Document summary
This policy defines allowed uses, prohibited data, human oversight, transparency, provider governance, and challenge routes for material outputs.
Uses
AI tools may summarize text, suggest drafts, classify requests, detect similarity, translate, search authorized knowledge, or analyze aggregated data. Output is presented as assistance, not an approved fact.
Data not sent
Passwords, keys, session tokens, payroll data, full payment data, and highly restricted files must not be sent. Identity and unnecessary information are removed before sending where the purpose allows.
Provider selection
The system uses a provider-neutral layer. Each provider is reviewed for processing location, training use, retention, security, subprocessors, cost, and exit plan. Keys are not displayed after saving.
Human review
External replies, contracts, policies, official decisions, permanent bans, and material decisions require authorized human approval. The system does not reject a suggestion, delete a user, or change a vote result based only on a model.
Accuracy and testing
Prompts and models are tested for correct and incorrect cases, bias, safety, and privacy before activation. Staff review retrieved sources and verify claims before approval.
Transparency
Users are told when they interact with an automated assistant or material content was AI-assisted, including limits and a route to a person. The assistant does not impersonate a real employee.
Logs and retention
Use, user, module, provider, model, prompt, version, cost, and outcome are logged with sensitive content redacted. Input and output retention follows purpose and is not indefinite by default.
Challenge and correction
A user may request human review of an output affecting a ticket, content, or access. We correct the record and update the prompt or control for recurring errors. A user appeal is not used for external training without a basis.
Knowledge sources and permissions
The assistant does not retrieve a document the user lacks permission to view. Used sources are shown, permission is enforced before and after embedding, and access withdrawal removes the source from the index.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.