Test Company / Policy authoring

Policies

Supabase liveBundle v16Bundle current

Current Guard bundle · v16

Approved rules ship as a compact bundle for the extension.

Deployed

Draft

0

Unapproved rules

Pending

0

Need publish

Published

0

Active in Guard

Previous

5

Review only

Bundle rules

8

Last shipped

Accord built-ins

Enable reviewed policy families and configure which AI destinations your organization approves. Publishing creates one versioned Guard bundle.

Client & Veterinary DataProtects identifiable client information and confidential veterinary case material without treating veterinary records as human HIPAA data.3 rules

Redact identifiable client information

REDACT · HIGH

Removes client or owner identifiers while preserving useful non-identifying context.

any · Accord Core signals · retrieval examples

De-identify veterinary case material

REDACT · HIGH

Redacts identifiers from discharge notes, lab results, diagnostic reports, and treatment plans.

any · Accord Core signals · retrieval examples

Hold full veterinary records on unapproved AI

HOLD · CRITICAL

Prevents complete confidential case records from being submitted to an unapproved AI destination.

unapproved_only · local concept evidence · retrieval examples

Approved AI / External AI UsageApplies destination-aware controls so confidential material is processed only by organization-approved AI services.3 rules

Hold confidential information on unapproved AI

HOLD · CRITICAL

Requires confidential organizational information to use an approved AI destination.

unapproved_only · local concept evidence · retrieval examples

Hold client records on unapproved AI

HOLD · CRITICAL

Routes confidential client and veterinary records away from unapproved AI services.

unapproved_only · local concept evidence · retrieval examples

Allow approved AI destination

ALLOW · LOW

Confirms that provider scope alone does not block confidential material on an approved service; stricter data rules still apply.

approved_only · local concept evidence · no semantic retrieval

Confidential Business InformationProtects non-public financials, strategy, pricing, contracts, leadership material, security procedures, and proprietary documentation.3 rules

Hold unpublished financial results

HOLD · CRITICAL

Protects internal forecasts, margins, projections, and unreleased operating results on unapproved AI.

unapproved_only · local concept evidence · retrieval examples

Hold internal strategy, pricing, and commercial terms

HOLD · HIGH

Protects expansion plans, internal pricing, contracts, and vendor terms on unapproved AI.

unapproved_only · local concept evidence · retrieval examples

Block highly restricted internal material

BLOCK · CRITICAL

Blocks board material, internal security procedures, or proprietary technical documentation on unapproved AI.

unapproved_only · local concept evidence · retrieval examples

Security & CredentialsUses Accord Core credential findings to redact secrets locally instead of attempting semantic secret detection.2 rules

Redact credentials and secrets

REDACT · CRITICAL

Redacts API keys, passwords, tokens, and other deterministic Accord Core secret findings.

any · Accord Core signals · retrieval examples

Redact private keys and database credentials

REDACT · CRITICAL

Redacts private keys and credential-bearing database URLs using Accord Core findings.

any · Accord Core signals · retrieval examples

Employee & HR InformationProtects compensation, performance, disciplinary, termination, and sensitive employee records.2 rules

Hold sensitive employee records on unapproved AI

HOLD · HIGH

Protects compensation, performance, disciplinary, and termination material.

unapproved_only · local concept evidence · retrieval examples

Redact employee identifiers

REDACT · HIGH

De-identifies employee-sensitive content when identifiers can be safely removed.

any · Accord Core signals · retrieval examples

Provider IDs are organization-specific. Current ChatGPT Guard traffic uses chatgpt; future Copilot, Claude, and Gemini adapters can use the same scope.

Create rules

Import a policy document, or write a rule manually — everything starts as a draft

Import an AI policy document

PDF, DOCX, DOC, TXT, or Markdown. Accord extracts obligations as editable draft rules; the full raw document is never saved.

Write a rule manually

Pending publish

0

No pending policy changes.

Bundle history

v16 · published

98183154710d68430e57f614

8 rules

v15 · superseded

fd54cba42001a433a9a7d1d7

15 rules

v14 · superseded

cc845b8167d6092834da12a4

15 rules

Show 7 older bundles

v13 · superseded

2f66a2cd5f22407d748fa04a

15 rules

v12 · superseded

7d197c1d54a5e4613d375f72

18 rules

v11 · superseded

9fe5283f8f95ccf6dbeb0814

12 rules

v10 · superseded

216355311d19da79daca4d69

12 rules

v9 · superseded

4851e5dfffe763ce7c5ccfc5

12 rules

v8 · superseded

5d348e833b93d2ae6d19455d

12 rules

v7 · superseded

cd33b58dc3e63e3faef0a902

12 rules

Published rules

0

No rules in the current published bundle yet.

Draft rules

0

No draft rules yet.

Previous versions

5

Do not submit client identifying information to unapproved AI

do_not_submit_client_identifying_information_to_unapproved_ai

Requirement summary

Do not submit client identifying information to unapproved AI

Employee explanation

This policy does not allow client identifying info, confidential data, hr context to be submitted to approved AI.

Supporting excerpt

• AI-generated content must not falsely state that it was written or approved by a veterinarian. • When AI is used to draft sensitive client communications, the employee should be reminded to verify accuracy, tone, and organizational policy before sending.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infoconfidential datahr context

Do not submit client identifying information to unapproved AI

do_not_submit_client_identifying_information_to_unapproved_ai

Requirement summary

Do not submit client identifying information to unapproved AI

Employee explanation

This policy does not allow client identifying info, regulated financial context, hr context to be submitted to personal AI.

Supporting excerpt

Approved AI Tools • Employees may use only AI tools approved by Information Technology and the AI Governance Committee for organizational work. • Employees must not use personal AI accounts for organizational work when an approved company-managed account is available. • Access to an unapproved public AI service must be blocked when the employee attempts to submit organization data.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying inforegulated financial contexthr context

Rule 2

external_ai_client_info

Requirement summary

Rule 2

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Do not submit client identifiers to personal AI

external_ai_client_info

Requirement summary

Do not submit client identifiers to personal AI

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Rule 3

external_ai_client_info

Requirement summary

Rule 3

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Rejected rules

0

No rejected rules yet.

Archived rules

8

Do not submit client identifiers to personal AI

external_ai_client_info

Requirement summary

Do not submit client identifiers to personal AI

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information

Do not submit client identifying information to unapproved AI

do_not_submit_client_identifying_information_to_unapproved_ai

Requirement summary

Do not submit client identifying information to unapproved AI

Employee explanation

This policy does not allow client identifying info, hr context to be submitted to external AI.

Supporting excerpt

Test design: Each numbered clause uses explicit terms such as “must,” “must not,” “only,” “blocked,” and “required” so Accord’s current deterministic policy importer has a fair chance to identify candidate rules.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infohr context

Require approval for confidential data in AI workflows

require_approval_for_confidential_data_in_ai_workflows

Requirement summary

Require approval for confidential data in AI workflows

Employee explanation

This policy requires review or approval before confidential data, medical context is used with approved AI.

Supporting excerpt

Purpose • This policy governs the use of generative artificial intelligence tools by employees, contractors, trainees, and volunteers of Northstar Veterinary Medical Center. • The organization supports responsible use of approved AI tools when those tools improve work without exposing confidential information, replacing professional judgment, or violating organizational policy.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

confidential datamedical context

Require approval for client identifying information in AI workflows

require_approval_for_client_identifying_information_in_ai_workflows

Requirement summary

Require approval for client identifying information in AI workflows

Employee explanation

This policy requires review or approval before client identifying info, hr context, legal context is used with approved AI.

Supporting excerpt

Monitoring and Privacy • The organization may record policy events such as the rule triggered, action taken, risk level, AI destination, department, and timestamp. • The organization should not retain complete employee prompts or AI responses for routine governance reporting unless a separately approved investigation or legal requirement authorizes retention. • Governance reporting must be limited to the minimum information required to understand risk, improve policy, and demonstrate compliance.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infohr contextlegal context

Do not submit confidential data to unapproved AI

do_not_submit_confidential_data_to_unapproved_ai

Requirement summary

Do not submit confidential data to unapproved AI

Employee explanation

This policy does not allow confidential data, regulated financial context, intellectual property to be submitted to personal AI.

Supporting excerpt

• Employees must not submit confidential contracts, pricing terms, donor information, unpublished financial results, strategic plans, internal investigation material, proprietary procedures, or nonpublic business-development information to an unapproved AI tool. • Confidential internal information may be used with an approved enterprise AI tool only when the applicable data-handling agreement and department policy permit that use.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

confidential dataregulated financial contextintellectual property

Do not submit secrets and credentials to unapproved AI

do_not_submit_secrets_and_credentials_to_unapproved_ai

Requirement summary

Do not submit secrets and credentials to unapproved AI

Employee explanation

This policy does not allow secrets credentials, prompt injection to be submitted to external AI.

Supporting excerpt

Credentials and Security Secrets • Employees must never submit passwords, authentication codes, API keys, access tokens, private keys, database credentials, or other security secrets to any generative AI tool. • Any detected credential or secret must be blocked rather than merely warned or redacted. • Employees must not attempt to bypass, disable, or evade AI governance controls.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

secrets credentialsprompt injection

Redact client identifying information before external AI use

redact_client_identifying_information_before_external_ai_use

Requirement summary

Redact client identifying information before external AI use

Employee explanation

This policy requires client identifying info, personal data, regulated financial context, medical context to be removed or masked before use with personal AI.

Supporting excerpt

Client, Patient, and Medical Information • Employees must not submit identifiable client or patient information to an unapproved AI tool. • Protected information includes client names, patient names, email addresses, phone numbers, street addresses, medical record numbers, account numbers, appointment dates, invoices, photographs, diagnostic reports, treatment records, and any combination of details that could identify a client or patient. • When an approved workflow permits AI assistance, direct identifiers must be removed or replaced with placeholders before content is submitted. • If identifiable client or patient information is detected in an unapproved AI destination, Accord should redact the identifiers when safe redaction preserves the task.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infopersonal dataregulated financial contextmedical context

Do not submit client identifiers to personal AI

external_ai_client_info

Requirement summary

Do not submit client identifiers to personal AI

Employee explanation

Client identifying information cannot be sent to personal AI. Accord will remove identifiers when it can do so safely, otherwise the submission is blocked or routed for approval.

Supporting excerpt

Employees must not submit client names, addresses, account numbers, veterinary medical records, payment information, or other identifying information to personal or unapproved AI services. When identifying information can be removed without preventing the task, it must be removed before submission. If adequate de-identification is not possible, the submission must be blocked or routed for approval.

Condition

Legacy rule imported before requirement-level enforceability metadata.

Reasoning

Legacy rule retained as an enforceable organization policy rule.

Data categories

client identifying infopersonal dataaddressaccountveterinary medical recordpayment information