Acceptable Use Policy
Use of Claude AI at Sunshine Bouquet
| Effective date: | 9/21/2026 |
| Policy owner: | Brian Stacy, Director of IT & Security |
| Approved by: | Bill McAllister, CIO |
| Applies to: | All Sunshine Bouquet personnel issued a Claude license |
| Review cycle: | Annually, or upon material change to Claude's admin controls or data terms |
1. Purpose
Sunshine Bouquet provides Claude, an AI assistant from Anthropic, to licensed employees to support their work. This policy sets the rules for using it responsibly, alongside our existing Acceptable Use and Information Security policies, which continue to apply in full. Where this policy is silent, the existing Acceptable Use Policy governs.
2. Scope
This policy applies to every employee and contractor issued a Sunshine Bouquet Claude license, across all locations, including U.S. and Colombia operations. It covers Claude accessed through the web, desktop, and mobile apps, and any connectors, integrations, or custom tools built on top of it.
Personal (Free, Pro, or Max) Claude accounts are not covered by this policy and must not be used for Sunshine Bouquet business, data, or communications. Different data terms apply to personal accounts, and IT has no visibility or control over them.
3. Approved Uses
Claude is approved for work that helps you do your job faster and better, including:
- Drafting, editing, and summarizing internal documents, emails, and reports
- Researching technical questions, vendor options, and industry best practices
- Writing, reviewing, and debugging code and scripts for internal tools
- Analyzing non-sensitive data sets, logs, and reports
- Creating presentations, training materials, and process documentation
- Using IT-approved connectors to reference data you already have access to (for example, your own Zendesk tickets or Azure DevOps work items)
4. Prohibited Uses
Do not enter the following into Claude, in any form, including pasted text, uploaded files, or screenshots, unless it is being handled through an IT-approved connector with equivalent access controls already in place:
Do not paste or upload: • Employee personal data: SSNs, dates of birth, home addresses, banking or payroll details, immigration or medical information • Financial account numbers, card numbers, or wire/banking credentials • Passwords, API keys, access tokens, certificates, or system credentials of any kind • Legal matters under privilege, active HR investigations, or unreleased M&A, financial, or executive information • Grower, farm, and production data (volumes, yields, site-level output, sourcing details) and customer or vendor contract terms • Anything you would not be comfortable seeing outside the company |
Additional prohibited uses:
- Connecting Claude to any internal system, database, or third-party service that has not been approved and configured by IT (see Section 6).
- Using Claude to make production changes to infrastructure, network configuration, security tools, or the corporate directory without the same change control and review your team already requires.
- Using Claude to generate content for external publication, legal filings, or regulatory submissions without human review and normal approval channels.
- Attempting to bypass connector permissions, approval prompts, or role-based access controls configured by IT.
- Sharing your Claude account or license with anyone else, including contractors without their own license.
5. Data Classification Quick Reference
If you are unsure whether something is safe to enter, treat it as Restricted and ask IT first.
| Classification | Examples | OK to use in Claude? |
| Public | Published marketing content, public job postings, press releases | Yes |
| Internal | Internal process docs, non-sensitive reports, general project notes | Yes |
| Confidential | Vendor pricing, internal financials, unreleased plans, source code for proprietary systems, grower/farm/production data (volumes, yields, site-level output, sourcing) | Only via an IT-approved connector, never pasted directly |
| Restricted | Employee PII, payment data, credentials, legal/HR matters, security incident details | No |
6. Connectors and Integrations
Claude can be connected to systems like Microsoft 365, Zendesk, and Azure DevOps to work with data you already have access to. This carries more risk than a normal chat, so it is centrally controlled:
- Only IT enables connectors at the organization level. Employees cannot self-connect an unapproved service.
- Write actions (creating, updating, or deleting records) require approval by default. Do not request that a specific write action be pre-approved for convenience without going through IT.
- If you have a business case for a new connector or broader access, submit it to IT for review rather than seeking a workaround.
- Report immediately if a connector appears to expose data you should not have access to, or behaves unexpectedly.
7. Account, Access, and Monitoring
- Access is provisioned and removed automatically through Entra, tied to your employment status and role.
- Sunshine Bouquet's Claude license operates under Anthropic's commercial terms, which do not use conversation content to train Anthropic's models. IT maintains the org's retention and audit log configuration; contact IT with questions about how long chat data is retained.
- IT has visibility into license usage, connector activity, and administrative audit logs for security and compliance purposes. This is the same posture we apply to email, file storage, and other business systems.
- Per-seat spend limits are configured by IT. Contact IT if you hit a limit that is blocking legitimate work rather than finding a workaround.
8. Reporting a Concern
If you accidentally enter Restricted or Confidential data, notice unexpected connector behavior, or suspect misuse of Claude, report it to IT immediately. Early reporting is not a disciplinary matter; failing to report is.
9. Enforcement
Violations of this policy are handled through the same process as violations of our existing Acceptable Use Policy, in partnership with Human Resources. Depending on severity, this may include a documented warning, mandatory retraining, suspension of Claude access, or further disciplinary action up to and including termination, consistent with standard HR policy.
10. Questions
Direct questions about this policy, connector requests, or data classification to the IT & Security team.
Acknowledgment: By using your Sunshine Bouquet Claude license, you confirm you have read and agree to follow this policy.
Comments
0 comments
Article is closed for comments.