Northstar EV Infrastructure

EV Infrastructure Workspace

Policies & Guardrails

Syntra Demo

Review demo policies for AI usage, data handling, approvals, brand usage, and external delivery controls.

6

Demo Policies

AI usage, data handling, approval, brand, delivery, integration

5

Approval Rules

Across proposal, incentive, business case, brand, and writes

4

Blocked External Actions

Email, calendar, SharePoint, Smartsheet all blocked

0

External Sends

Zero external communications active in demo

0

Live Integrations

No M365, Smartsheet, or Copilot production connections

View PermissionsView Audit TrailView Integration ConfigView Production Readiness

Policy Sections

6 Sections ->

AI Usage Policy

Use approved workspace context only

AI workers operate within the current workspace scope; cross-workspace data must be explicit.

Do not send never-send fields to AI

Fields marked as sensitive, PII, or financial must be redacted before AI processing.

External LLMs disabled unless explicitly approved

Only Syntra approved models are used; external public LLM calls require admin approval.

Human review required before client-facing delivery

AI-generated content must be reviewed by a human before any client-facing delivery.

Data Handling Policy

Demo uses fictional data only

All demo data is fictional and seeded for demonstration purposes. No real client data is used.

Production requires approved data sources

Real production data must come from approved, authenticated sources with documented lineage.

Sensitive fields must be redacted or scoped

PII, financial, and regulated data fields must be scoped to authorized roles only.

Store only required metadata where possible

Minimize stored data to what is operationally required; avoid unnecessary retention.

Approval Policy

Human approval required before final proposal delivery

All proposals must pass human approval before client delivery or external sharing.

Incentive assumptions require approval

Funding estimates, incentive calculations, and rebate projections require sign-off.

Business case assumptions require approval

TCO models, ROI projections, and business case assumptions must be approved.

Brand/client logo usage requires approval

Company and client logos must be validated against approved brand assets before use.

External writes require approval

Any save, send, or write to external systems requires explicit human approval.

Brand Usage Policy

Company logo must come from approved brand assets

Logos used in proposals and decks must match the brand asset registry.

Client logo usage requires approval

Client logos require documented permission before inclusion in materials.

Templates must be approved before production use

PowerPoint and document templates must be reviewed and approved.

Case studies and disclaimers must be approved

All case studies, testimonials, and legal disclaimers require review.

External Delivery Policy

No automatic email send

Emails are never sent automatically; all outbound communication requires human review.

No automatic calendar event creation

Calendar events are never created automatically; must be human-initiated.

No automatic SharePoint final save

SharePoint document saves require explicit human approval.

No automatic Smartsheet writeback

Smartsheet data writes are disabled by default; must be manually approved.

No client delivery until approval

External delivery of any kind is blocked until all approval gates pass.

Integration Policy

Microsoft 365 connection requires tenant/admin approval

M365 Graph integration requires explicit tenant admin consent.

Smartsheet connection requires authorized access and column mapping

Smartsheet access must be authorized with proper column-level permissions.

Copilot action path must be verified

Copilot integration paths must be verified through admin settings before enablement.

Production writes are disabled by default

All integration write paths are disabled in demo and must be explicitly enabled for production.

Demo Safety

All policies are demo guardrails for professional consulting demonstration only. No real data, user emails, client tenants, or external integrations are active. External delivery paths are blocked. These policies demonstrate enterprise readiness without connecting to live systems.