Loading your training…

?
Loading…
Your Progress 0 of 9 sections complete
Content Assessment Acknowledgment
1
Approved Tools and the Registry
What you may use, and how to get something added
β–Ό

An unapproved AI tool may not be used for organizational work. This applies regardless of the tool's cost, general availability, or how low the risk appears.

An unapproved tool is any AI tool or AI-powered feature not currently listed in the Approved Tool Registry.

AI features newly switched on inside software the Company already approved require separate review. Approving the software was not approving the feature.

Approval is per use case, not per tool. Being cleared to draft marketing copy in a tool is not clearance to process customer financial data in that same tool. A new use case requires a new intake submission.

Check the registry before using any AI tool for organizational work. Any employee may submit a tool for vetting through the AI Tool Intake Form, which routes to the CISO for a risk-tier determination.

Risk tierDecision timelineNote
Tier 1Within 5 business daysDecisions are issued in writing.
Tier 2Within 15 business daysApproved tools reach the registry within 5 business days.
Tier 3Within 30 business daysAgentic capability is automatically Tier 3.
Amnesty window. During the window you may disclose a tool you are already using with no disciplinary consequence. Disclosed tools simply enter the vetting queue. After the window closes, use of unapproved tools falls under the consequence framework. AI Policy Β§4Β§5
2
What AI May and May Not Touch
The Non-Supersession Rule and system access defaults
β–Ό
The Non-Supersession Rule. An AI system will never hold, exercise, or be granted access permissions exceeding those of the authorized human user. The security posture of the underlying system is the ceiling for any AI interaction with it, not the floor. This rule is absolute, and no exception is ever granted to it.
  • An AI tool operating under your credentials cannot reach systems, files, or data you are not personally authorized to access.
  • Granting an AI system elevated permissions to work around a workflow inconvenience is a policy violation.
  • When your access changes through promotion, role change, or departure, your AI access is adjusted at the same time.
  • Shared or service-account AI access is prohibited without written CISO approval.

Default AI access by system. Variation from these defaults requires written approval from the CISO.

SystemDefault accessKey condition
FOSRead + draftNo automatic release of flights. A human reviews and executes all scheduling and dispatch actions.
Financial systemsRead + draftWrite access requires President and CFO written approval. No AI-initiated transactions.
HR and people systemsRead onlyAI may not modify compensation, titles, employment status, or performance records.
Code repositoriesAI-assistedHuman commit required. No autonomous merge or deploy.
Email and messagingDraft onlyNo automatic send. Sending requires explicit human action.
External-facing contentDraft onlyFull human review and approval before publication.
Customer and passenger dataScoped readLimited to approved fields. Governed by data classification and TSA SSI handling rules.
Identity and access managementRead onlyAI may not provision, modify, or revoke user access under any circumstances.
Payment and transaction systemsProhibitedNo access without explicit AI Steering Committee approval.
AI Policy Β§6.1Β§6.4
3
Connectors, Skills, and Plugins
How a tool gets extended, and who decides
β–Ό

Approved tools can be extended, and the three ways of doing it carry very different weight. Two of them change how a tool works. The third changes what it can reach, which makes it an access decision rather than a preference.

Skill
A set of instructions that changes how a tool performs a task, for example following a house format or a standard checklist. A skill grants no access to anything. It changes output, not reach.
Plugin
A bundle that can contain skills, tools, and connectors together. Treat a plugin as whatever the strongest thing inside it is: if it contains a connector, it is an access decision.
Connector
An integration that lets an AI tool reach into a system: a document store, a mailbox, a calendar, a code repository. This is the one that matters, because it changes what data the tool can see and sometimes what it can change.
Connectors are enabled by the CISO only, at the organization level. You cannot add one yourself, and you should not ask a colleague to work around it. The set of enabled connectors, and whether each is read-only or permitted to write, is recorded in the Approved Tool Registry entry for that tool and reviewed under §4.5.

Once a connector is enabled for the organization, you connect your own account to it. That is where the Non-Supersession Rule does its work: the tool sees what you are authorized to see in that system, and nothing more. Enabling a connector does not hand anyone access they did not already have.

Two consequences worth holding onto. A tool with a connector can read content you did not paste, so prompt hygiene applies to what the connector can reach, not only to what you type. And an AI tool reading from a connected system is reading whatever is there, including anything a colleague put in a shared folder without thinking about it.

If a task seems to need a connector that is not enabled, submit it through the Tool Intake form rather than looking for a workaround. Adding a connector is a material change to what an approved tool does, and it goes through the same review the tool itself did. AI Policy Β§6.4Β§6.1Β§4.5
4
Agentic AI Controls
No silent agents
β–Ό

An agentic system takes actions rather than producing content for you to review. That difference matters, because when the output is an action the mistake has already happened by the time you see it. Content can be corrected before it goes anywhere. An action cannot.

Every autonomous AI action is pre-authorized through a named Action Scope document approved by the AI Steering Committee. That document defines what the agent may do, which systems and data it may reach, the conditions it operates under, the maximum scope of any single action, and the escalation path when it hits a boundary.

Automatically Tier 3
Agentic capability is itself a Tier 3 criterion. The Action Scope document is submitted as part of that Tier 3 intake and follows the same 30 business day timeline.
Everything is logged
Each agentic action is recorded with timestamp, user, scope, the action taken, and the outcome. An unlogged agent is not an approved agent.
Rollback first
Rollback capability is required before write or execute permissions are granted, not added afterward. If an action cannot be undone, it does not get authorized.
A human can stop it
Multi-step workflows require a human interrupt, and the mechanism is documented and tested before deployment. Tested, not assumed.

Agentic systems may not initiate contact with anyone outside the Company, including customers, vendors, and regulators, without a human reviewing and approving each message.

An agentic action outside its Action Scope is a Category C incident and is addressed under the consequence framework, whether or not the action caused any harm. The scope is the authorization; acting outside it means acting without authorization. AI Policy Β§6.5Β§8.4
5
Personal Use and Company Seats
Where your own AI use ends and the Company's begins
β–Ό

Use AI freely in your personal life, on personal devices and personal accounts, for any purpose unrelated to Company business. No approval, oversight, or disclosure is required. That freedom ends where personal use touches organizational systems, data, or work product.

Four hard boundaries. These apply regardless of whose device or account is involved.
  1. Nothing unapproved on Company equipment. If it is not in the Approved Tool Registry, do not install it, sign into it, or open it on a Company laptop, phone, account, or network. This holds even when what you are doing is personal.
  2. No Company data in a personal account. Client information, passenger information, anything confidential: it does not go into your own AI account or into an unapproved tool. Your kitchen table counts the same as your desk.
  3. No Company work on a personal tool. Not drafts, not analysis, not code. Moving the finished output into an approved tool afterward does not fix it, because the data already left.
  4. Personal output is not Company work product. Something you made on your own account for your own purposes does not get submitted, forwarded, or folded into a Company deliverable.

If you are unsure whether a specific use qualifies as personal, treat it as organizational and apply the approval requirement.

Company-provisioned seats. If the Company pays for your individual seat, for example a company-provisioned Claude seat, occasional personal use is permitted provided it does not interfere with job performance. The account is Company property. The Company can access content created under it where there is a compliance, legal, or investigative need, so treat anything you enter there as Company records rather than private. Your own personal account is separate and is not covered by that. The seat may not be used for outside commercial purposes, including a side business, freelance work, or work for another employer, and access ends immediately on termination. AI Policy Β§6.6Β§6.7
6
Training and Recertification
What is required, and when
β–Ό

Both AI modules are completed before AI tool access is provisioned. There is no exception for seniority, prior experience, or time pressure.

RequirementDetail
Before accessBoth modules complete. Access is provisioned after, not before.
Passing score90 percent, so nine of ten. Three attempts, after which AI access is suspended until you pass.
AnnualRe-certification on both modules every year.
Role changeWithin 10 business days of a role change that affects AI access.
TriggeredAfter an AI-related incident, a significant policy change, or deployment of a new high-risk tool.
Non-completion of required training has its own row in the consequence framework: access suspended until completion, then a written warning, then escalation. The simplest way to avoid that is to finish the modules when they are assigned. AI Policy Β§10.1Β§10.3Β§11.4
7
Reporting
How and what to report
β–Ό

Reporting. Submit a safety report, the same way you would for any other safety event. Anonymous and confidential options are both available.

AI-related incidents fall into three categories:

Category A
Data breach or disclosure
An AI-related data breach, or organizational or client data disclosed to somewhere it should not be.
Category B
Hallucination-driven decision
A decision with material business, legal, or safety consequences that was made on the basis of AI output which turned out to be wrong.
Category C
Agent outside its scope
An agentic AI system took an action outside the boundaries set in its approved Action Scope document.
Report thisWhat happens
Shadow AI use, yours or a colleague'sTriaged by the CISO. During the amnesty window, no disciplinary consequence.
Suspected data exposure through an AI toolCategory A. Triaged by the CISO and Director of Safety within 1 business day.
A hallucination that drove a material decisionCategory B. Same channel and triage timeline.
An AI agent acting outside its authorized scopeCategory C. Addressed whether or not harm resulted.
A deepfake, AI fraud attempt, or AI phishingTriaged by the CISO. External Legal engaged where there is legal exposure.
Good-faith reporting is protected. Retaliation against a reporter is a policy violation. AI Policy Β§7.1Β§7.2Β§12.4
8
The Forms, and Where to Learn More
Five resources, and how to get better at this
β–Ό

Five resources exist to make all of this easy to act on. Each has its own page and QR code, posted in FOS under Compliance, Documents, Company, Other.

ResourceUse it when
Approved Tool Registry Before using any AI tool for Company work. Every employee is responsible for this check.
AI Tool Request Something you want is not on the registry. Any employee may submit.
AI Amnesty Disclosure You are already using something that is not on the registry. No consequence during the window.
Agentic AI Action Scope You are deploying AI that takes action on its own. Automatically Tier 3.
AI Policy Exception You need a time-limited exception. Caps at 90 days, renewable only by re-approval.
Two of the five matter to almost everyone. Check the registry before you use a tool. Disclose anything you are already using, while the window is open. The other three are there when you need them.

Ask Gold Aviation is the Company's own assistant, built in Claude with our manuals, procedures, and company context loaded in. It is subject to this policy like any other tool, so check the Approved Tool Registry for its current status and approved use cases before relying on it for Company work.

Getting better at this. Nothing in this policy discourages using AI well; the standard is that you own what it produces, and the better you are at prompting, the less there is to fix. Anthropic publishes free training at anthropic.skilljar.com. The AI Fluency track is written for general users rather than developers and is the right place to start. It is optional and it is not a substitute for this module.

Learning material from a vendor is guidance, not authorization. Where anything a course suggests conflicts with this policy or the registry, the policy governs. AI Policy Β§4.2Β§5.1Β§12.3
9
Pre-Release Checklist
Before any AI-assisted output leaves your hands
β–Ό

Everything in both modules reduces to this. Run it before anything AI-assisted goes anywhere.

CheckWhy
The tool is in the Approved Tool Registry, for this use caseApproval is per use case, not per tool.
Nothing prohibited went into the promptNo SSI, personal, health, payment, or personnel data, in any tool.
The output has been read in fullNot skimmed, not summarized. All of it.
Material facts and figures verifiedAgainst the source, not against the tool.
Edited into the Company's voiceAnd anything you cannot stand behind removed.
The minimum review standard for this output type has been metSome types need legal, numerical, or manager sign-off.
AI involvement disclosed where requiredRegulators, client deliverables, and material decisions.
You could defend it if questionedThat is the standard, and it is the last check for a reason.
If any line fails, the output is not ready. That is true under time pressure, and it is true when the tool was approved and the draft looks fine. AI Policy Β§1.1Β§7.1

Knowledge Check

Complete all nine sections above to unlock the assessment

Pass Score90%
πŸ”’

Complete all 9 content sections to unlock the assessment.