Which rules apply, and in what order
Narrowest wins
- Law and regulationData protection, sector rules, contracts with clients
- Anthropic Usage PolicyApplies to every user on every plan
- Your employer’s AI policyApproved accounts, approved data, required review
- Organization instructionsOwners set standing guidance for every chat
- Project and personal setupInstructions and preferences for your own work
Who can set what
On Team and Enterprise plans, governance is not an abstraction — it is a set of named roles with named controls. Owners and Primary Owners can set organization instructions: standing guidance, up to 3,000 characters, that Claude follows across every conversation in the organisation. They live in organisation settings, under organisation and access. Where they conflict with an individual user’s own instructions, Claude favours the organisation’s; where the organisation is silent, the individual’s still apply.
On Enterprise, a Primary Owner or Owner can also configure custom data retention. By default data is retained indefinitely unless a period is set; the minimum is thirty days and longer periods are chosen in thirty-day increments. Shortening a period schedules everything outside it for permanent, irreversible deletion, carried out by a daily background process that runs at midnight UTC and can take several days to work through. Retention actions are recorded in audit logs. And across Team and Enterprise, the Primary Owner can request data exports that may include conversations, uploaded files and usage patterns, and can remove a user’s access.
| Control | Who sets it | What it actually does |
|---|---|---|
| Organization instructions | Owner / Primary Owner, Team and Enterprise | Standing guidance in every chat, up to 3,000 characters |
| Custom data retention | Owner / Primary Owner, Enterprise | Deletes data past a set period; minimum 30 days |
| Data exports | Primary Owner | Produces conversations, uploaded files and usage patterns |
| Audit logs | Organisation administrators | Record retention changes and deletion events |
| Removing access | Primary Owner | Ends a user’s access to the work account |
| Incognito chat | Any user, any plan | Skips history, memory and training — not an exemption from policy |
What a usable AI policy actually says
Most policies fail not because they are wrong but because they are unreadable. A policy people follow answers six questions in language they recognise. Which accounts may be used — almost always “the company Team or Enterprise account, never a personal one”. Which data may go in, by classification rather than by example. Which tasks need a named human reviewer before the output leaves the building. When AI involvement must be disclosed to a customer, candidate or patient. What has to be recorded, and where. And who to ask when the policy does not cover the case in front of you.
That last question is the one most policies omit and the one staff need most. A rule with no escalation route turns every unanticipated situation into a private judgement call, made at speed by whoever is under deadline pressure. Naming a person — a data owner, a line manager, a compliance contact — costs one line and prevents most of the quiet workarounds.
A policy page that gets followed
Unusabletext
AI Usage Policy
Employees must use AI
tools responsibly and
in line with company
values.
Confidential data must
be handled with care.
Outputs should be
checked for accuracy.Usabletext
AI Usage Policy
1. Company Claude
account only. Never a
personal account.
2. No customer names,
account numbers or
health data in prompts.
3. Anything sent to a
customer: named
reviewer signs off.
4. Note in the file that
AI was used.
5. Not covered? Ask
Priya, the Data Owner.Configured guardrails and the gap they leave
There is a real difference between a rule that is written down, a rule that is configured, and a rule that is enforced. Organization instructions are guidance Claude follows; the documentation is explicit that they are not a way to override safety guidelines, and equally they are not a technical barrier that makes a forbidden action impossible. Retention settings genuinely delete data. Data exports and audit logs genuinely create visibility. Nothing in the product stops a determined person pasting something they should not.
That gap is why governance standards pair configuration with two human things: training, so people know the rule, and review, so a second pair of eyes sees output before it matters. Deciding which outputs need that second pair of eyes is covered in 2.4; the judgement about which tasks belong to Claude at all is 6.1.
The third human thing is the record. Governance standards, in every field, come down to being able to show afterwards what was done and why — the same accountability idea the data-protection principles state directly. In practice this is modest: a line in the case file, the engagement record or the ticket saying a draft was AI-assisted and who reviewed it. It costs seconds, it is the first thing an auditor or a complaining customer asks for, and it is the part teams skip first because nothing breaks when they do.
A governance review, item by item
- Passes: Work happens on the organisation’s account, not personal onesTeam plan in place; personal use discouraged in writing
- Passes: Organization instructions carry the two rules that matter mostNo tenant identifiers; review before sending
- Check: A retention period is set deliberatelyEnterprise default is indefinite until someone chooses
- Fails: Staff know who to ask when the policy is silentNo named escalation contact anywhere in the document
- Missing: Use of AI is recorded where the work is recordedNothing in case files says a draft was AI-assisted
- Fails: New joiners are told the rules in inductionPolicy circulated once by email, eight months ago
Traps the wrong answers are built from
| Tempting but wrong | Do this instead |
|---|---|
| Using a personal account for work because the company has not provided one | Raise the gap; work under the organisation’s agreement, where the employer is the controller. |
| Assuming an incognito chat puts work outside company policy | Policy applies to the task, not the chat mode, and work-plan incognito chats still appear in exports. |
| Writing a policy of principles with no named contact | Answer six concrete questions and name who to ask when it is silent. |
| Treating organization instructions as enforcement | Treat them as a default that prevents accidents, backed by training and review. |
| Leaving Enterprise retention on its default and calling it a decision | Choose a period deliberately; the default is indefinite retention until someone sets one. |
You should now be able to
- Order the rules that apply to a work task and identify which one governs.
- Name the administrative controls available to Owners and Primary Owners, and what each does.
- Judge whether an AI policy is usable by testing it against six concrete questions.
- Recognise shadow AI as a supply problem and describe the sanctioned-tool response.
- Distinguish a rule that is written, a rule that is configured, and a rule that is enforced.