Scope
Applies to every tool that generates, recommends or executes using AI, whether bought or built.
Principles
- A human is accountable for every action; an agent acts within limits set by that human.
- No decision affecting a person's rights, pay or employment is automated without review.
- Company data is shared with a model only under a contract that excludes training on it, unless approved by <role>.
Autonomy levels and approvals
| Level | Example | Approval required | | --- | --- | --- | | Assistance (drafts, summaries) | Draft a supplier email | none | | Copilot (recommendations) | Suggest a supplier for an event | user accepts | | Action (single action) | Send an RFQ | user approves each action | | Workflow (multi-step) | Run an event to award recommendation | owner approves the workflow, reviews the result | | Autonomous (within rules) | Award under <threshold> | policy owner approves the rules, audit monthly |
Records
Every action by an agent is logged with input, output, time and the account it acted for. Logs are retained for <period>.
Review
Policy reviewed <interval>; incidents reported to <role> within <hours>.