Start with what the policy is for
Most small firms already have staff using AI before anyone writes a rule. Someone in accounts pastes a supplier dispute into a free chatbot. A project manager drafts a tender answer on a personal subscription at home. The policy exists to move that activity onto an account the business controls, to keep the wrong information out, and to make sure a person checks anything that leaves the building.
Write it for Claude specifically, not for AI in the abstract. Staff follow rules that mention the buttons they actually press: Projects, connectors, incognito chats, file uploads. A generic statement about responsible AI gives nobody an answer when they are halfway through a task and unsure whether a client spreadsheet can go in.
Before you draft, have the person who handles privacy questions in your business read the Privacy Commissioner's material on generative AI and the information privacy principles in the Privacy Act 2020. The public-sector generative AI guidance published through digital.govt.nz and MBIE's guidance for businesses are also worth an hour. They are written for New Zealand conditions, and your policy should be consistent with them. Treat this guide as the Claude-specific layer that sits on top of that reading, not as legal advice.
- One owner: a named person who answers questions and approves exceptions.
- One account rule: work happens in the business's Claude organisation, not in personal accounts.
- One data rule: a short list of what never goes in, and what needs care.
- One review rule: who checks output before it reaches a client, a regulator or a staff file.
Decide the account rule first
The account type changes the data terms, so settle it before anything else. Anthropic's consumer terms cover the Free, Pro and Max plans. Since the 2025 update, people on those plans choose whether their chats can be used to improve the models, and if they allow it, new and resumed chats can be kept for up to five years3. That choice belongs to the individual, not to you. Claude for Work, the API and the government and education offerings are outside those consumer terms3.
On the Team and Enterprise plans, Anthropic describes your business as the controller of the data your users submit and itself as the processor, acting on your instructions2. It also states that it does not use data from its commercial products to train models unless the customer joins its Development Partner Program2. That is the main reason a business account is the default recommendation for any team handling client material.
The same help article spells out something your staff should hear from you, not discover later. The Primary Owner of a Team or Enterprise organisation can request exports of user data, which may include conversations and uploaded files, and can remove a person's access1. Put a plain sentence in the policy saying that work chats belong to the business and may be reviewed. It avoids surprises and supports honest use.
Team plans need at least two members and support up to 150 seats, after which Anthropic points organisations to Enterprise13. For most firms in the five-to-a-few-hundred range, Team is where the policy will live.
- Rule to write: use only your work Claude account for work. Do not use Free, Pro or Max accounts for client or staff information.
- Rule to write: chats, projects and files in the work account are business records and can be exported by the owner.
- Rule to write: if you used a personal account for work before this policy, tell the policy owner so it can be dealt with.
Write the data rules with real NZ examples
Three tiers work for most small businesses. Keep the wording concrete, because staff will skim it under time pressure.
Green is material you would happily email to a stranger: published web copy, your own blank templates, generic questions about Excel formulas or tax deadlines. Amber is normal client and business information that Claude can help with inside the work account, provided the person minimises it first: a client's job notes, a supplier contract, an internal procedure. Red is material that stays out unless the policy owner has approved a specific workflow: IRD numbers, bank account details, passwords, health information, disciplinary records, anything covered by a confidentiality undertaking, and full customer databases.
Anthropic's own guidance for consumer users makes a similar point, recommending care with financial details, health records, passwords and confidential business documents14. A business policy should be stricter than that, not looser.
Be clear about incognito chats, because staff often assume they are a privacy switch. In Claude, an incognito chat is not saved to chat history or memory, but on Team and Enterprise plans it is kept for at least 30 days for safety and appears in organisational data exports7. It is useful for a one-off question that should not shape memory. It does not make red-tier data acceptable.
- Example, Hamilton accounting practice: a staff member wants Claude to tidy a client's year-end notes. Amber. Remove the IRD number and bank details, keep the figures and narrative.
- Example, Dunedin physiotherapy clinic: a practice manager wants a template reply for appointment changes. Green, as long as no patient names or conditions go in.
- Example, Napier orchard contractor: a supervisor wants a summary of a worker's disciplinary history. Red. Not without a documented, approved process.
Human review, and the uses that need more
Every policy needs a review rule, because Claude can be wrong in a convincing way. Anthropic's help centre says Claude can produce incorrect or misleading answers, including quotes that look authoritative, and that people should not rely on it as a single source of truth for high-stakes matters8. The practical rule is that the person who sends the output owns it, and they must check facts, figures and quotations against the source.
Some uses need a named professional, not just a careful staff member. Anthropic's Usage Policy lists high-risk use cases, including legal interpretation, healthcare decisions, insurance claims and underwriting, financial eligibility, and decisions about employing people or screening CVs4. For those, it requires a qualified professional to review the content or decision before it is finalised, and, where output goes directly to consumers, disclosure that AI was involved4.
Translate that into your own context. An Auckland immigration adviser using Claude to draft a client letter needs the licensed adviser to sign off. A Tauranga property manager using Claude to compare tenant applications is in the housing category and needs a person making the decision, with the reasons recorded. A recruitment step that ranks CVs automatically is the clearest example of a use to avoid until you have taken advice.
- Rule to write: you are responsible for anything Claude helped you write. Check it before it leaves the business.
- Rule to write: Claude does not make decisions about hiring, pay, discipline, tenancy, credit or client advice. A qualified person does, and records why.
- Rule to write: if a customer reads Claude output directly, tell them AI was used.
Make the settings match the policy
A policy that the software contradicts will not survive the first busy week. On Team and Enterprise plans, the owner roles control most of what matters. Owners and the Primary Owner can enable integrations and capabilities, turn project sharing on or off, and manage membership, while the data export request sits with the Primary Owner9.
Organisation instructions are the most useful bridge between the document and daily use. Owners can set instructions that Claude follows in every conversation across the organisation, up to 3,000 characters, under Organization settings, then Organization and access5. Anthropic notes that changes can take up to an hour to apply and that organisation instructions win when they conflict with a user's own5. Use them for reminders such as writing in New Zealand English, never including customer account numbers in output, and pointing HR questions to the right person.
Connectors need a deliberate decision. On Team and Enterprise, an owner must enable each connector before staff can use it, and each person then signs in with their own account, so Claude only reaches what that person can already reach6. Owners can also restrict actions, for example letting Claude read email but not send it, or read Google Drive files without editing them6. Start read-only.
Check three other settings. Project sharing and public projects are both on by default, and can be turned off under Organization settings, then Data and privacy10. Code execution and file creation are on by default for Team organisations, with network access limited to package managers, and an owner can change this under Organization settings, then Capabilities11. Finally, plan for leavers: when someone is removed, other members lose access to that person's private projects and chats, although the Primary Owner's exports still include them12.
A template outline you can fill in
Keep each heading to a short paragraph or a few bullets. If a section runs past half a page, it is probably procedure, and belongs in a Project or a checklist instead of the policy.
- Purpose and scope: why the business uses Claude, which staff and contractors the policy covers, and that it applies on any device.
- Owner and contacts: the named policy owner, who approves exceptions, and who to tell if something goes wrong.
- Approved tool and accounts: the Claude plan in use, the rule against personal accounts for work, and how people get a seat.
- Information rules: green, amber and red tiers with three local examples each, plus a reminder that incognito is not a privacy control.
- Approved uses: the tasks the business has tested and wants people to use Claude for.
- Uses needing approval or a professional: legal, health, finance, employment, housing and anything that reaches customers unedited.
- Review and disclosure: who checks output, how facts are verified, and when customers are told AI helped.
- Connectors, Projects and sharing: which connectors are on, read or write, and who may share a Project with the whole organisation.
- Records and access: that work chats are business records, can be exported, and are kept according to your normal retention practice.
- Mistakes and incidents: what to do if red-tier data goes in or a wrong answer reaches a client, and that early reporting is expected, not punished.
- Training and review date: the minimum training before getting a seat, and when the policy is next reviewed.
Introduce it properly
A policy that arrives by email on a Friday changes nothing. Walk the team through it in a short meeting, show the settings that enforce it, and invite questions. Where Claude will change how people do their jobs, workloads or monitoring, talk to your employment adviser about your good-faith obligations under the Employment Relations Act 2000 before you finalise it, and run any wellbeing concerns through your usual health and safety process.
Review the policy after the first month and then twice a year. Claude's features change often, and settings such as memory, connectors and organisation instructions have all been added or reworked in the past year. A dated review line at the bottom keeps the document honest.