Episode Transcript
[00:00:00] Speaker A: If you ever wondered what's actually hiding in your shared drives, Trailblazer Insights scans your files locally for pii, hipaa, PCI, and other compliance risks. No cloud, no IT ticket, just answers. Search Trailblazer Insight in the Microsoft Store.
Good morning, good afternoon, good evening. Whenever you listen to this.
[00:00:24] Speaker B: Welcome back, Good evening and good night.
[00:00:27] Speaker A: Yeah, welcome back to what Counts. Every organization hides a story in their data. This is the podcast that digs into the governance problems people inherit, ignore, and discover too late. I'm Lee and as always, I'm here with my co host, Maura Dunn.
So, Maura, last episode we laid out three action principles. Stop making copies, which I said was almost impossible, but we'll work through that. Stop making copies. Focus on data creation and touch. Once used many times.
Simple to say and in your words, generally hard to do.
And we ended on a cliffhanger.
First time in ever in history.
Information governance podcast could end on a cliff. Hager, are you sure?
[00:01:18] Speaker B: Are you sure it's the first time? Because I feel like we are constantly running into unknowns in the world of information.
[00:01:24] Speaker A: We're constantly running into a time cutoff and that too. Yeah.
The value, you know, is it worth it? The value. How do you start are tool your own tools tripping you up today to today. More out.
Let's make the case. What should anybody do?
How should anybody do the hard thing?
Like stop making copies.
[00:01:52] Speaker B: Yeah. So stop making copies is deceptively simple like you're saying. But let's talk about why. Why is it worth it to do that as a starting point? Because you know what, it's easier to not think about information governance. And a lot of people go through their whole lives without thinking about it, but that leaves them at the mercy of other people who have thought about it.
So it's hard to prove that you paid your credit card bill if you are paying in cash at the register. It's hard to prove that if you lost the receipt and then your credit card comes back and says no, you didn't pay.
It's hard to prove that you paid a car payment or a mortgage payment. If your bank makes a mistake and you don't have any record of what happened.
So the worth it is to protect yourself. That's as an individual when it comes to the company.
If you own a company, you work in a company, you are responsible for that type of activity. In a company, it's the same thing. You need to prove your half of a transaction.
And it's great if you can also prove the other Half of the transaction, because then you've got the whole picture.
So the worth is, what's the cost if you can't prove something?
Right, that's the easiest one. What's the cost if you can't prove it? If you can't prove that you made a payment, then the cost is you're going to have to make the payment again. And you might have a late fee, but it could be worse. You can't prove that you wrote the report that was written in as a requirement in your contract. You can't prove that you sent that report on time.
Then you don't know what kind of consequences there are. There could be consequences to missing that date.
You miss the deadline, they say you missed the deadline, you didn't send us the report. And now as a consequence, we get to escalate your cost or we get to renegotiate our fee, or who knows?
We've seen a lot of variations on that kind of thing written into different kind of deals, different kind of contracts over the years.
Happened all the time in the kind of the development side, the project development side of the renewable energy world. Because it's a complicated process. It's a complicated and complex process with a lot of moving parts from finance to town government, local government, to utilities and landowners. A lot of different people involved.
Everybody made their stake in the agreement saying X needs to happen for me to do Y.
You miss any one of those and there's a cascade effect.
So being able to prove things is why you're creating records is one of the reasons that we create records.
The other side of it is that we're creating records so that we have the information that we need to do our jobs.
So we need to have information. If we're running a railroad, we need to have information about the model of each rail car in case we have to fix something. What if we have to replace a part? If we don't know the model number, we could like a metro system, I know in the past did order all the doors in the wrong size.
So you've ordered all new doors for a set of subway cars and they don't fit.
And they don't fit because you have the wrong model number. Well, that is a huge cost in terms of, hey, I bought all the wrong doors and I had to pay for them. And then I had to pay for the right doors. And also the subway cars had broken doors for a while while you were trying to fix that mistake. And I remember at the airport when we were doing the project at the airport. We had kind of a fight one day between the BIM people, the building Information management people, who were arguing for we need better data, we need better data, we need better data.
And the technicians who'd been there for 25 or more years.
And the argument went like this. And it turned out to be the most, I'm going to call it like, clarifying and illuminating discussion that we had during building that asset hierarchy. Do you remember it? You weren't there, but I've talked about it a lot.
Fire doors. It was about fire doors.
And the technicians were like, we don't need the documentation. We're just going to go and measure the door and measure the window and we're just going to fix it when it needs to be fixed.
And surprisingly, it was the commercial guy who said, no, that's not okay.
Because when the fire marshal comes in and does an inspection, it's not enough for the fire marshal to go look at the door and say, yeah, looks good. The fire marshal needs documentation that this door is of the appropriate fire rated material, and especially the glass in the window in the door is of the appropriate fire rated material.
And you have to have that documentation of how you know the right ratings, how you ordered the right materials, and how you checked that the materials that came in matched your specs and how you installed it correctly because you need to meet that fire rating. And that turned out. Everybody in the room was like, oh yeah, oh yeah, oh yeah. And that fire door example turned out to be the one that we took everywhere when we were socializing the asset hierarchy because people understood the implications.
So that's where it's worth it, right? It's worth it because you want your business to run the right way. You want to have the right information available and ready and easy to find to make your decisions.
So that's the why.
And now we get to the how. Okay, so the how again, it sounds easy.
Just capture all the information when it comes in the door and file it appropriately. And then everybody should go to that place, do their searches, or look at that file system and find the information that they need.
But anybody who's ever just tried to manage their own notes app on a phone, or their own folder system or desktop on a laptop, on your computer knows that that is not easy.
Because it goes like this. Your day gets really busy and 15 emails come in and three of them have contracts and 10 of them have purchase order or material receipts or something, and you got to get through it, and you just need to get through it. And you're like, I'm just going to put this. I for a while in my inbox had a folder that was called look at this later.
And that's me. I do this every day. And I really try hard to keep on top of my inbox. But there was a point where I was just like, I can't have this clutter anymore. And if these things were important, I guess somebody would have called me back about them.
So everybody gets to that point.
And the goal here is to try and set up processes and technology that keep that point at bay. They make it easier every day to put the information where it belongs, with or without you actively doing anything, preferably without you having to do anything, so that you know where to find it when you need it. And more importantly, somebody else knows where to find it when you need it.
[00:09:50] Speaker A: So set up an AI assistant is what you're saying.
[00:09:53] Speaker B: Well, maybe in the future. I'm not going that far yet, because the AI let's. We can talk about it for a second. The AI is only as good as the prompt, right?
[00:10:07] Speaker A: I agree.
[00:10:08] Speaker B: So I know I have talked about this before, too. How two different cataloging librarians will sit next to each other and look at the same document or same book and catalog it two different ways, even following all the rules in the AACR2, which is a massive book that's like 2,000 pages long, just full of rules about how to catalog books in a library.
It's not for the faint of heart.
And that the same thing will happen with the same cataloger in the morning and in the afternoon or on two different days, because the first six or eight choices that you make are very clear, but those last two or three are kind of subjective.
And the same thing happens in filing. And so we've taken in our approach to building retention schedules and file plans that match. We're starting with business process, and we do that because this is how people work with information to get something done.
We think this is the closest way, like the most intuitive way to keep the information in a. In a place where it's easy to find.
And I still think that's true.
But if you're relying on your whole company to just follow a manual process and file things, it's not going to work no matter how hard you try.
And I do want to get into email. I know we talked about it a little bit last week, and I want to spend more time on it. Even though this is going a little long, I think it's worth watching while. But let's just talk about process before we get into email.
So the third principle is touch once is the two. The second two principles after don't make copies are talk about data, think about data, capture the data capture point, and then touch once, use many. Those two go together really well.
And the way that we look at process, when we're doing a process map, we think about what is the easiest place to capture the information.
So when it comes in is a really easy place. Right. And you started this when you were talking years ago about mail rooms, like physical mail coming in, and how you would use that point to sort and capture useful information way back when you were in a law firm or whatever working for law firms.
So the, the electronic equivalent of a mailroom is email. It is the intake point, could be email, could be a portal in a system that's looking outward. So you have a contractor who's able to upload documents or upload information into a portal and the system captures it right away. And you have to program the system, you have to say when, when a W9 comes in from a vendor, you need to have the vendor ID number, which is an internal number that your company has assigned to this vendor. And then you automatically file that W9 with that vendor in the, in the system.
And you can notify whoever needs to know, hey, we got a new W9 from this group. Maybe somebody should check that because maybe they have a new tax ID or they're a new vendor. And we were waiting on their W9 and now they've made it one more step, but we still don't have their insurance certificates.
So let's have the system send them another notice that says, hey, where's your insurance certificate?
And then the vendor comes back to the portal and uploads the insurance certificate at some point and they get through all those steps and then the system is able to push the information through to the next level approver and say, hey, this vendor has answered all our questions and they met all of our requirements.
Are they active now so that they can become a vendor in our system and trigger the next step in. Okay, the contract is ready to be approved. It's been going on its parallel track and it's got all the language is worked out and now the vendor is approved so we can execute.
So that process, that process flow happens whether you capture the data or not.
But if you can build in the data capture, then you've saved yourself a lot of time because the system has captured the W9 and the certificates of insurance and maybe the the banking information to do the ACH payments or whatever else you've asked for up front. It's all in one place now and it's not in somebody's email, which is the critical thing. You're still probably using email to communicate with this vendor, but the substance is happening in the system. Even if an email gets sent out from the system, from you as the internal person, and then the vendor might be responding, but they're responding to the system and it gets uploaded.
A lot of companies are doing this for invoice processing.
How many, how many clients have we had where there's an email address called invoices@x company, but you.
But the system gets that email in
[00:15:39] Speaker A: your email because the system's going to read it.
[00:15:42] Speaker B: Right. And make sure. Right, exactly. Make sure you put these three pieces of information, the purchase order number, the date, the invoice number or something, and the system can pick those three things out and match them to other information that it already has.
It downloads the invoice and uploads it into the system and moves it through its process.
I think in the insurance industry the same thing happens with insurance claims and they have built in some other safeguards where, okay, you want to upload pictures of your car, of the dents and damage that happened in the accident, you have to use this link. It opens up a camera, you take your pictures right in real time. It uploads them into the system right then. Because you don't want to have, you don't want to let people just upload any old picture of a damaged car if it's not, if you can't prove that it was the actual car in question, having recently gone through that.
So that sort of very routine processing in the financial world is actually pretty sophisticated now.
So back to your. Can you have an AI do this?
Yeah. If you explain to the AI every one of those steps that's happening in this process, then sure, the AI can do some of that. But if you just say, hey, AI, I need to get a vendor set up, then no, the AI cannot do that on its own. It's got to understand what all these steps are and what all the requirements are, what the checkpoints are and those data capture points.
Because that data capture is the critical thing.
Because then when you come back in a year and somebody wants to give another contract to that vendor, you need to go look and see, do we have an NDA with that vendor? Do we have a W9? Do we have up to date contract certificates of insurance, or do we need to ask ones. And so the person who's looking to give them a new contract needs to have a reliable place to go find that information. And they do, because it was all captured up front in your initial process.
So that's why those two things go together.
And if you do those two things well, then you do stop making copies because you have a place to work where everything's in it.
But I think that breaks down, or at least it's harder when the process is sort of less standard, more creative, more in the hands of a person and less just following steps, particularly developing documents.
So this is where email starts to be at the same time. Both so easy and so awful.
[00:18:33] Speaker A: I think I'm just going to say share instead of attach.
[00:18:39] Speaker B: Share instead of attach is definitely a good start.
Share instead of attach. So add a link to your email instead of a copy to your email does require some other things though. It requires that either the two or three people that are on the email all have access to the location where that document is living, and that that location has sufficient collaboration tools for different people to go in and review and comment or edit, depending on what you've given them permission to do.
It also depends on it being smart enough to manage conflicting commenting, conflicting edits and wait for resolution, which they mostly are. So I've done quite a bit of work in the Google Suite for editing Google documents and a lot in the SharePoint world, Microsoft editing documents there.
And Google defaults to a commenting approach as opposed to a straight edit. And so it will save all the comments, at least every time I've used it. That's how it's worked.
Save all the comments from all different users and then whoever's the document owner is going to go through later and accept the change, the proposed change, or not accept the proposed change in SharePoint depending on if you say you're editing or you're commenting.
If you have track changes on or not track changes on, you can run into conflicts if two people are trying to change the exact same thing at the exact same time.
But it is possible to set up SharePoint as well so that it will capture the proposed changes and then an owner can come in later and do that, that resolution, which is helpful, but it's not perfect and it's sometimes not easy.
It's hard. You can't work on a. Can't necessarily work on an airplane that way because you can't be online reliably.
Not all features of the Microsoft Suite are available in the online version.
In some cases you're able to open in desktop. But again, that requires that everybody's logged into all the same places.
Otherwise you'll end up downloading something in order to work on it offline. And then you have to upload it as a new version.
And you can, you can work around all that. You can have process steps in place for how people can do that offline editing or offline commenting and how they resubmit a document. You can set up a check in, checkout process so that if I check something out, you're not able to edit it while I'm working on it offline. And then when I upload my new version, it notifies you that the new version is here.
So there are things you can do, but they require a few extra steps in the setup and they require a little more awareness and discipline in the activity. Because now it's not just you and your computer making changes, it's you and your collaborators and a different system all working together.
But the alternative is that you send an email.
Even if I only send an email to you and I attach something to it, I've got a copy in my OneDrive, I've attached a copy to the email, which means it's in my sent mail. So that's two. You've got a copy in your inbox, you download it and now it's on your OneDrive. So that's four and we haven't done anything. We, at that point, we have four exact copies of the same thing and then it's late on a Friday and I don't think you're going to look at it. So I'd make a change and I send you a new version. But you did look at it because you were bored. And so you've made changes on the version on your OneDrive, and now we've got six and they don't match, or eight and they don't match.
Now we've got a problem because that's only the two of us and it's not a whole team looking at things at the same time. And we haven't created exponentially the possible copies of things that are out there.
And it's, it's only a minor problem when we're actively working on a document and we need to get it done. And then we have an official version, it's a deliverable. We turn it in. It's a proposal. We turn it in, we're done with it. We have a place where we keep the finals and we do have them, but we probably have two. We probably Each have one.
So just being honest here, we know the right thing to do. We don't always do it because it's hard.
But when you get into a bigger company and that problem just keeps multiplying and then something goes wrong, how do you find the right version? Or you end up in an audit or a legal situation and you have to put things on hold.
How many copies are out there that you have to put on hold?
This, this now puts your whole company on hold.
Everybody's got some piece of it so that nobody's email is rolling off on an automated, a timeout kind of thing because everybody's got copies in their email that adds up. Or people are trying to, you know, leave the company for different reasons. Maybe they're retiring, but you have to save their OneDrive because they might have copies of something in it. And you have to put that on hold until you get through whatever this is.
So the, the, you don't pay that price right away, but you pay it eventually.
That multiple copy, uncontrolled versions, uncontrolled copies, you pay it eventually. You can take care of it with a system or you can take care of it with disciplined process and checkpoints.
But if you don't do either of those things, then you know that bill is coming.
And that's, that's the thing we're trying to get around is if we, okay, if we go to the process driven thing and we're capturing the data right away and it's always where we expect it to be, then we don't build up that bill and we don't have that looming over our heads, or not even our heads, but the poor person who takes over after us in five years.
So I'm going to stop there for now because I feel like I've been talking for 15 minutes non stop.
[00:25:24] Speaker A: Yes, that's it.
[00:25:28] Speaker B: That's all you got.
[00:25:32] Speaker A: We went a little overtime, so that's fine. And I understand, you know, people have podcasts that go hours, but ours are short snippets of informative information governance pieces.
So email is a trick.
How do you determine what's the last one, the latest piece of data?
How do you determine reliability of your data?
I think these are still questions that we could wrap into next episodes.
[00:26:00] Speaker B: I think so too. I think there's a lot more to explore here because email's not going away, so we need to think about how to make it less risky.
[00:26:13] Speaker A: If you have any questions, please send us an email at info trailblazer.us.com or find us on the web at www.trailblazer.us.com and check out the Trailblazer Learning Academy at trailblazerlearningacademy.com thank you for listening. Please tune into our next episode if you like like this one. Please be a champion and share it with people in your social media network like or subscribe to the channel. Always helpful as well.
We appreciate you the listeners. Special thanks goes to Jason Blake created our music.
[00:26:49] Speaker B: Thanks everyone.
Till next time.