A practical Tessa AI policy should define what the assistant may do, what requires human review, which information it may use, and how employees can challenge or correct an output. The goal is not to approve every use of AI in the abstract. It is to create clear operating boundaries for workplace teams using AI to find information, summarize requests, identify patterns, and support decisions without transferring accountability to a tool.
This template is designed for workplace, facilities, employee experience, operations, and people leaders. Adapt the bracketed choices to your organization, then publish the final policy alongside your broader privacy, security, records-management, and acceptable-use policies.
Purpose: This policy governs the responsible use of Tessa AI for workplace operations, including workplace information discovery, request triage, operational analysis, employee support, and preparation of recommendations.
Operating principle: Tessa AI may assist people with workplace work, but it does not replace accountable judgment. A designated owner remains responsible for decisions, communications, approvals, and actions taken in the workplace environment.
The policy should be easy to understand in daily use. Employees should know when Tessa is appropriate, what they should avoid entering, and how to request human assistance. Administrators should be able to review whether the system is being used consistently with organizational policies.
Subject to the organization’s configured permissions and data controls, Tessa AI may be used to support tasks such as:
These uses are assistive. A Tessa response should be treated as a starting point for investigation or communication, not as evidence that a policy exception, access change, personnel action, or facilities intervention has been approved.
Human review is required before an AI-assisted output is used to make or communicate a consequential decision. Consequential decisions include changes that may affect an employee’s access, safety, privacy, accommodations, work location, assigned space, visitor access, or employment experience.
The responsible team must verify important facts, check the relevant policy, and confirm that the proposed action is within its authority. For example, Tessa may help summarize a pattern of workplace requests, but a workplace leader should determine whether the pattern warrants a policy change. Tessa may help draft a response, but the accountable owner should confirm that the response is accurate, appropriate, and consistent with employee commitments.
Each organization should name decision owners for common outputs:
Users may provide only the information needed for the approved workplace task. They should not enter sensitive personal information, confidential investigation details, credentials, security secrets, or unrelated employee records unless the organization has explicitly approved that use and configured appropriate controls.
Do not use Tessa as a substitute for a secure case-management system. Sensitive matters should be routed through the organization’s approved channel, especially when they involve health information, allegations, legal advice, disciplinary action, security incidents, or personal safety.
Users must not attempt to obtain information by asking Tessa to bypass permissions, infer restricted personal details, reveal another person’s private activity, or combine data for an unauthorized purpose. Access to a Tessa-assisted answer does not expand the user’s underlying authorization.
Escalate to the designated human owner rather than relying on an AI response when:
Escalation should be a normal service path, not a failure. The policy should identify where users can go, the information they should include, and who owns the response.
| Decision point | What to evaluate |
|---|---|
| Assist with routine information | Low-risk workplace information, process explanations, and draft summaries. Human review is useful but not always required before sharing. |
| Human review required | Operational patterns, draft employee communications, and recommendations that may influence a workplace action. An accountable owner verifies facts and approves the result. |
| Escalate to a specialist | Safety, privacy, accessibility, security, personnel, accommodation, investigation, or emergency matters. Route to the designated human team instead of relying on Tessa. |
Use the following matrix as a starting point for configuring guidance, training users, and reviewing proposed use cases.
For each proposed use case, document the task, intended users, data involved, expected benefit, human owner, approval requirement, and escalation route. Review the use case before launch and whenever the workflow, data source, permissions, or business purpose changes.
A lightweight review record can include:
Connect this review to the organization’s wider connected workplace management platform governance. A clear operating context helps teams distinguish an informational answer from an action that changes a booking, request, assignment, or workplace record.
Employees should be told when AI assistance is materially involved in a workplace service or communication, where that is required by organizational policy or applicable law. They should also have a practical way to ask questions, correct inaccurate information, or request human review.
Transparency does not require exposing technical details that would confuse users. It does require explaining the role of the tool, the responsible team, the types of information used, and the route for correction or escalation.
When Tessa helps draft an employee-facing answer, the sender remains responsible for its content. Communications should avoid presenting an unverified suggestion as a final policy, entitlement, or confirmed operational fact.
Administrators should monitor usage at an appropriate level to identify recurring errors, unsupported requests, permission problems, and opportunities to improve workplace guidance. Monitoring should follow applicable privacy, labor, and information-governance requirements. It should not become a hidden system for evaluating employees’ productivity or personal behavior unless separately approved for a lawful, clearly communicated purpose.
Training should cover approved uses, prohibited inputs, verification, escalation, and the difference between an answer and an authorized action. New users should practice with low-risk workplace questions before using AI assistance in more sensitive workflows.
Review this policy at least annually and after significant changes to Tessa, workplace systems, organizational policies, or applicable requirements. Incorporate lessons from employee feedback, corrections, security reviews, and operational incidents. Teams using workplace requests can use those correction and escalation patterns to identify where instructions or routing need improvement.
Before publishing the policy, confirm that:
No. Low-risk informational assistance may not need individual approval. Human review is required when an output informs a consequential decision, changes a workplace record, communicates a sensitive conclusion, or creates a commitment on behalf of the organization.
Tessa can support analysis and prepare recommendations, but the organization should retain decision authority with an accountable human owner. The policy should state which actions require approval and which roles may approve them.
Provide a clear human escalation route, such as a workplace operations queue or designated service owner. The request should capture the disputed information, the relevant context, and the action the employee needs reviewed.
Policy owner: [Name or team]
Approved by: [Role or committee]
Effective date: [Date]
Review date: [Date]
Related policies: [Privacy, security, acceptable use, records management, accessibility, and workplace policies]