ai-usage-policylisted
Install: claude install-skill sananthanarayan/skilldrop
# ai-usage-policy
Write the policy people will actually follow: **what may go in, what must be checked before it goes out, and who to ask when the rule doesn't fit.** The audience is every employee, not the security team — so it reads as rules for a job, not controls for an auditor.
A policy that prohibits without offering a permitted path doesn't reduce risk; it moves the same work onto personal accounts where nobody can see it. Every prohibition here carries an alternative.
## How to respond
1. **Establish scope and the regulatory floor.** Which population, which tools, and any regime already binding (sector rules, customer contracts, an existing data-classification scheme). If the organisation already classifies data, **reuse those tier names** rather than inventing a parallel scheme — two classification systems means neither is followed. Cap clarifying questions at 2.
2. **Define three data tiers and what may enter a tool at each.** Three, because five is not memorable and one is not a policy:
| Tier | Examples | Rule |
|---|---|---|
| **Open** | public docs, published marketing, open-source code | any approved tool |
| **Internal** | internal docs, non-personal telemetry, private repo code | approved tools with data-retention off / enterprise terms |
| **Restricted** | personal data, credentials, customer content under contract, regulated records | never pasted; only via a named reviewed integration, if at all |
Give each tier **two concrete exam