Allowed use
Define which assistants, repositories, data types, and task categories are approved.
AI coding assistant policy
This policy preview gives engineering leaders the decisions to make before AI-assisted delivery spreads across teams. The implementation-ready policy starter is included in the Starter Kit.
Policy decisions
Define which assistants, repositories, data types, and task categories are approved.
Set expectations for human review, verification, product acceptance, and release ownership.
Prevent unsafe handling of secrets, customer data, production actions, dependencies, and infrastructure.
The implementation-ready policy starter is part of the AIDLC Team Starter Kit.
Policy sections
List allowed assistants, account types, data boundaries, and repository access rules.
Define what developers may paste into tools and what must stay out of prompts.
Set which changes need product, engineering, security, QA, or operations approval.
Define what the team must record before AI-assisted changes ship.
FAQ
It should include approved use, prohibited use, data handling, review requirements, test expectations, security gates, dependency rules, and evidence requirements.
For material code, configuration, architecture, dependency, or release changes, disclosure helps reviewers understand what evidence to look for.
The human team owns the shipped result. Assistants generate candidate work, but people remain accountable for correctness, safety, compliance, and customer impact.
Related guides
Support the resource
Small donations help maintain free workflows, tutorials, references, and public learning material for product and engineering teams.