Skip to main content
Security & Compliance•9 min read

Document Control When AI Can Edit the File

October 7, 2026•By Ajan Kanagalingam

Until recently, getting AI output into a business document required a person to select it, copy it and paste it somewhere. That person read the text on the way past, decided it was good enough, and chose where it went. None of that was written in a procedure. All of it was approval, and assistants that edit the live file have started to remove it.

What document control is for

Three questions, and a business either answers them or discovers it cannot at a bad moment. Which version is authoritative. Who is allowed to change it. How a change gets approved and recorded.

Most small and mid-sized businesses answer the first with a folder convention, the second with trust, and the third not at all. That held together while changes were slow and deliberate, because a document only changed when somebody sat down and changed it.

It holds together less well when a change can be generated, applied and saved in one instruction, and when the person who issued the instruction did not necessarily read the result.

Sort your documents into two piles

Controlled documents are the ones where being wrong has a consequence outside the room. Anything a customer receives. Anything forming part of a contract. Pricing. Safety and operating procedures. Regulatory submissions. Any figure that reaches a financial statement.

Everything else is a working file, and treating working files as controlled is how document control gets quietly abandoned. If every draft needs approval, the approval becomes a formality and then a nuisance, and then somebody turns it off for everything.

Write the two lists down and put the controlled ones somewhere structurally different, which can be as simple as a separate drive with different permissions. The distinction has to be visible in the file location, because a rule that depends on people remembering which category a document is in will not survive a busy week.

Match the approval mode to the pile

Document typeAI editing modeWhat to record
Customer-facing and contractualApprove each changeWho approved, and when
Pricing and financial figuresApprove each changeSource of every number
Procedures and safetyApprove, plus a named ownerEffective date and version
Internal reports and analysisAutomatic is reasonablePlatform version history
Drafts and working filesAutomatic, and take the speedNothing beyond the default

Tools now commonly ship with exactly these two modes, one that surfaces each change for approval and one that applies changes without stopping. Treat the choice as policy rather than preference, because left as a per-user setting it drifts toward whichever is faster, and it drifts in the week somebody is behind.

Where a tool cannot tell your two piles apart, keep approval on everywhere. That costs some speed on drafts and it is the defensible position, which is worth more on the documents in the top three rows.

What version history does and does not prove

Platform version history is better than most businesses credit. It usually records what changed, when, and which account made the change, which is more than a shared drive full of files named final-v3 ever managed.

What it rarely records is whether a person read the change or an assistant applied it on that account's behalf. Both appear as the same user editing the document. An auditor, an insurer or a regulator asking who approved this will not be satisfied by an entry showing that an account saved it.

On controlled documents, capture the approval separately from the edit. A line in a log, a signed-off change note, a status field that a named person sets. The mechanism matters less than the fact that it exists outside the tool that made the change, which is the same principle behind keeping automated decisions audit-ready.

Who holds the switch

Connecting an assistant to a document platform is usually an administrator action on business plans, and it applies to a workspace rather than to one person. One decision, organisation-wide effect.

Decide deliberately who holds that switch, and write down when it was flipped and what was enabled. The question is the same for any integration that acquires write access to a system of record, and it is the one most often discovered after the fact, which is the theme of building an AI governance framework.

Review scales differently now

An approval card you click forty times in a morning stops being an approval. The volume of changes an assistant can propose exceeds what a person reads carefully, and the failure mode is approving without reading rather than refusing.

Two things help. Keep controlled-document editing sessions short and deliberate rather than continuous. And decide in advance what you are checking, which on most documents is the numbers, the names, the dates and anything stated as a commitment. That discipline is set out in quality assurance when AI writes the first draft.

Procedures deserve a named owner on top of that, because a procedure edited by whoever had it open is how operating documents drift away from how the work is actually done. Writing them properly in the first place is covered in standard operating procedures with AI.

A week of work, not a project

List your controlled documents, which in most businesses runs to a page. Move them somewhere with different permissions. Set approval-required mode wherever an assistant can reach them. Name an owner for each procedure. Add one log where approvals get recorded.

That is a few days of work and it answers the three questions document control exists to answer. Skipping it does not mean you have no policy, only that your policy is whatever each person's default setting happens to be, and recovering the history afterwards is the expensive version described in root cause analysis.

Frequently Asked Questions

What is document control and why does AI change it?

Document control is knowing which version of a document is authoritative, who may change it, and how a change gets approved and recorded. AI changes it because assistants have begun editing files in place rather than producing text you paste in. The paste step was doing approval work nobody wrote down, since a person had to read the output and decide to move it. Remove the step and the approval has to live somewhere explicit.

Which documents need formal control?

The ones where being wrong has a consequence outside the room: anything a customer receives, anything forming part of a contract, pricing, safety and operating procedures, regulatory submissions, and any figure that feeds a financial statement. That list is short in most businesses and it is also the list most likely to be edited by whoever has the file open. Everything else, including internal drafts and research notes, can be left loose on purpose.

How should we handle approval modes in AI tools?

Treat the setting as a policy decision rather than a preference. Tools now commonly offer a mode that shows each change for approval and a mode that applies changes without stopping. Match the mode to the document class: approval required on controlled documents, automatic acceptable on drafts and working files. Where the tool cannot distinguish, the honest answer is to keep approval on everywhere, because a per-user default will drift toward whichever is faster.

Is version history enough of an audit trail?

It is better than most businesses realise and weaker than an audit trail needs to be. Platform version history usually records what changed and which account made the change, which answers more than a filename ever did. What it rarely records is whether a human reviewed the change or an assistant applied it on that account’s behalf, and that distinction is the one an auditor or an insurer will ask about. Where it matters, capture the approval separately.

Who should be allowed to turn these connectors on?

On business plans, enabling an assistant’s access to a document platform is usually an administrator action that applies to a workspace rather than to one person. Decide deliberately who holds that switch and record when it was flipped, because the organisation-wide blast radius is the part people discover afterwards. The same question applies to any integration that gains write access to a system of record.

Decide it before the setting decides it

We help Canadian businesses separate controlled documents from working files, set AI editing permissions to match, and record approvals where they can be produced on request.

Related Articles

Security & Compliance

When the US Can Switch Off Your AI: Export Controls in Canada

June 16, 2026Read more →
Security & Compliance

From Chatbots to Agent Gateways: How to Control What AI Agents Can Touch

May 27, 2026Read more →
Security & Compliance

Data Loss Prevention When Staff Use AI Every Day

September 2, 2026Read more →
AK
Ajan Kanagalingam
Founder & ChatGPT Consultant, ChatGPT.ca

Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.