, repeatable, and the same for everyone, which is exactly what governance is supposed to be.

What do green, yellow, and red actually mean?

Green is non-sensitive and shareable, yellow is internal and handled with care, and red is confidential client data and personal information. Those three definitions carry the whole model, so it is worth stating each one precisely.

Green data is anything that could be public without harm. Published blog posts, live ad copy, general market research, product descriptions, and reference material that already sits outside the building. Green data can be used freely across AI tools, pasted into chats, loaded into a workspace, and processed by an agent. There is no restriction because there is nothing to protect.

Yellow data is internal information that is not public and not confidential in the legal sense. Draft strategy, internal process notes, planning documents, performance summaries that name no outside party. Yellow data is handled with care, which means it stays inside controlled workspaces with known access, and it is not pasted into personal or unmanaged tools. It can support AI work, but only inside the governed environment.

Red data is confidential client information and personal data. Contracts, personally identifying information, anything covered by a client agreement or a privacy regulation. Red data is referenced but never moved without a deliberate, documented decision. That single sentence is the most important rule in the framework, and it earns its own section below.

Why does labeling every piece of data drive every downstream rule?

Because the label is the input that every other governance decision reads. Once an item is green, yellow, or red, the questions that used to require judgment now have automatic answers. Can this go through that connector? Can an agent act on it? Who can open the folder it lives in? Each answer keys off the tag.

This is what makes classification the base layer rather than one control among many. A connector review decides which integrations may touch which tiers. Access rules decide who can reach yellow and red folders. Human review rules decide when a person must sign off before output ships. None of those rules can function until the data underneath them is tagged, because each rule is written in terms of tiers. Skip the tagging and every downstream control is guessing about what it is protecting.

The practical effect is that you tag once and enforce everywhere. A file marked red carries that mark into every workflow it enters. The rule travels with the data instead of living in someone's memory.

Why is red data referenced but never moved without a documented decision?

Red data is referenced but never moved because moving it is the action that creates real exposure, and exposure that large deserves a deliberate choice on the record. Referencing red data means an AI process can be pointed at where it lives and can use validated conclusions drawn from it. Moving red data means copying it into a chat, a workspace, a connector, or an agent's working set, where it now sits in a second location under a second set of controls.

The distinction matters because most AI data incidents are movement incidents. The data was fine where it started. It became a problem when it was copied somewhere with weaker controls, or somewhere the logs could not see. By treating movement as the bright line, the framework puts its strictest control exactly where the risk concentrates.

Never without a documented decision does not mean never. It means the default is no, and overriding the default requires a named person to record what is moving, why, where it is going, and what protects it there. That record is cheap to produce and worth a great deal later, because it converts a silent risky habit into a visible, reviewable event. For regulated data this pairs with human-in-the-loop validation, where a review prompt surfaces the content for a required human sign-off. The prompt speeds the review up. It never replaces the human.

How do you run the classification in practice?

You run it by tagging at the folder level first, then handling the exceptions, rather than trying to label every file by hand on day one. A folder template gives each tier a home. Green lives in shareable spaces, yellow in controlled internal spaces, red in restricted spaces that AI tools reference but do not copy from. New work lands in the right place because the place already exists.

Start with the folder map. Define where green, yellow, and red each live, and set access on those locations to match. Once the structure holds, most items are classified the moment they are saved, because location implies tier. Then you deal with the edge cases: a document that mixes tiers gets split or treated at its highest tier, and a reclassification happens through a small, recorded step rather than a quiet drag between folders.

This is deliberately low effort per item. A framework that demands a careful decision on every file will be abandoned inside a week. A framework that makes the safe path the default path, where saving to the right folder is the whole action, survives contact with a busy team. The trained internal champions who own the system after handoff keep the folder map honest and settle the rare disputes about where something belongs.

How does classification live inside the AI platform's native controls?

Classification lives inside the platform's own permissions rather than in a separate document that no tool enforces. The tiers map onto native controls: private versus organization visibility, single sign-on, provisioning, and role-based access. A red folder is not red because a policy says so. It is red because the access controls on it only admit the people who are allowed, and because the tools pointed at it are configured to reference rather than copy.

This is the difference between governance as a slogan and governance delivered as a working artifact. When the framework is wired into real permissions, the rule enforces itself. When it lives only in a PDF, it depends on everyone remembering the PDF. We build the classification into the controls that already gate access, so the tier and the enforcement are the same object. That segregation also keeps one account's data from reaching another, which matters enormously in any white-label arrangement.

The connector layer sits on top of the same tags. Before any integration is switched on, it is assessed against the tiers it will touch through a connector risk register, so a tool that should never see red is never wired to a red location. The classification tells the connector review what is at stake.

Where do platform limits change what the framework can promise?

Platform limits change what you can prove, so an honest framework is built around where data actually lives and what the logs can show, not around controls that only sound reassuring. Some deeper capabilities sit at higher plan tiers: centralized audit logs, compliance APIs, and regulated-industry readiness are not always present at every level. Some agentic activity may not appear in standard audit logs at all. Pretending otherwise would be the opposite of governance.

So the model is built around the platform as it actually is. Where audit logging is thin, the framework leans harder on the movement rule and on keeping red data in places whose access is provable. Activity can be streamed to a security monitoring system for visibility, which is useful, but streaming activity is not the same as audit logging, and we say so plainly. Visibility helps you watch. It does not by itself give you the tamper-evident record that a regulator expects.

Being honest about the ceiling is what makes the rest credible. A framework that claims perfect coverage on a plan that cannot deliver it is worse than no framework, because it invites people to move data they should not. We would rather tell you exactly where the proof ends, and design the handling rules so the highest-risk data stays on the side of the line you can actually stand behind.

Frequently Asked Questions

Frequently Asked Questions

What is the difference between yellow and red data?

Yellow data is internal and not public, such as draft strategy or process notes, but it is not covered by a client confidentiality agreement or a privacy regulation. Red data is confidential client information and personal data, the kind that carries legal and contractual obligations. Yellow stays inside governed workspaces and can support AI work directly. Red is referenced in place and only moved through a documented decision.

Who assigns the classification to each piece of data?

In practice the folder structure assigns most of it automatically, because each tier has a defined home and saving to that location sets the tier. People handle the exceptions, such as mixed documents or reclassifications. After handoff, the trained internal champions own the folder map and settle any disputes about where an item belongs. The goal is that classifying an item is usually the same action as saving it.

Does classification slow the team down?

No, when it is built correctly it is close to free per item, because the safe path is the default path. Saving work to the correct folder is the whole classification step for most files. The effort goes into setting up the folder template and access once, not into a decision on every document forever. A framework that taxed every file would be abandoned quickly, which is why this one pushes the work to setup.

Can an AI agent work with red data at all?

Yes, but by reference rather than by copying. An agent can be pointed at where red data lives and can act on validated conclusions without pulling the raw confidential data into its working set. Moving red data into an agent's context is the action that requires a documented decision. For regulated data, human-in-the-loop validation adds a required human review before any output ships.

Is green, yellow, red the same thing as a connector risk register?

No, they are separate layers that depend on each other. Classification tags the data, and the connector risk register assesses each integration before it is switched on and decides which tiers that integration may touch. The register cannot function without the tags, because it is written in terms of them. Classification is the foundation the register stands on.

What happens when a document contains more than one tier?

It is either split so each part sits in its correct tier, or it is treated at its highest tier as a whole. A file that mixes green marketing copy with red client data is handled as red until it is separated. Treating a mixed document at its highest tier is the safe default, because it never accidentally exposes the sensitive part. Splitting is preferred when the sensitive portion is small and easily isolated.

Does this framework make us compliant with regulations?

It is a strong foundation, but compliance depends on your specific obligations and your platform tier. The framework enforces where sensitive data lives, how it moves, and who can reach it, and it adds human review for regulated data. Some proof capabilities, such as centralized audit logs and compliance APIs, sit at higher plan tiers, and we are explicit about that. A real compliance posture is built around what the logs can actually prove, not around assurances the platform cannot back.

About the author. Jaron Mossman is the founder of 360ROI, a boutique digital marketing consultancy based in Castle Rock, Colorado. He spent two years managing multimillion-dollar advertising accounts at Google's Manhattan office for Fortune 500 travel and hospitality brands before founding 360ROI in 2013. He built the green, yellow, red classification into 360ROI's own AI Operating System so that client data is governed by where it lives, not by who happens to remember the policy.

Read more about Jaron's background →

Stop guessing which files are safe to put into AI.

If your team is using AI without a shared rule for what counts as green, yellow, or red, you are one careless paste away from a problem you cannot see. A short assessment shows you where your sensitive data actually sits today and what it would take to govern it properly.

Get a Free Marketing Audit →