Skip to content

Governance starter

Write the boundary before someone has to guess it.

Adapt this one-page structure to your policies, contracts, laws, funder requirements, professional obligations, and Microsoft 365 configuration.

01

Green / allowed starting points

Routine drafts, structure, summaries, preparation, and formatting using approved, low-risk material. A named person reviews every result before external or official use.

02

Yellow / approval required

Donor, participant, employee, financial, contract, board, safeguarding, legal, eligibility, or unpublished strategy information. The data owner and policy owner decide whether and how the task proceeds.

03

Red / do not use in an early pilot

Final eligibility, employment, disciplinary, safety, clinical, legal, fiduciary, grant-award, or crisis decisions. Personal accounts, consumer tools, bypassed permissions, hidden recording, or unattended external communication.

Add these six lines

  1. The exact approved Microsoft account and Copilot product.
  2. The person who owns the policy and answers questions.
  3. Restricted data categories in the language staff already use.
  4. The required review and approval path for each use level.
  5. How to report unexpected access, output, disclosure, or harm.
  6. The next policy review date and who records changes.