Rubric
Contents — domains, guide and mocks

Appropriate and inappropriate use

CCAO-F 6.115 min read · checked 21 September 2026

Task statementIdentify appropriate and inappropriate use cases

The three gates

Ask in this order

  1. 1 · Permitted?Does the Usage Policy allow this at all?
  2. 2 · Suited?Is this the kind of work Claude does well?
  3. 3 · Controlled?Who reviews it, and is AI use disclosed?
Work down the stack. A task must clear all three; the gate it fails at tells you whether to abandon it, reshape it, or simply add a reviewer.

Gate 1 — is it permitted at all?

Anthropic publishes a Usage Policy that applies to everyone using Claude, on every plan. Its first part, the Universal Usage Standards, is a list of things nobody may do with Claude. It is broader than most people expect and worth reading once end to end, but the themes are recognisable: attacking computer systems or critical infrastructure, developing weapons, generating child sexual abuse material, creating fraudulent or deceptive content such as phishing and fake documents, impersonating a real human being, interfering with elections, and promoting self-harm or violence.

Two entries in that list catch ordinary office workers out. The policy prohibits compiling personal data about people without a proper basis, which rules out the “find me everything about this named individual” research request. And it names criminal-justice applications — parole and sentencing decisions, predictive policing, surveillance and emotion recognition — as off limits, which matters to anyone in the public sector.

Gate 2 — the high-risk middle ground

The Usage Policy has a second part, High-Risk Use Case Requirements, that covers uses affecting a person’s rights, safety, livelihood or access to essential services. The named domains are legal advice and decisions with legal consequences, healthcare and mental-health guidance, insurance underwriting and claims, financial decisions such as lending and investment advice, employment decisions including résumé screening, housing eligibility, academic testing and admissions, and automated journalistic or media content.

These are not forbidden. They carry two standing conditions. Human-in-the-loop: a qualified professional reviews the output before it is acted on. Disclosure: where the output reaches a consumer or member of the public, they are told that AI was involved — the policy asks for this at a minimum at the start of each session. A separate guideline applies the same logic to consumer-facing chatbots, which must tell people they are talking to an AI rather than a person.

Which gate did it fail?

The task feels risky. Why?
  • On the prohibited list
    Do not use ClaudeNo configuration makes it allowed
  • High-risk domain
    Add expert reviewQualified reviewer plus disclosure to the person affected
  • Claude cannot know it
    Supply the sourceAttach the document rather than asking from memory
  • Merely unfamiliar
    Proceed and verifyNormal checking, covered in 2.4
The action depends on the gate. Only the first gate ends in “don’t”; the others end in “reshape” or “add a reviewer”.

Gate 3 — is Claude suited to it?

Permission is not fitness. Anthropic’s own help centre is blunt that Claude can hallucinate: it can produce fabricated quotations, and it can be confidently wrong about recent events because its training data has a cutoff. The guidance is to scrutinise high-stakes advice rather than rely on it, and, when Claude has searched the web, to open the cited pages and read them in their original context.

That gives a practical test for fit. Ask where the facts in the answer are going to come from. If they come from a document you attached, a connector you configured, or the text of the conversation itself, Claude is on solid ground — it is reading, summarising, restructuring, drafting. If they have to come from Claude’s memory of the world — a policy number, a price, a regulation, last quarter’s figures, whether a client is still under contract — you are asking for trouble, and the fix is almost always to supply the source rather than to prompt harder.

TaskWhere the facts come fromVerdict
Summarise this 40-page supplier contractThe attached documentGood fit
Rewrite this rejection letter in plainer EnglishThe letter you wroteGood fit
Draft interview questions for this job descriptionThe description, plus general craftGood fit
What does our refund policy say?Claude’s memory — unless you attach itAttach the policy
Which of these 200 applicants should we interview?A high-risk employment decisionHuman decides; disclose
Find everything about this named private individualCompiling personal dataNot permitted

Reshaping a high-risk request

Asks Claude to decidetext

Here are 340 CVs.
Tell me the best 12
candidates for the
seasonal supervisor
role and rank them.

Asks Claude for evidencetext

Attached: the approved
scoring rubric and one
application.

For each of the five
criteria, quote the
words in the application
that bear on it. If the
application says nothing
about a criterion, write
"no evidence". Do not
score or rank.
Same underlying job, same person doing it. The second version names the decision-maker, supplies the source and asks for evidence rather than a verdict.

Writing it down before you need it

Judgement made case by case does not survive a busy week. Teams that use Claude well keep a short written list with three columns — green, amber, red — and put real examples in each, not abstractions. Green is work that goes ahead unsupervised: internal drafting, summarising documents you already have, reformatting, brainstorming. Amber is work that goes ahead with a named reviewer: anything customer-facing, anything quoting a figure, anything in a high-risk domain. Red is the short list of things nobody does: the Usage Policy prohibitions plus whatever your own sector adds.

A team’s use-case list, checked

  • Passes: Summarise a supplier contract we holdGreen — source attached, internal use
  • Passes: Draft the weekly team update from my notesGreen — no external facts asserted
  • Check: Write the customer-facing outage noticeAmber — comms lead signs off before it posts
  • Check: Explain a declined claim to a policyholderAmber — high-risk; adjuster decides, clauses checked
  • Fails: Score job applicants and pick the shortlistReshape — human decides; disclose AI involvement
  • Missing: Build a profile of a named private individualRed — compiling personal data, not permitted
Each line is a real task somebody wanted to do. The verdict column is what makes the list useful — an abstract policy nobody can apply is worse than three worked examples.

Anthropic does its own work on the other side of this line: it tests policies with outside domain experts, runs classifiers that detect violations in real time, and evaluates models for bias before release. None of that removes your responsibility for the particular task in front of you — the safeguards are built for harm at population scale, not for whether this letter to this policyholder is accurate. Data sensitivity and the privacy questions that sit alongside these gates are covered in 6.2; your own employer’s rules are 6.3.

Traps the wrong answers are built from

Tempting but wrongDo this instead
Refusing any task that sounds sensitiveCheck which gate it fails. Most high-risk tasks are permitted with a qualified reviewer and disclosure.
Treating a permitted task as automatically a good fitAsk where the facts will come from; if from Claude’s memory, supply the source instead.
Using AI in a high-risk domain without telling the affected personDisclose AI involvement to consumers, at minimum at the start of each session.
Asking Claude for the verdict in a legal, medical, lending or hiring decisionAsk for structured evidence against criteria a human set, and let the qualified person decide.
Keeping the rules in one person’s headWrite a green/amber/red list with real examples your team recognises.

You should now be able to

  • Sort a proposed task into prohibited, high-risk-with-conditions, or ordinary use.
  • Name the two standing conditions the Usage Policy attaches to high-risk uses.
  • Spot the domains — legal, health, insurance, finance, employment, housing, academic, media — that trigger those conditions.
  • Reshape a request so a qualified human makes the decision and Claude does the drafting or extraction.
  • Judge fitness by asking where the facts in the answer will come from.

Practice questions

Original questions written for this lesson, in the exam’s style. Answer first, then open the reasoning — every option is explained, including why the wrong ones are tempting.

  1. Question 1

    A mortgage adviser at a building society wants to speed up applications. She proposes pasting each applicant’s income and credit summary into Claude and asking whether the application should be approved, then sending the answer to underwriting.

    What is the best assessment of this proposal?

    1. AAcceptable, because underwriting still sees the file afterwards.
    2. BProhibited outright by the Usage Policy, as lending is on the banned list.
    3. CHigh-risk: allowed only with a qualified human deciding and AI use disclosed to the applicant.
    4. DFine as long as she removes the applicant’s name before pasting the details.
    Show answer and reasoning
    1. AIncorrect. A later handoff is not the same as a qualified professional reviewing the AI output as the basis of the decision, and nothing here discloses AI involvement to the applicant.
    2. BIncorrect. Lending decisions sit in the High-Risk Use Case Requirements, not the prohibited list — they are permitted with conditions rather than forbidden.
    3. CCorrect. Loan approval is a named high-risk use, which carries standing human-in-the-loop and disclosure conditions rather than a ban.
    4. DIncorrect. Removing a name addresses a data question but leaves the lending decision itself being made by an AI without the required safeguards.
  2. Question 2

    An operations manager asks Claude, in a plain chat with nothing attached, what his company’s supplier payment terms are. Claude answers confidently with a 45-day figure. The real terms are 30 days.

    Which gate did this task fail, and what is the fix?

    1. AGate 1, permission — internal finance data is off limits.
    2. BGate 3, fitness — the answer had no source, so attach the supplier agreement and ask again.
    3. CNo gate — Claude was simply out of date and a newer model would know.
    4. DGate 2, high-risk — payment terms are a financial decision.
    Show answer and reasoning
    1. AIncorrect. Nothing in the Usage Policy prohibits asking about your own company’s payment terms; the failure is elsewhere.
    2. BCorrect. The facts had to come from Claude’s memory of the world, which is where fabrication happens; supplying the document moves the answer onto ground that can be checked.
    3. CIncorrect. No model has ever been trained on one company’s private contract terms, so a model upgrade would not help.
    4. DIncorrect. The high-risk financial category concerns decisions such as lending and investment advice affecting a person, not a factual lookup of your own terms.
  3. Question 3

    A hospital communications team wants a public-facing chatbot on its website that answers questions about clinic opening times, parking and how to book, using content from the hospital’s own pages.

    Which two requirements apply most directly to this deployment? (Select 2.)

    1. AThe chatbot must disclose to users that they are interacting with an AI.
    2. BIts answers must be grounded in the hospital’s own published content rather than the model’s general knowledge.
    3. CThe deployment is prohibited because healthcare is a banned domain.
    4. DEvery answer must be reviewed by a clinician before it is shown.
    5. EThe hospital must obtain written consent from each visitor before they use it.
    Show answer and reasoning
    1. ACorrect. Consumer-facing chatbots are covered by a specific guideline requiring users be told they are talking to an AI rather than a person.
    2. BCorrect. The facts are institution-specific, so without the source attached the assistant is guessing — the classic fitness failure.
    3. CIncorrect. Healthcare appears in the high-risk requirements, not the prohibited list, and logistical questions are not medical guidance in any case.
    4. DIncorrect. Clinician review belongs to medical guidance; opening times and parking are not clinical decisions and such a rule would make a chatbot impossible.
    5. EIncorrect. No such requirement is stated; the relevant obligation is disclosure of AI involvement, not signed consent.
  4. Question 4

    Your team is writing its green/amber/red use-case list. Which entry is correctly placed?

    1. AAmber: rewriting an internal meeting summary you dictated.
    2. BGreen: answering customer emails automatically without anyone reading them.
    3. CRed: compiling a dossier on a named private individual from public sources.
    4. DRed: drafting a press release from an approved fact sheet.
    Show answer and reasoning
    1. AIncorrect. This asserts no external facts and reaches no one outside the team, so holding it for review just adds friction to green work.
    2. BIncorrect. Anything customer-facing that asserts facts belongs in amber with a named reviewer, however routine the emails look.
    3. CCorrect. Compiling personal data about someone without a proper basis is a Usage Policy prohibition, so no reviewer or configuration makes it acceptable.
    4. DIncorrect. Media content generation is high-risk rather than prohibited, and with an approved source and sign-off this is ordinary amber work.

Sources

Drafted with AI assistance and checked against the sources above; expert review is in progress. Spotted an error? Tell us and it gets fixed, dated and listed on how this is written.