AIM is designed around separation of responsibilities: the customer controls its AI provider credentials, the local WordPress installation controls private work, and AIM Network Hub receives only the data required for activation, directory/community functions and deliberately shared learning.
No public AIM OpenAI key
Customers connect their own OpenAI Platform project through WordPress Settings → Connectors. AIM should not distribute one central provider API key across unrelated customer websites. The provider key is not sent to AIM Network Hub.
Sharing scopes are explicit
Private
Working material remains on the customer installation and is not exposed through the community.
Network anonymised
Reusable learning can contribute without identifying the organisation publicly.
Network attributed
The organisation chooses to attach its identity to the contribution.
Public
Approved material can be published through the AIM website, Directory or shared Library.
Governance is more than credential separation
Separate provider credentials improve isolation and accountability, but they do not by themselves make an organisation compliant with ISO standards, SOC requirements or UK data-protection law. Each organisation remains responsible for its own governance, retention, permissions, supplier review and lawful processing.
Deployment checklist
Review hosting, WordPress roles, authentication, provider project permissions, connector access, network sharing defaults, retention, moderation, approval flows and internal policy before production rollout.
