Test Company / Policy authoring
Policies
Current Guard bundle · v16
Approved rules ship as a compact bundle for the extension.
Draft
0
Unapproved rules
Pending
0
Need publish
Published
0
Active in Guard
Previous
5
Review only
Bundle rules
8
Last shipped
Accord built-ins
Enable reviewed policy families and configure which AI destinations your organization approves. Publishing creates one versioned Guard bundle.
Create rules
Import a policy document, or write a rule manually — everything starts as a draft
Import an AI policy document
PDF, DOCX, DOC, TXT, or Markdown. Accord extracts obligations as editable draft rules; the full raw document is never saved.
Write a rule manually
Pending publish
No pending policy changes.
Bundle history
v16 · published
98183154710d68430e57f614
8 rules
v15 · superseded
fd54cba42001a433a9a7d1d7
15 rules
v14 · superseded
cc845b8167d6092834da12a4
15 rules
Show 7 older bundlesHide older bundles
v13 · superseded
2f66a2cd5f22407d748fa04a
15 rules
v12 · superseded
7d197c1d54a5e4613d375f72
18 rules
v11 · superseded
9fe5283f8f95ccf6dbeb0814
12 rules
v10 · superseded
216355311d19da79daca4d69
12 rules
v9 · superseded
4851e5dfffe763ce7c5ccfc5
12 rules
v8 · superseded
5d348e833b93d2ae6d19455d
12 rules
v7 · superseded
cd33b58dc3e63e3faef0a902
12 rules
Published rules
No rules in the current published bundle yet.
Draft rules
No draft rules yet.
Previous versions
5
Previous versions
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Fully enforceableapprovedv3previous version
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Requirement summary
Do not submit client identifying information to unapproved AI
Employee explanation
This policy does not allow client identifying info, confidential data, hr context to be submitted to approved AI.
Supporting excerpt
• AI-generated content must not falsely state that it was written or approved by a veterinarian. • When AI is used to draft sensitive client communications, the employee should be reminded to verify accuracy, tone, and organizational policy before sending.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Fully enforceableapprovedv2previous version
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Requirement summary
Do not submit client identifying information to unapproved AI
Employee explanation
This policy does not allow client identifying info, regulated financial context, hr context to be submitted to personal AI.
Supporting excerpt
Approved AI Tools • Employees may use only AI tools approved by Information Technology and the AI Governance Committee for organizational work. • Employees must not use personal AI accounts for organizational work when an approved company-managed account is available. • Access to an unapproved public AI service must be blocked when the employee attempts to submit organization data.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Rule 2
external_ai_client_info
Fully enforceableapprovedv3previous version
Rule 2
external_ai_client_info
Requirement summary
Rule 2
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Do not submit client identifiers to personal AI
external_ai_client_info
Fully enforceableapprovedv2previous version
Do not submit client identifiers to personal AI
external_ai_client_info
Requirement summary
Do not submit client identifiers to personal AI
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Rule 3
external_ai_client_info
Fully enforceableapprovedv4previous version
Rule 3
external_ai_client_info
Requirement summary
Rule 3
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Rejected rules
0
Rejected rules
No rejected rules yet.
Archived rules
8
Archived rules
Do not submit client identifiers to personal AI
external_ai_client_info
Fully enforceablearchivedv5
Do not submit client identifiers to personal AI
external_ai_client_info
Requirement summary
Do not submit client identifiers to personal AI
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Fully enforceablearchivedv1
Do not submit client identifying information to unapproved AI
do_not_submit_client_identifying_information_to_unapproved_ai
Requirement summary
Do not submit client identifying information to unapproved AI
Employee explanation
This policy does not allow client identifying info, hr context to be submitted to external AI.
Supporting excerpt
Test design: Each numbered clause uses explicit terms such as “must,” “must not,” “only,” “blocked,” and “required” so Accord’s current deterministic policy importer has a fair chance to identify candidate rules.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Require approval for confidential data in AI workflows
require_approval_for_confidential_data_in_ai_workflows
Fully enforceablearchivedv1
Require approval for confidential data in AI workflows
require_approval_for_confidential_data_in_ai_workflows
Requirement summary
Require approval for confidential data in AI workflows
Employee explanation
This policy requires review or approval before confidential data, medical context is used with approved AI.
Supporting excerpt
Purpose • This policy governs the use of generative artificial intelligence tools by employees, contractors, trainees, and volunteers of Northstar Veterinary Medical Center. • The organization supports responsible use of approved AI tools when those tools improve work without exposing confidential information, replacing professional judgment, or violating organizational policy.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Require approval for client identifying information in AI workflows
require_approval_for_client_identifying_information_in_ai_workflows
Fully enforceablearchivedv1
Require approval for client identifying information in AI workflows
require_approval_for_client_identifying_information_in_ai_workflows
Requirement summary
Require approval for client identifying information in AI workflows
Employee explanation
This policy requires review or approval before client identifying info, hr context, legal context is used with approved AI.
Supporting excerpt
Monitoring and Privacy • The organization may record policy events such as the rule triggered, action taken, risk level, AI destination, department, and timestamp. • The organization should not retain complete employee prompts or AI responses for routine governance reporting unless a separately approved investigation or legal requirement authorizes retention. • Governance reporting must be limited to the minimum information required to understand risk, improve policy, and demonstrate compliance.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Do not submit confidential data to unapproved AI
do_not_submit_confidential_data_to_unapproved_ai
Fully enforceablearchivedv1
Do not submit confidential data to unapproved AI
do_not_submit_confidential_data_to_unapproved_ai
Requirement summary
Do not submit confidential data to unapproved AI
Employee explanation
This policy does not allow confidential data, regulated financial context, intellectual property to be submitted to personal AI.
Supporting excerpt
• Employees must not submit confidential contracts, pricing terms, donor information, unpublished financial results, strategic plans, internal investigation material, proprietary procedures, or nonpublic business-development information to an unapproved AI tool. • Confidential internal information may be used with an approved enterprise AI tool only when the applicable data-handling agreement and department policy permit that use.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Do not submit secrets and credentials to unapproved AI
do_not_submit_secrets_and_credentials_to_unapproved_ai
Fully enforceablearchivedv1
Do not submit secrets and credentials to unapproved AI
do_not_submit_secrets_and_credentials_to_unapproved_ai
Requirement summary
Do not submit secrets and credentials to unapproved AI
Employee explanation
This policy does not allow secrets credentials, prompt injection to be submitted to external AI.
Supporting excerpt
Credentials and Security Secrets • Employees must never submit passwords, authentication codes, API keys, access tokens, private keys, database credentials, or other security secrets to any generative AI tool. • Any detected credential or secret must be blocked rather than merely warned or redacted. • Employees must not attempt to bypass, disable, or evade AI governance controls.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Redact client identifying information before external AI use
redact_client_identifying_information_before_external_ai_use
Fully enforceablearchivedv1
Redact client identifying information before external AI use
redact_client_identifying_information_before_external_ai_use
Requirement summary
Redact client identifying information before external AI use
Employee explanation
This policy requires client identifying info, personal data, regulated financial context, medical context to be removed or masked before use with personal AI.
Supporting excerpt
Client, Patient, and Medical Information • Employees must not submit identifiable client or patient information to an unapproved AI tool. • Protected information includes client names, patient names, email addresses, phone numbers, street addresses, medical record numbers, account numbers, appointment dates, invoices, photographs, diagnostic reports, treatment records, and any combination of details that could identify a client or patient. • When an approved workflow permits AI assistance, direct identifiers must be removed or replaced with placeholders before content is submitted. • If identifiable client or patient information is detected in an unapproved AI destination, Accord should redact the identifiers when safe redaction preserves the task.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories
Do not submit client identifiers to personal AI
external_ai_client_info
Fully enforceablearchivedv1
Do not submit client identifiers to personal AI
external_ai_client_info
Requirement summary
Do not submit client identifiers to personal AI
Employee explanation
Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.
Supporting excerpt
Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.
Condition
Legacy rule imported before requirement-level enforceability metadata.
Reasoning
Legacy rule retained as an enforceable organization policy rule.
Data categories