A

Test Company / Policy authoring

Policies

Supabase liveBundle v12Bundle current

Current Guard bundle · v12

Approved rules ship as a compact bundle for the extension.

Deployed

Draft

0

Unapproved rules

Pending

0

Need publish

Published

7

Active in Guard

Previous

5

Review only

Bundle rules

7

Last shipped

Create rules

Import a policy document, or write a rule manually — everything starts as a draft

Import an AI policy document

PDF, DOCX, DOC, TXT, or Markdown. Accord extracts obligations as editable draft rules — raw text is never saved.

Write a rule manually

Pending publish

0

No pending policy changes.

Bundle history

v12 · published

7d197c1d54a5e4613d375f72

7 rules

v11 · superseded

9fe5283f8f95ccf6dbeb0814

1 rules

v10 · superseded

216355311d19da79daca4d69

1 rules

Show 7 older bundles

v9 · superseded

4851e5dfffe763ce7c5ccfc5

1 rules

v8 · superseded

5d348e833b93d2ae6d19455d

1 rules

v7 · superseded

cd33b58dc3e63e3faef0a902

1 rules

v6 · superseded

356703e0f5a1f84c1c9ba617

1 rules

v5 · superseded

9ac8371ec3dc693632af5d4a

1 rules

v4 · superseded

99176802df272ea87e3682a8

1 rules

v3 · superseded

8b6c29916427727c2673c19e

1 rules

Published rules

7

Redact client identifying information before external AI use

redact_client_identifying_information_before_external_ai_use

Employee explanation

This policy requires client identifying info, personal data, regulated financial context, medical context to be removed or masked before use with personal AI.

Supporting excerpt

Client, Patient, and Medical Information • Employees must not submit identifiable client or patient information to an unapproved AI tool. • Protected information includes client names, patient names, email addresses, phone numbers, street addresses, medical record numbers, account numbers, appointment dates, invoices, photographs, diagnostic reports, treatment records, and any combination of details that could identify a client or patient. • When an approved workflow permits AI assistance, direct identifiers must be removed or replaced with placeholders before content is submitted. • If identifiable client or patient information is detected in an unapproved AI destination, Accord should redact the identifiers when safe redaction preserves the task.

Data categories

client identifying infopersonal dataregulated financial contextmedical context

Do not submit secrets and credentials to unapproved AI

do_not_submit_secrets_and_credentials_to_unapproved_ai

Employee explanation

This policy does not allow secrets credentials, prompt injection to be submitted to external AI.

Supporting excerpt

Credentials and Security Secrets • Employees must never submit passwords, authentication codes, API keys, access tokens, private keys, database credentials, or other security secrets to any generative AI tool. • Any detected credential or secret must be blocked rather than merely warned or redacted. • Employees must not attempt to bypass, disable, or evade AI governance controls.

Data categories

secrets credentialsprompt injection

Do not submit confidential data to unapproved AI

do_not_submit_confidential_data_to_unapproved_ai

Employee explanation

This policy does not allow confidential data, regulated financial context, intellectual property to be submitted to personal AI.

Supporting excerpt

• Employees must not submit confidential contracts, pricing terms, donor information, unpublished financial results, strategic plans, internal investigation material, proprietary procedures, or nonpublic business-development information to an unapproved AI tool. • Confidential internal information may be used with an approved enterprise AI tool only when the applicable data-handling agreement and department policy permit that use.

Data categories

confidential dataregulated financial contextintellectual property

Require approval for client identifying information in AI workflows

require_approval_for_client_identifying_information_in_ai_workflows

Employee explanation

This policy requires review or approval before client identifying info, hr context, legal context is used with approved AI.

Supporting excerpt

Monitoring and Privacy • The organization may record policy events such as the rule triggered, action taken, risk level, AI destination, department, and timestamp. • The organization should not retain complete employee prompts or AI responses for routine governance reporting unless a separately approved investigation or legal requirement authorizes retention. • Governance reporting must be limited to the minimum information required to understand risk, improve policy, and demonstrate compliance.

Data categories

client identifying infohr contextlegal context

Require approval for confidential data in AI workflows

require_approval_for_confidential_data_in_ai_workflows

Employee explanation

This policy requires review or approval before confidential data, medical context is used with approved AI.

Supporting excerpt

Purpose • This policy governs the use of generative artificial intelligence tools by employees, contractors, trainees, and volunteers of Northstar Veterinary Medical Center. • The organization supports responsible use of approved AI tools when those tools improve work without exposing confidential information, replacing professional judgment, or violating organizational policy.

Data categories

confidential datamedical context

Do not submit client identifying information to unapproved AI

do_not_submit_client_identifying_information_to_unapproved_ai

Employee explanation

This policy does not allow client identifying info, hr context to be submitted to external AI.

Supporting excerpt

Test design: Each numbered clause uses explicit terms such as “must,” “must not,” “only,” “blocked,” and “required” so Accord’s current deterministic policy importer has a fair chance to identify candidate rules.

Data categories

client identifying infohr context

Do not submit client identifiers to personal AI

external_ai_client_info

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Draft rules

0

No draft rules yet.

Previous versions

5

Do not submit client identifying information to unapproved AI

do_not_submit_client_identifying_information_to_unapproved_ai

Employee explanation

This policy does not allow client identifying info, confidential data, hr context to be submitted to approved AI.

Supporting excerpt

• AI-generated content must not falsely state that it was written or approved by a veterinarian. • When AI is used to draft sensitive client communications, the employee should be reminded to verify accuracy, tone, and organizational policy before sending.

Data categories

client identifying infoconfidential datahr context

Do not submit client identifying information to unapproved AI

do_not_submit_client_identifying_information_to_unapproved_ai

Employee explanation

This policy does not allow client identifying info, regulated financial context, hr context to be submitted to personal AI.

Supporting excerpt

Approved AI Tools • Employees may use only AI tools approved by Information Technology and the AI Governance Committee for organizational work. • Employees must not use personal AI accounts for organizational work when an approved company-managed account is available. • Access to an unapproved public AI service must be blocked when the employee attempts to submit organization data.

Data categories

client identifying inforegulated financial contexthr context

Do not submit client identifiers to personal AI

external_ai_client_info

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Rule 2

external_ai_client_info

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Rule 3

external_ai_client_info

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Rejected rules

0

No rejected rules yet.

Archived rules

1

Do not submit client identifiers to personal AI

external_ai_client_info

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information