Bracketed details and operational commitments require completion and legal review.
1. Authorised environments only
Connect, document or change an environment only with appropriate authority. Do not bypass tenant boundaries, permissions, authentication or security controls.
2. Protect credentials and data
Use suitable access controls, safeguard secrets and avoid entering unnecessary sensitive information into documentation or prompts. Share client information only with authorised recipients.
3. Responsible automation
Scope agents to the task and authorised client. Review consequential actions, maintain oversight and do not use the platform to perform destructive or unauthorised changes.
4. Prohibited conduct
Do not distribute malware, facilitate fraud, harass others, infringe rights, attack systems, overload the service or use obtained information unlawfully. Security testing requires prior written authorisation defining scope.
5. Reporting and enforcement
Report suspected misuse to [security contact]. Final procedures should define investigation, proportional access restrictions, notice and a route to resolve disputes. This draft is not yet an effective enforcement policy.