Skill: The AI Notetaker Boundary Check — 5 Settings to Lock Before You Let a Bot Into Your Calls
AI notetakers are joining your Zoom and Meet calls automatically now. Before one records a client, a candidate, or a deal, run this 5-setting check so it does not store or train on conversations it should never keep.
What it is. A 5-setting check you run once on any AI meeting assistant (the bots that auto-join Zoom, Google Meet, and Teams to transcribe and summarize) before it sits in on a real conversation. It takes about 10 minutes and it closes the most common ways these tools quietly keep or reuse things they should not.
Why it matters. These bots are helpful and they spread fast: one person on the team connects one, and soon it is auto-joining every call, including client calls, candidate interviews, partner negotiations, and legal conversations. By default many of them record, store the transcript indefinitely, share it with everyone on the invite, and in some cases use your conversations to improve their models. A single unguarded setting can put a confidential deal or a customer's private information somewhere you cannot pull it back from. You do not need to ban the tool. You need to set five things.
When to use it. Before you let any AI notetaker into a call the first time, and again for every new tool a team member connects. Do it before the client call, not after.
How to run it. Open the notetaker's settings and confirm each of these five:
Auto-join is off by default. The bot should only join calls you deliberately add it to. Turn off any "automatically join all meetings on my calendar" option. Sensitive calls should never get a silent guest.
Training is off. Find the data or privacy setting and confirm your transcripts are not used to train or improve the vendor's models. If you cannot find a clear "do not use my data for training" control, treat that as a no and keep the bot out of confidential calls.
Retention is set, not forever. Set transcripts to auto-delete on a schedule that matches your business (for example 30 or 90 days). Indefinite storage is a growing pile of liability you will never review.
Sharing is locked to you. Change the default so summaries and recordings go to you or the host, not automatically to everyone on the invite. Outside guests should never receive the full internal transcript by default.
Consent and a visible notice are on. Enable the setting that announces the bot is recording, and make it your rule to get a quick verbal or written okay on external calls. In several places one-sided recording is a legal problem, and either way it is a trust problem.
The one-line policy to hand your team: the notetaker joins only calls we choose, keeps nothing forever, trains on nothing, shares only with the host, and always announces itself. If a tool cannot do all five, it does not join client calls. Keep anything truly sensitive in a private workspace and off the bot entirely.
What it is worth. Ten minutes now versus a leaked negotiation, a candidate's private details in the wrong inbox, or a client conversation sitting on a vendor's servers you forgot existed.