Governance starter
Write the boundary before someone has to guess it.
Adapt this one-page structure to your policies, contracts, laws, funder requirements, professional obligations, and Microsoft 365 configuration.
Green / allowed starting points
Routine drafts, structure, summaries, preparation, and formatting using approved, low-risk material. A named person reviews every result before external or official use.
Yellow / approval required
Donor, participant, employee, financial, contract, board, safeguarding, legal, eligibility, or unpublished strategy information. The data owner and policy owner decide whether and how the task proceeds.
Red / do not use in an early pilot
Final eligibility, employment, disciplinary, safety, clinical, legal, fiduciary, grant-award, or crisis decisions. Personal accounts, consumer tools, bypassed permissions, hidden recording, or unattended external communication.
Add these six lines
- The exact approved Microsoft account and Copilot product.
- The person who owns the policy and answers questions.
- Restricted data categories in the language staff already use.
- The required review and approval path for each use level.
- How to report unexpected access, output, disclosure, or harm.
- The next policy review date and who records changes.