Start with the work you want to improve
Indigo Tree specializes in bespoke WordPress websites and manages more than 200 clients across retainers and care plans. Managing that volume requires well-defined processes, which also gives the team plenty of opportunities to improve how work gets done.
When Louise and her team began exploring AI more intentionally, they gathered their support team and lead project manager and started by looking at the work itself. Louise said they asked, “What are the bits of friction?” and looked for the tasks that were getting in the way of the team doing their best work.
One answer was client reporting. Each month, the team had to reconcile time logged in its project management system, calculate retainer balances, and prepare reports for clients. For more complex accounts, that could take one or two hours per report. After reorganizing the underlying process and introducing automation and AI, Indigo Tree brought that down to roughly five to ten minutes.
The time savings didn’t mean removing people from the process. An account manager or project manager still reviews each report, verifies the information, and makes any necessary changes before it reaches the client. Louise said she doesn’t think they’ll ever get to the point where those reports will go out without a human looking at them.
That combination of efficiency and oversight helped shape Indigo Tree’s AI policy, turning the lessons from individual AI projects into guidelines the entire team could follow.
Put the guardrails in place
Indigo Tree created its AI policy alongside its internal AI work so the team had guidelines in place as AI became part of client-facing processes.
The policy covers some of the questions every agency should be prepared to answer:
Indigo Tree maintains a list of approved AI tools and provides appropriate company accounts rather than leaving employees to use personal accounts. If someone wants to introduce another tool, Louise or the agency’s engineering director reviews its licensing and privacy practices first.
That also helps address shadow AI, where team members independently adopt tools without the agency knowing how information is being handled.
For client data, Louise uses a useful test: Would you want this information to show up in a search result?
Even when AI is used for something relatively routine, such as helping draft a difficult email, the agency expects identifying or sensitive client information to be removed before it reaches the AI tool.
Transparency is another part of the policy. Louise said that if she used AI to analyze client data, she would tell the client, “I’ve used AI to help me, and these are the results.” She added, “I would never go to the client and pass it off as my work if it wasn’t.”
The goal is to give the team room to use AI where it makes sense without leaving privacy, accountability, or disclosure to individual judgment.
Your clients may start asking about your AI policy
For Indigo Tree, the policy has already become relevant outside the agency. While completing a security questionnaire for a larger organization, Louise was asked specifically about Indigo Tree’s AI policy and whether data shared with AI tools could be used as training data.
Because Indigo Tree had already established its policy, the agency had answers. That experience shows how an internal AI policy can become relevant to client trust, security reviews, and even the process of winning new work.
That may be especially important for agencies working with larger organizations, regulated industries, nonprofits, and other clients with established security or procurement requirements. As AI becomes more common in agency workflows, clients may want to understand how their information is being handled before they agree to work with you. A documented policy gives your team a consistent way to answer those questions.
The same framework becomes even more important as AI moves into client websites. Indigo Tree is exploring connections between AI and WordPress, which raises new questions about permissions and security. If an AI system can interact directly with a website, the agency needs to decide what it should be allowed to read, create, change, or delete.
Those decisions become much easier when the underlying rules have already been established. They also show why an AI policy can’t be treated as a one-time exercise.
Treat your AI policy as a working document
An agency’s AI policy doesn’t need to anticipate every tool or use case your team will encounter. Indigo Tree’s policy establishes a framework for making those decisions, including approved tools, boundaries around data, human oversight, transparency, and a process for evaluating something new.
It’s also designed to evolve. Louise and her team plan to revisit the policy after six months, review how people were using AI, and tighten the guidelines where needed. She described the goal as making sure people are “using AI to help them get a solution, not to rely on it for a solution.”
That regular review gives the agency a chance to respond as the technology and its own workflows change. Specific tools may come and go, but the principles behind the policy can continue to guide how the team evaluates and uses them.
Give your team a framework now
If AI is already showing up in your agency’s work, you don’t need to have every future use case figured out before creating a policy. Start with the decisions your team is making today, document the boundaries around them, and make it clear who is responsible for evaluating new tools and uses as they emerge.
Then revisit those decisions as your team learns more. Indigo Tree’s experience shows that an AI policy can give people room to experiment while creating a shared framework for making good decisions. Your team may not know every way it will use AI next, but it should know the rules it’s expected to follow.