Test Company / Policy authoring
Policies
Current Guard bundle · v12
Approved rules ship as a compact bundle for the extension.
Draft
0
Unapproved rules
Pending
0
Need publish
Published
7
Active in Guard
Previous
5
Review only
Bundle rules
7
Last shipped
Create rules
Import a policy document, or write a rule manually — everything starts as a draft
Import an AI policy document
PDF, DOCX, DOC, TXT, or Markdown. Accord extracts obligations as editable draft rules — raw text is never saved.
Write a rule manually
Pending publish
No pending policy changes.
Bundle history
v12 · published
7d197c1d54a5e4613d375f72
7 rules
v11 · superseded
9fe5283f8f95ccf6dbeb0814
1 rules
v10 · superseded
216355311d19da79daca4d69
1 rules
Show 7 older bundlesHide older bundles
v9 · superseded
4851e5dfffe763ce7c5ccfc5
1 rules
v8 · superseded
5d348e833b93d2ae6d19455d
1 rules
v7 · superseded
cd33b58dc3e63e3faef0a902
1 rules
v6 · superseded
356703e0f5a1f84c1c9ba617
1 rules
v5 · superseded
9ac8371ec3dc693632af5d4a
1 rules
v4 · superseded
99176802df272ea87e3682a8
1 rules
v3 · superseded
8b6c29916427727c2673c19e
1 rules
Published rules
Redact client identifying information before external AI use
redact_client_identifying_information_before_external_ai_use
approvedv1bundle v12
Redact client identifying information before external AI use
redact_client_identifying_information_before_external_ai_use
Employee explanation
This policy requires client identifying info, personal data, regulated financial context, medical context to be removed or masked before use with personal AI.
Supporting excerpt
Client, Patient, and Medical Information • Employees must not submit identifiable client or patient information to an unapproved AI tool. • Protected information includes client names, patient names, email addresses, phone numbers, street addresses, medical record numbers, account numbers, appointment dates, invoices, photographs, diagnostic reports, treatment records, and any combination of details that could identify a client or patient. • When an approved workflow permits AI assistance, direct identifiers must be removed or replaced with placeholders before content is submitted. • If identifiable client or patient information is detected in an unapproved AI destination, Accord should redact the identifiers when safe redaction preserves the task.
Data categories
Do not submit secrets and credentials to unapproved AI
do_not_submit_secrets_and_credentials_to_unapproved_ai
approvedv1bundle v12
Do not submit secrets and credentials to unapproved AI
do_not_submit_secrets_and_credentials_to_unapproved_ai
Employee explanation
This policy does not allow secrets credentials, prompt injection to be submitted to external AI.
Supporting excerpt
Credentials and Security Secrets • Employees must never submit passwords, authentication codes, API keys, access tokens, private keys, database credentials, or other security secrets to any generative AI tool. • Any detected credential or secret must be blocked rather than merely warned or redacted. • Employees must not attempt to bypass, disable, or evade AI governance controls.
Data categories
Do not submit confidential data to unapproved AI
do_not_submit_confidential_data_to_unapproved_ai
approvedv1bundle v12
Do not submit confidential data to unapproved AI
do_not_submit_confidential_data_to_unapproved_ai
Employee explanation
This policy does not allow confidential data, regulated financial context, intellectual property to be submitted to personal AI.
Supporting excerpt
• Employees must not submit confidential contracts, pricing terms, donor information, unpublished financial results, strategic plans, internal investigation material, proprietary procedures, or nonpublic business-development information to an unapproved AI tool. • Confidential internal information may be used with an approved enterprise AI tool only when the applicable data-handling agreement and department policy permit that use.
Data categories
Require approval for client identifying information in AI workflows
require_approval_for_client_identifying_information_in_ai_workflows
approvedv1bundle v12
Require approval for client identifying information in AI workflows
require_approval_for_client_identifying_information_in_ai_workflows
Employee explanation
This policy requires review or approval before client identifying info, hr context, legal context is used with approved AI.
Supporting excerpt
Monitoring and Privacy • The organization may record policy events such as the rule triggered, action taken, risk level, AI destination, department, and timestamp. • The organization should not retain complete employee prompts or AI responses for routine governance reporting unless a separately approved investigation or legal requirement authorizes retention. • Governance reporting must be limited to the minimum information required to understand risk, improve policy, and demonstrate compliance.
Data categories
Require approval for confidential data in AI workflows
require_approval_for_confidential_data_in_ai_workflows
approvedv1bundle v12
Require approval for confidential data in AI workflows
require_approval_for_confidential_data_in_ai_workflows
Employee explanation
This policy requires review or approval before confidential data, medical context is used with approved AI.
Supporting excerpt
Purpose • This policy governs the use of generative artificial intelligence tools by employees, contractors, trainees, and volunteers of Northstar Veterinary Medical Center. • The organization supports responsible use of approved AI tools when those tools improve work without exposing confidential information, replacing professional judgment, or violating organizational policy.
Data categories
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
approvedv1bundle v12
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Employee explanation
This policy does not allow client identifying info, hr context to be submitted to external AI.
Supporting excerpt
Test design: Each numbered clause uses explicit terms such as “must,” “must not,” “only,” “blocked,” and “required” so Accord’s current deterministic policy importer has a fair chance to identify candidate rules.
Data categories
Do not submit client identifiers to personal AI
external_ai_client_info
approvedv5bundle v12
Do not submit client identifiers to personal AI
external_ai_client_info
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Data categories
Draft rules
No draft rules yet.
Previous versions
5
Previous versions
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
approvedv3previous version
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Employee explanation
This policy does not allow client identifying info, confidential data, hr context to be submitted to approved AI.
Supporting excerpt
• AI-generated content must not falsely state that it was written or approved by a veterinarian. • When AI is used to draft sensitive client communications, the employee should be reminded to verify accuracy, tone, and organizational policy before sending.
Data categories
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
approvedv2previous version
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Employee explanation
This policy does not allow client identifying info, regulated financial context, hr context to be submitted to personal AI.
Supporting excerpt
Approved AI Tools • Employees may use only AI tools approved by Information Technology and the AI Governance Committee for organizational work. • Employees must not use personal AI accounts for organizational work when an approved company-managed account is available. • Access to an unapproved public AI service must be blocked when the employee attempts to submit organization data.
Data categories
Do not submit client identifiers to personal AI
external_ai_client_info
approvedv2previous version
Do not submit client identifiers to personal AI
external_ai_client_info
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Data categories
Rule 2
external_ai_client_info
approvedv3previous version
Rule 2
external_ai_client_info
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Data categories
Rule 3
external_ai_client_info
approvedv4previous version
Rule 3
external_ai_client_info
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Data categories
Rejected rules
0
Rejected rules
No rejected rules yet.
Archived rules
1
Archived rules
Do not submit client identifiers to personal AI
external_ai_client_info
archivedv1
Do not submit client identifiers to personal AI
external_ai_client_info
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Data categories