← ClaudeAtlas

ai-usage-policylisted

Draft an organisation's AI acceptable-use policy — three data-sensitivity tiers with what may be put into a tool at each, permitted and prohibited uses stated as behaviours, a human-review matrix keyed to consequence, an approved-tool list with an exception route, and a named owner per rule. Use when a team needs rules for what people may put into AI tools, or asks for an AI acceptable-use or governance policy. Do NOT use to write a repo's agent-tooling policy (that's agents-md-generator) or to analyse one agent's capability surface (that's agent-threat-model).
sananthanarayan/skilldrop · ★ 2 · AI & Automation · score 73
Install: claude install-skill sananthanarayan/skilldrop
# ai-usage-policy Write the policy people will actually follow: **what may go in, what must be checked before it goes out, and who to ask when the rule doesn't fit.** The audience is every employee, not the security team — so it reads as rules for a job, not controls for an auditor. A policy that prohibits without offering a permitted path doesn't reduce risk; it moves the same work onto personal accounts where nobody can see it. Every prohibition here carries an alternative. ## How to respond 1. **Establish scope and the regulatory floor.** Which population, which tools, and any regime already binding (sector rules, customer contracts, an existing data-classification scheme). If the organisation already classifies data, **reuse those tier names** rather than inventing a parallel scheme — two classification systems means neither is followed. Cap clarifying questions at 2. 2. **Define three data tiers and what may enter a tool at each.** Three, because five is not memorable and one is not a policy: | Tier | Examples | Rule | |---|---|---| | **Open** | public docs, published marketing, open-source code | any approved tool | | **Internal** | internal docs, non-personal telemetry, private repo code | approved tools with data-retention off / enterprise terms | | **Restricted** | personal data, credentials, customer content under contract, regulated records | never pasted; only via a named reviewed integration, if at all | Give each tier **two concrete exam