What an AI assistant for members does and does not see
A member-facing AI assistant should answer only from what any signed-in member could already find for themselves. Published events, news, guides and the member directory sit inside that line. Other members' records, private messages, staff notes, survey answers and anything unpublished sit outside it, and the time to draw the line is before anything is switched on.
This guide is for the chief executive or membership manager at a chamber of commerce or association who has been offered an assistant, or asked by the board whether the organisation needs one. You hold members' personal data, and the checks below apply whichever supplier you talk to.
One rule: nothing a member could not already see
An assistant should make published material quicker to find without opening anything that was closed before. So agree one test with your team first: could any signed-in member find this by clicking around the portal or the members' area of your website? If yes, the assistant may read it. If no, it may not, however useful that would be.
The rule saves anyone deciding case by case what the assistant may know, and it is easy to explain to a board member who asks what the thing can see.
It also keeps the data protection conversation simpler. UK GDPR expects you to use personal data only for the purpose you collected it for, and to use no more of it than you need. An assistant that reads only published material makes those questions easier to answer, and one that reads the member register makes them harder. Talk the detail through with whoever handles data protection for you. The ICO's guidance on AI and data protection is a sensible place for them to start. The ICO says that guidance is under review following the Data (Use and Access) Act.
What sits inside the line
Inside the line is everything you have already chosen to publish to members:
- published events, with the dates, venues and ticket prices shown on each event page
- news and insights
- resources and guides, including the documents attached to them
- the member directory, as members see it
- discussions that any member can read
The directory holds personal data, but only what members agreed to show one another, such as a name, a job title and an organisation. An assistant that answers "who else here works in logistics?" is doing what the directory is for. It should follow the directory's rules, so a detail a member has hidden from other members stays hidden from the assistant.
What sits outside it
Outside the line is everything a member cannot see, even when your staff can:
- other members' details and payments, including who is late with a renewal
- private messages, which members wrote to one person
- staff notes, which stay candid only while nobody else reads them
- survey answers, given on the understanding that your team would read them
- drafts and unpublished content, such as next year's price list before anyone has agreed it
- the organisation's finances, from budgets to board papers
The awkward cases are the shortcuts that look harmless. Someone suggests letting the assistant read the events team's notes so it can answer "is there parking at the venue?" The better fix is to put the parking information on the event page, where members and the assistant can both see it.
How a member assistant should behave
Deciding what it reads is half the job. The other half is how it answers.
It shows its sources
Every answer should link to the page it came from. A member about to act on a deadline can open that page and check, and your team can trace a wrong answer to the page that caused it. An assistant that cannot show sources asks members to take everything on trust, and your organisation carries the blame when that trust is misplaced.
It says "I don't know"
When nothing published answers the question, the assistant should say so and point the member to a person. A guess delivered in the same confident tone as a real answer is worse than no answer, because the member cannot tell the two apart. Ask any supplier to show you what happens when you ask something your content does not cover.
It never quotes a price or rule it cannot see on a page
Prices, fees, deadlines, refund rules and eligibility criteria should come from a published page or not at all. If the only gala dinner price the assistant can find is last year's, the right answer is that this year's price is not published yet, with a pointer to the events team.
It answers questions and does not act
A member-facing assistant should not book places, cancel memberships, change profiles or send messages on anyone's behalf. It can tell a member where to do those things. A read-only assistant that misunderstands a question gives a wrong answer the member can ignore. One that acts on a misunderstanding creates a booking someone on your team has to unpick.
Keep the team's assistant separate
An assistant for staff is useful in a different way. It can count renewals due this month or pull attendance for last quarter's exporters' briefings. Doing that needs access to things members must never see, so it should be a separate tool with its own permissions.
Limit it to what each person on the team can already open. If your events coordinator cannot see the billing screens, the assistant should not answer their billing questions either. When a figure was never recorded it should say so and never fill the gap with a zero or an estimate. It should also be unable to change records. A plausible wrong figure in a board paper does more damage than a gap someone notices.
Keep your data apart from everyone else's
Your supplier probably runs many organisations from one system. Ask how your records are kept apart from theirs and at what level that is enforced. Ask whether your content is used to train AI models, and what happens to the support requests you send, since those often contain member details.
What to ask any supplier
| Ask | A good answer sounds like |
|---|---|
| What exactly does the member assistant read? | A specific list of published content, and nothing a member could not see. |
| What can it never see? | Named exclusions: private messages, staff notes, payments, survey answers, drafts. |
| Does every answer show its source? | Yes, as a link to the page it came from. |
| What happens when it cannot find an answer? | It says so and points the member to your team, and the supplier shows you this live. |
| Will it quote a price that is not on a published page? | No. Prices and rules come only from published pages. |
| Can it act for a member? | No. It says where to do something and leaves the doing to the member. |
| How is the staff assistant limited? | To what each person can already open, with no ability to change records. |
| Is our content kept apart from other customers' and out of model training? | A specific explanation in writing, which you can hand to whoever handles data protection. |
How the Portava assistant is set up
We make Portava, and the assistant in our membership software follows the rule above. The member assistant answers only from content every member may already see: published events, news, insights, resources, the directory and discussions. It never sees direct messages, staff notes, individual payments, survey answers or unpublished content, and problems your team reports to us are never indexed for it. A discussion post the team holds or hides drops out of its index.
The assistant shows its sources. It will not share other members' payments, status or renewals, the organisation's finances or internal notes, and it will not quote a price it cannot see on a page. When it cannot find something it says so and points the member to Support. It cannot take actions such as booking an event.
Answers members give to your joining questions are kept out of member-facing search, and only the administrator assistant can draw on them. Records of members accepting your rules of engagement never reach the assistant.
The administrator assistant computes figures live from your organisation's own data, within each administrator's access areas. It says "not tracked" rather than zero, never estimates and cannot change anything. Every organisation's records are separated at the database row level.
One limit: the assistant answers only from content added to Portava and cannot read your existing website, so anything members should be able to ask about has to be published in the portal or added as a resource.
If you would like to see what the assistant will and will not answer, request a demo.
Frequently asked questions
Is it safe to give members an AI assistant?
It can be, if you control what it reads. An assistant limited to content any member could already see adds little new risk, because it cannot reveal what it never had. The risk grows with every private source connected to it. Decide the boundary first, then ask the supplier to show you how it is enforced.
What does UK GDPR mean for a member AI assistant?
The same principles apply as to any other use of members' personal data. Use it only for the purpose you collected it for, use no more than you need, tell members what you are doing and keep it secure. An assistant limited to published content makes that easier to show. Check your own case with whoever handles data protection.
Should staff and members share one AI assistant?
No. Staff need figures and records that members must never see, so a shared assistant would hold both and rely on filtering to keep them apart. Run two assistants with separate permissions. Limit the staff one to what each person can already open, and make sure neither of them can change a record on anyone's behalf.
What should an assistant say when it does not know?
It should say plainly that it cannot find an answer in your published content, then tell the member where to go next, usually your team's contact details or support route. It should never guess. Each unanswered question is useful to you as well, because it points to a page members need that nobody has written yet.
