Mitchell Growth System← All documents

Which AI tool does which job, and the rules that keep borrower data out of them.

19 — AI Stack and Standard Operating Procedure

Prepared 2026-07-22. Figures verified as of this date unless marked otherwise. Scope: which AI tools Mitchell uses, for what jobs, at what cost, under what rules. This document is written to be handed to Ready Mortgage compliance for written approval before go-live.

Core operating principle (non-negotiable):

AI researches, drafts, organizes, rehearses, and measures. Mitchell decides, verifies, communicates, and owns the relationship.


1. Tool-to-job assignment

Core stack cost: $40/month (Claude Pro $20 + ChatGPT Plus $20). Everything else is $0 or dropped.

Tool / tier Job assignment Cost Data-safety posture Company approval
Claude Pro ($20/mo) The system-builder and long-horizon research engine: multi-source research and synthesis; parallel subagent fan-out (e.g., profiling the 30-agent pilot list); building and maintaining the business-plan file tree, data models, scripts, and website prototype; compliance checklists; red-team review of drafts and plans; scheduled weekly routines (Monday pipeline review, Friday metrics rollup). Only tool in the stack that natively edits local files. $20 Training toggle OFF day one (Settings → Privacy → "Help improve our AI models" = OFF). No NPI ever — consumer tier. Repo stays free of borrower data. Upgrade to Max 5x ($100) only if weekly caps interrupt work 2+ consecutive weeks. Yes — disclose in written AI-use approval
ChatGPT Plus ($20/mo) The rehearsal and voice engine: one dedicated Project ("Mitchell — Approved Materials") holding only public/approved scripts, objection libraries, and product one-pagers; Advanced Voice Mode daily role-play against those materials; Deep Research (~10 runs/mo) for narrowly scoped questions; script refinement; meeting prep; weekly review accountability. $20 Training toggle OFF (Settings → Data Controls → "Improve the model for everyone" = OFF — paying $20 does NOT change the default). Temporary Chat for anything borderline. Project holds public/approved content only. Yes — same disclosure
Kimi K3 / Kimi Claw Public-content-only at most; recommended default: skip entirely. If approved at all: long-context research on public documents, formatting already-public content. Never borrower docs, never credentials, never secure systems, never autonomous sends. $0 Security basis (documented, factual): Moonshot is Beijing-based; hosted prompts sit under Chinese law including National Intelligence Law compelled-disclosure obligations. Its privacy policy states prompts/uploads may be used to train models, with no clear consumer opt-out. The Institute for AI Policy and Strategy published a specific risk analysis of Kimi Claw as a Chinese-hosted always-on agent; Harmonic Security measured Kimi as the most-used China-based AI tool inside enterprises (~3.5x DeepSeek), with leaked financial and PII data categories; Fisher Phillips issued employer guidance on controlling Kimi use at work; US federal restrictions on Chinese AI services are reportedly under consideration. Under a GLBA Safeguards mindset this is an unvetted offshore service provider with zero contract. Yes — explicit written approval required; expect "no." The plan loses nothing if Kimi is dropped.
Grok (free tier) Optional only: X/Twitter trend and local-conversation discovery, alternative brainstorming. Never authoritative for rates, law, program guidelines, or product claims. $0 Trains on user data (incl. X activity) by default — opt out under X Privacy & Safety → Grok data controls. No paid tier in year one. Yes if used for any work content

Redundancy check: no two tools share a primary job. Claude builds and researches; ChatGPT rehearses and voices; Kimi and Grok are droppable experiments. If budget must go to $20, drop ChatGPT Plus last-in-first-out is wrong — drop nothing; $40/mo is the floor for the plan as designed, and both core tools carry non-overlapping load.

The differentiator framing: Fannie Mae Lender Letter LL-2026-04 (2026-04-08) requires AI/ML governance frameworks of seller/servicers using AI in origination or servicing; Freddie Mac added parallel servicer-guide requirements in late 2025. Every mortgage employer now needs (or soon will have) a written AI policy. A brand-new MLO who shows up to his manager with this SOP already written is ahead of most veteran LOs on a requirement the company itself is now under. Present it that way: not "please let me use AI," but "here is my governance framework, ready for your file."


2. AI Standard Operating Procedure

2.1 Approved uses

  1. Research and synthesis of public information: market data, publicly published agency guidelines, competitor content, education material.
  2. Drafting marketing and education content for human review before publication — nothing publishes straight from a model.
  3. Role-play and coaching against approved scripts using fictional personas only — never real borrower details.
  4. Meeting prep from public/approved inputs; weekly metrics review on anonymized numbers (counts and rates, no names).
  5. Building and maintaining business-plan files, checklists, templates, and the prompt library.

2.2 Prohibited data — the NPI list (never enters any AI tool on current consumer tiers)

Why this is absolute: an MLO handles nonpublic personal information — exactly what the GLBA Safeguards Rule (16 CFR Part 314) obligates the institution to protect, including oversight of service providers. A personal consumer AI account is an unvetted service provider with no contract, no audit rights, and (on consumer defaults) active training use. Pasting borrower data into one is a Safeguards Rule gap and, at most companies, a fireable policy violation.

2.3 Human-review gates (nothing skips these)

  1. All external-facing content (social, email, flyers, website, video scripts): Mitchell reviews → company compliance/marketing approval per Ready policy → then publish. NMLS IDs and Equal Housing language per 38 Ill. Adm. Code 1050.940 and company policy ([MITCHELL_NMLS], [READY_NMLS_1100518 — verify]).
  2. All numbers (rates, payments, program limits, dates): verified against an authoritative source — rate sheet, agency guideline, official program site — before leaving draft status. AI is never the source of record for any figure.
  3. All borrower-facing communication is sent by Mitchell from company systems. AI drafts; Mitchell sends. No AI tool sends messages autonomously — no exceptions, including any Kimi Claw or agent-mode capability.
  4. Legal/compliance questions: AI may summarize the landscape, but the answer of record comes from Ready compliance.

2.4 Source-checking rule

Every research output retains its source URLs. Any claim without a checkable source is marked "unverified" and never reaches a borrower, an agent, or a published page. Anything Ready-specific stays marked [UNVERIFIED — confirm with manager] until confirmed in writing.

2.5 File naming convention

YYYY-MM-DD_topic_status.md — e.g., 2026-07-22_fthb-dpa-stack-onepager_DRAFT.md. Status values: DRAFTREVIEWED (Mitchell verified numbers) → APPROVED (compliance sign-off) → PUBLISHED. Nothing leaves DRAFT without passing a gate in §2.3. Bill-facing/company-facing documents carry the date prefix so versions are never ambiguous.

2.6 Compliance-approval workflow

  1. Present this SOP + the §1 tool table to Mitchell's managing broker/compliance for written approval before go-live.
  2. Re-approve on any tool or tier change (new tool, tier upgrade, new capability like agent mode).
  3. Keep the approval email/document in the business-plan repo (compliance/ folder).
  4. Quarterly: re-present a one-paragraph "no changes" or "changes requested" note so the approval never goes stale.

2.7 Prompt templates (the working library)

Stored in the repo; each template used verbatim, then refined monthly. All templates assume public/approved inputs only.

T1 — Daily planning (Claude or ChatGPT, 5 min, morning): "Here is my calendar for today and my current next-actions list [paste anonymized list — initials or codes only]. Order my day: 60–90 min outreach sprint placement, prep blocks before each call, one recovery block after the highest-social-intensity item, and the top 3 outcomes that would make today a win. Flag anything overdue."

T2 — Realtor research brief (Claude): "Build a one-page brief on [AGENT NAME], a real estate agent at [BROKERAGE] in [TOWN], using only public sources (their website, public listings, public social posts). Include: apparent niche and price band, recent listings/sales activity, communication style, one genuine specific compliment I could make, and one difficult-scenario opener relevant to their business. Cite every source URL. Mark anything inferred as inference."

T3 — Scenario drill (ChatGPT, daily): "Act as an underwriter quizzing me on [PRODUCT: FHA / conventional / VA / bank-statement / DPA pairing]. Present a realistic but fictional borrower scenario for the Chicago southwest suburbs ($250–400k price band). Let me talk through qualification, then critique my answer against published agency guidelines. Do not invent guideline numbers — if unsure, say so and I'll verify."

T4 — Objection role-play (ChatGPT Advanced Voice, daily): "You are a skeptical listing agent in Orland Park who already has a preferred lender. I'm going to practice my Scenario Desk pitch. Push back realistically — busy, mildly dismissive, 'my lender is fine.' After 5 minutes, break character and score me on: opener, credibility without borrowed experience, the one-scenario ask, and close. Persona is fictional."

T5 — Call debrief from written notes (either tool): "Here are my written notes from a call with a realtor [anonymized — no borrower info, agent first name only]. What did I miss? What was the real objection under the stated one? Draft the follow-up email (for my review, not sending) and the specific next-action with a date." (Written notes only — no recordings, no transcripts of the other party without consent; Illinois is a two-party consent state.)

T6 — Content fact-check (Claude, before anything moves to REVIEWED): "Fact-check this draft line by line. For every number, program name, limit, date, or legal claim: state whether I've provided a source, and flag it 'VERIFY' if not. Flag any sentence that implies experience I don't have, any guarantee-like language, and any missing licensing disclosure. Do not fix silently — list findings."

T7 — Weekly KPI review (Claude, Fridays, feeds the §23 scorecard): "Here are this week's KPI numbers [anonymized counts]. Compare to targets and last 3 weeks. Which leading indicators moved? Which stop/continue rules from 23_kpi_scorecard.md are triggered? Give me the 3 highest-leverage adjustments for next week — behavior changes, not platitudes."

2.8 Training-toggle kill-list (do once, re-verify quarterly)

Account Setting State
ChatGPT Data Controls → "Improve the model for everyone" OFF
Claude Privacy → "Help improve our AI models" OFF (note: opted-out = 30-day retention; opted-in chats retained up to 5 years; safety-flagged conversations may be used regardless — another reason NPI never goes in)
Grok / X Privacy & Safety → Grok data controls OFF
Kimi No reliable consumer opt-out exists Treat every input as public — which is why only public content may enter, if used at all

Also: unique passwords + MFA on every AI account; all work AI use in a dedicated work browser profile (reduces accidental paste from personal contexts and vice versa).

Quarterly re-verify (calendar recurring, 1st business day of Jan/Apr/Jul/Oct): reopen each settings page, confirm toggles survived app updates, screenshot, file in repo.

2.9 Weekly maintenance checklist (15 min, part of Friday review)

2.10 Incident response — sensitive data accidentally entered

  1. Stop. End the conversation immediately; do not keep prompting around it.
  2. Delete + vendor deletion request. Delete the chat and any uploaded file from tool history; if NPI was involved, also submit a data-deletion request through the vendor's privacy portal (ChatGPT/Claude both have one; Kimi effectively does not — which is itself a reason it never touches anything sensitive).
  3. Document: what data, which tool and tier, date/time, training-toggle state at the time.
  4. Report to Ready compliance/manager the same business day if borrower NPI was involved. The company may have GLBA incident-assessment obligations — that determination is theirs, not Mitchell's.
  5. Rotate credentials immediately if any login, password, or MFA material was entered.
  6. Remediate: identify the mechanism (usually copy/paste from LOS or email) and add a guard — a redaction step, the separate browser profile, or removing the source window from the workflow.

3. What this SOP is for

It keeps Mitchell fast where AI is safe (research, drafting, rehearsal, measurement) and slow where the law and the license live (numbers, borrower data, external communication). A CCO reading any file in this repo should be able to see exactly which gate it passed. That is the whole design.

PreviousRisk RegisterNextAssumptions & Unknowns