Northstar EV Infrastructure
EV Infrastructure Workspace
Sarah Miller
Owner
Policies & Guardrails
Syntra DemoReview demo policies for AI usage, data handling, approvals, brand usage, and external delivery controls.
6
Demo Policies
AI usage, data handling, approval, brand, delivery, integration
5
Approval Rules
Across proposal, incentive, business case, brand, and writes
4
Blocked External Actions
Email, calendar, SharePoint, Smartsheet all blocked
0
External Sends
Zero external communications active in demo
0
Live Integrations
No M365, Smartsheet, or Copilot production connections
Policy Sections
6 Sections ->AI Usage Policy
Use approved workspace context only
AI workers operate within the current workspace scope; cross-workspace data must be explicit.
Do not send never-send fields to AI
Fields marked as sensitive, PII, or financial must be redacted before AI processing.
External LLMs disabled unless explicitly approved
Only Syntra approved models are used; external public LLM calls require admin approval.
Human review required before client-facing delivery
AI-generated content must be reviewed by a human before any client-facing delivery.
Data Handling Policy
Demo uses fictional data only
All demo data is fictional and seeded for demonstration purposes. No real client data is used.
Production requires approved data sources
Real production data must come from approved, authenticated sources with documented lineage.
Sensitive fields must be redacted or scoped
PII, financial, and regulated data fields must be scoped to authorized roles only.
Store only required metadata where possible
Minimize stored data to what is operationally required; avoid unnecessary retention.
Approval Policy
Human approval required before final proposal delivery
All proposals must pass human approval before client delivery or external sharing.
Incentive assumptions require approval
Funding estimates, incentive calculations, and rebate projections require sign-off.
Business case assumptions require approval
TCO models, ROI projections, and business case assumptions must be approved.
Brand/client logo usage requires approval
Company and client logos must be validated against approved brand assets before use.
External writes require approval
Any save, send, or write to external systems requires explicit human approval.
Brand Usage Policy
Company logo must come from approved brand assets
Logos used in proposals and decks must match the brand asset registry.
Client logo usage requires approval
Client logos require documented permission before inclusion in materials.
Templates must be approved before production use
PowerPoint and document templates must be reviewed and approved.
Case studies and disclaimers must be approved
All case studies, testimonials, and legal disclaimers require review.
External Delivery Policy
No automatic email send
Emails are never sent automatically; all outbound communication requires human review.
No automatic calendar event creation
Calendar events are never created automatically; must be human-initiated.
No automatic SharePoint final save
SharePoint document saves require explicit human approval.
No automatic Smartsheet writeback
Smartsheet data writes are disabled by default; must be manually approved.
No client delivery until approval
External delivery of any kind is blocked until all approval gates pass.
Integration Policy
Microsoft 365 connection requires tenant/admin approval
M365 Graph integration requires explicit tenant admin consent.
Smartsheet connection requires authorized access and column mapping
Smartsheet access must be authorized with proper column-level permissions.
Copilot action path must be verified
Copilot integration paths must be verified through admin settings before enablement.
Production writes are disabled by default
All integration write paths are disabled in demo and must be explicitly enabled for production.
Demo Safety
All policies are demo guardrails for professional consulting demonstration only. No real data, user emails, client tenants, or external integrations are active. External delivery paths are blocked. These policies demonstrate enterprise readiness without connecting to live systems.