How to split Legal, Protection, IT and Procurement work between routine tasks AI can draft or triage and decisions that must stay human, such as safeguarding disclosures, contract sign-off and access grants.
Six playbooks in, and this one is the odd entry in the series: not one department but four, bundled together because none of Legal, Protection, IT, or Procurement is usually large enough on its own to warrant a standalone chapter, and because all four share the same underlying shape despite covering completely different ground. A wide base of routine, well-defined work sits underneath a narrow set of decisions that carry legal, safeguarding, security, or financial consequence, and no tool can absorb that narrow slice regardless of which of the four functions it sits in.
This piece sorts real work across all four functions the same way as the last five: what is genuinely worth delegating, and what never should be.
Legal handles contract review, compliance filings, and policy drafting. Protection handles the intake, assessment, and referral of anyone reporting harm. IT handles systems administration, access provisioning, and security monitoring. Procurement handles vendor sourcing, quote comparison, and purchase approval. The domains are unrelated, but the pattern repeats: most of the volume is matching, drafting, and comparison against criteria that already exist, and a small number of decisions concentrate all of the real consequence.
A tool can sort the routine work. It cannot carry the safeguarding, legal, security, or procurement judgement underneath it.
Treating Legal, Protection, IT, and Procurement as one article risks flattening how differently serious their worst-case failures actually are: a misconfigured access grant and a mishandled safeguarding disclosure are not equivalent, and putting them side by side here is a simplification for the sake of one readable playbook, not a claim that they carry equal weight. The honest answer is that all four genuinely share the same structural principle even though their consequences differ wildly: the matching and comparison work underneath each function is safe to delegate, and the moment a decision requires professional accountability, security clearance, a person's safety, or a material financial commitment, it stops being delegable regardless of which function it sits in.
Delegate the matching, triage, and comparison work that touches no legal, security, safeguarding, or monetary decision directly; never delegate a safeguarding disclosure, a contract's legal sign-off, a system-access grant, or a material vendor selection.
No external statistic cited; this article presents an internal department playbook rather than third-party evidence.
If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.