Resources · Policy
A one-page AI coding policy you can drop into Confluence tonight.
Approved tools, secrets, senior PR review, PHI, and no production data in prompts. Written so a staff engineer could enforce it — not a slogan.
Most “AI policies” are a Slack thread
Teams approve Copilot in a meeting, then discover Cursor agents, secrets in prompts, and PHI adjacent to autocomplete. A usable policy is one page: what is allowed, who reviews, what never enters a model context, and that client source stays in client environments. This generator drafts that page from a short questionnaire.
Who this is for
- Engineering leaders who need language before the next security questionnaire.
- Platform and DevEx owners rolling out Copilot or Cursor without a written review bar.
- Compliance partners who want something tighter than “human in the loop.”
What you get
- A Markdown policy covering tools, languages, secrets, PR review, PHI, and production data in prompts.
- Maxiom-flavored defaults: senior review on sensitive paths; client code stays put.
- Copy or print. Edit in Confluence. It is a draft, not a signed control.
Frequently asked questions
What does the AI coding policy generator produce?
A one-page Markdown policy you can paste into Confluence or a staff handbook. It covers approved tools, secrets, pull-request review, PHI, and a hard rule against production data in prompts — written in Maxiom’s voice: senior review, client code stays put.
Is this a substitute for platform governance?
No. A policy page is not evidence that Origin, Copilot admin, or Claude auto mode matches the words. For the toolchain itself, see AI coding platform governance.
Do you train on the answers?
Answers stay in your browser except the work-email gate (same HubSpot pattern as the checklist). We never ask you to paste source. Client code stays in your environment.
Who is this for?
Engineering leaders who rolled out Copilot, Cursor, or Claude Code and still have a Slack-thread policy. Legal and security can review the draft; they should not be the people inventing language about PR review seniority.
Can we edit the output?
Yes. It is Markdown. Change names, add repos, tighten PHI language. The generator is a starting draft, not a signed control.
Does the policy claim human-in-the-loop is enough?
No. The draft requires named seniority on sensitive paths and says a process sentence is not a findings packet. That gap is explained in why human-in-the-loop is not evidence.
What about PHI and healthcare teams?
If you handle PHI, the draft forbids it in prompts and logs unless a BAA and minimum-necessary design say otherwise. Dedicated HealthTech work lives at Maxiom Labs. Pair with the HIPAA minimum-necessary mapper for a feature-level pass.
Why the work-email gate?
Same pattern as the AI Code Risk Checklist. Unlock once per browser session, then generate and export. No second CRM.
How do we enforce this?
Write it down, then inspect. Enforcement is review bars, admin defaults, and occasional independent audit — not a PDF in a shared drive. AI code oversight is the retainer when merges keep coming.
Launch
Launch the generator
Sign in with a work email, then run the tool in this page. Client code stays in your environment.
Work email to continue
Unlock AI coding policy generator
Same gate as the AI Code Risk Checklist. Unlock once per browser session to use or export. Client code stays in your environment — this tool never asks for a repository.
- Questionnaire only — no source upload
- Print or save a one-pager from the browser
- Unlocks the other Resources tools in this session
Related services & resources
