AI Assisted Work
Define acceptable use of AI tools for drafting, analysis, automation, and sensitive data.
Plain-language standards that define expectations, exception paths, and review ownership.
Define acceptable use of AI tools for drafting, analysis, automation, and sensitive data.
Define responsible use of systems, accounts, data, and shared resources.
Define how access is reviewed, changed, approved, and removed.
Set expectations for backup scope, retention, testing, and restoration responsibility.
Define when changes require review, approval, notice, or rollback planning.
Define simple levels for data sensitivity and required handling.
Define how long records are kept and when they may be archived or deleted.
Set expectations for current, findable, owner-assigned documentation.
Define who must be notified when incidents affect service, data, obligations, or reputation.
Define authentication expectations, MFA use, password handling, and exceptions.
Set expectations for access, devices, communication, security, and availability away from site.
Define when records may be kept longer or removed sooner than the standard rule.
Define how vendors, services, and external tools are reviewed before use.
Set rules for third-party access to systems, data, and support channels.