# Customer actions & communications: enterprise AI policy pack

Let agents research, draft and resolve routine work while requiring accountable review for broad communications, account-impacting changes and commercial commitments.

Implementation guidance, not executable Tracelet configuration or legal advice. Tool names identify places where the control may apply; they do not claim shipped connector coverage. Confirm actual tool/action coverage and enforce destination permissions. Replace example thresholds, IDs and approval windows with your approved values.

## Control scope

- Protected assets: Customer accounts, cases, entitlements, CRM records, audiences and public content
- Consequential actions: Cross-tenant lookup, suspension/deletion, bulk send, publication, discount and commitment
- Applicable systems: CRM, support, email, CMS, social, messaging and contract platforms
- Context to resolve: Resolve operator, customer/tenant, assigned case, target account, recipient snapshot, exact content, channel, authority and cumulative value.
- Enforcement boundary: Use tenant-aware APIs, least-privileged sending identities, native publish roles and commercial approval workflows. A reviewed draft is not permission to send or commit.

## Owners

Customer operations owner + communications or commercial owner

## Configure first

- Customer/tenant boundaries, assigned cases, account owners and authorised support actions
- External channels, audience-size thresholds, sending identities and approved content versions
- Delegated discount, credit, entitlement and account-lifecycle authority

## Shared decision baseline

### Resolve the real target

Decide on immutable IDs and effective context: principal, tenant/account, environment, resource, data classification and destination. Names and local profiles are hints, not authority.

### Fail closed on consequential ambiguity

If the target, blast radius, tenant or data classification cannot be resolved, hold the action. Do not treat missing metadata as non-production or low risk.

### Bind approval to the exact action

An approval covers the actor, operation, target set, content or artifact digest, value and expiry. Material changes invalidate it; the requester cannot approve their own action.

### Keep an evidence-grade decision record

Record resolved context, policy version, matched rule, decision, approver and downstream result. Minimise captured sensitive content and protect the record from the acting identity.

## Policies

### CA-01: Review bulk external sends and public publication

- Severity: High
- Decision: Require approval
- Owner: Communications or campaign owner

#### Policy statement

Hold production email/SMS sends, external-channel posts and public publication when they exceed the configured audience threshold or use a company publishing identity.

#### Covered operations

- Send or schedule campaign/broadcast
- Publish or schedule CMS/social content
- Post to public or external shared channel
- Resend, change segment or swap content after approval

#### Evaluation rules

- Resolve recipient snapshot, count, customer segment, exclusions, sender, channel, exact content/attachments and schedule.
- Approval binds to content and recipient digests plus sending identity; draft approval is not send approval.
- Aggregate split sends and require new approval for materially changed content, audience or timing.

#### Example decisions (illustrative; do not run against live systems)

- **Mailchimp:** `Send campaign launch-2026 to 180,000 contacts`. Hold for campaign-owner approval.
- **WordPress:** `Change an approved draft to status=publish after editing claims`. Hold again.

#### Applicable tools and systems

- Mailchimp
- HubSpot
- Salesforce Marketing Cloud
- Gmail / Microsoft 365
- Twilio
- WordPress / Contentful
- Slack / Teams
- Social platforms

#### Enforcement

Separate drafting from sending/publishing credentials. Gate the native send/publish operation and verify audience plus content immediately before execution.

#### Exception / approval

Approval covers exact content, audience snapshot, channel, sender and schedule with a short expiry.

#### Test fixtures

- Should remain permitted: Save a draft or send a test only to the approved internal test list.
- Should be blocked or held: Send to a real audience without approval, change the segment/content or split a large broadcast into smaller sends.

#### Implementation references

- [Mailchimp · Send campaign](https://mailchimp.com/developer/marketing/api/campaigns/send-campaign/)
- [WordPress · Posts API](https://developer.wordpress.org/rest-api/reference/posts/)

### CA-02: Block customer actions outside the assigned tenant or case

- Severity: Critical
- Decision: Block
- Owner: Customer systems owner

#### Policy statement

Deny customer-account reads and mutations unless the target tenant and account are bound to the operator’s assigned case, account scope or approved support role.

#### Covered operations

- Read or update customer profile/account
- Reset credential, change security setting or view diagnostic data
- Add internal note or public reply to a different tenant’s case

#### Evaluation rules

- Derive tenant and case assignment from signed source-system context; ignore model-supplied tenant claims.
- Enforce row/object-level access on every related-object traversal and tool call.
- Fail closed when account-to-case mapping is missing or ambiguous.

#### Example decisions (illustrative; do not run against live systems)

- **Zendesk:** `Use customer ID from another ticket to retrieve account details`. Block.
- **Salesforce:** `Update an account outside the seller’s assigned territory`. Block unless a separately authorised role applies.

#### Applicable tools and systems

- Zendesk
- Intercom
- Salesforce
- HubSpot
- ServiceNow
- Jira Service Management
- Internal customer-admin tools

#### Enforcement

Use tenant-aware service APIs, scoped integration identities and source-system entitlements. Never expose a global customer-admin credential to the assistant.

#### Exception / approval

A named escalation role may access specified tenants for a case and duration; approval does not grant global reusable access.

#### Test fixtures

- Should remain permitted: Read the minimum account fields for the customer attached to the assigned case.
- Should be blocked or held: Swap account ID, follow a relationship across tenants or act on an account with no assignment context.

#### Implementation references

- [NIST SP 800-207 · Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final)

### CA-03: Require approval for destructive customer-account actions

- Severity: Critical
- Decision: Require approval
- Owner: Customer account owner + customer operations

#### Policy statement

Hold deletion, irreversible anonymisation, suspension, security reset or bulk entitlement removal for a live customer account.

#### Covered operations

- Delete/anonymise customer or tenant
- Suspend account or terminate active sessions
- Remove all entitlements, domains or API credentials
- Bulk destructive action across accounts

#### Evaluation rules

- Resolve exact customer/tenant, account owner, case/request, regulatory retention and recoverability.
- Expand bulk selectors and identify strategic, protected or multi-entity accounts.
- Bind approval to action, target, reason and recovery window; changed action or target invalidates it.

#### Example decisions (illustrative; do not run against live systems)

- **Internal admin:** `Delete tenant acme-prod and all associated data`. Hold for account and data-owner workflow.
- **Okta / customer identity:** `Reset MFA and sessions for every user in one enterprise tenant`. Hold.

#### Applicable tools and systems

- Internal customer-admin tools
- Salesforce
- Zendesk
- Auth0 / Okta Customer Identity
- Stripe Billing
- SaaS entitlement systems

#### Enforcement

Use a customer-operations broker with soft-delete/recovery where possible, exact-target confirmation and native audit. Keep irreversible delete authority separate from normal support tools.

#### Exception / approval

Security containment may suspend access with incident approval; permanent deletion still follows retention and account-owner review.

#### Test fixtures

- Should remain permitted: Disable one compromised token or perform a reversible action within documented support authority.
- Should be blocked or held: Delete/suspend the wrong tenant, change target after approval or remove all access using a broad selector.

#### Implementation references

- [NIST · AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### CA-04: Review discounts, credits and commercial commitments

- Severity: High
- Decision: Require approval
- Owner: Deal desk or commercial owner

#### Policy statement

Hold discounts, pricing changes, service-level promises, renewal terms and non-standard commitments that exceed the operator’s delegated authority or approved playbook.

#### Covered operations

- Change quote price, discount or commercial term
- Commit to service level, delivery date, warranty or liability term
- Issue service credit or free entitlement
- Send final proposal containing non-standard terms

#### Evaluation rules

- Resolve opportunity/account owner, product, currency, list price, cumulative discount, term version and approval matrix.
- Detect commitments in free text as well as structured quote fields.
- Approval binds to exact document/content version and structured commercial values.

#### Example decisions (illustrative; do not run against live systems)

- **Salesforce CPQ:** `Set a 45% discount where delegated authority is 15%`. Hold for commercial approval.
- **Email:** `Promise a contractual 99.999% SLA in a final customer message`. Hold for legal/service-owner review.

#### Applicable tools and systems

- Salesforce CPQ
- HubSpot
- Microsoft Dynamics 365
- Gmail / Microsoft 365
- DocuSign
- Ironclad
- Deal-desk platforms

#### Enforcement

Use CPQ/contract authority matrices and a send/sign gate tied to the exact proposal version. Agents may draft but cannot create binding acceptance or override pricing controls.

#### Exception / approval

Approval covers the named account, exact values and document digest; changes require a new decision from the appropriate authority.

#### Test fixtures

- Should remain permitted: Prepare a standard quote within documented discount authority.
- Should be blocked or held: Increase discount, add non-standard terms after approval or send a binding offer under a different account.

#### Implementation references

- [NIST · AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### CA-05: Review broad entitlement and licensing changes

- Severity: High
- Decision: Require approval
- Owner: Billing or customer account owner

#### Policy statement

Hold changes that grant premium capabilities, remove contracted access, alter seat counts materially or change an enterprise customer’s plan outside a verified order or support entitlement.

#### Covered operations

- Upgrade/downgrade plan or change billing entitlement
- Grant premium/admin feature
- Remove seats or licensed capability in bulk
- Extend trial or service beyond delegated value

#### Evaluation rules

- Resolve contract/order, customer tenant, current and proposed entitlement, monetary impact, effective date and requester authority.
- Aggregate repeated extensions and per-seat changes against delegated limits.
- Require account/billing owner approval for material or contract-inconsistent changes.

#### Example decisions (illustrative; do not run against live systems)

- **Stripe Billing:** `Move enterprise tenant from 100 to 1,000 seats without an order`. Hold.
- **Internal admin:** `Disable a contracted security feature for the whole tenant`. Hold for customer owner approval.

#### Applicable tools and systems

- Stripe Billing
- Salesforce
- Chargebee
- Zuora
- Internal entitlement services
- Customer support platforms

#### Enforcement

Gate entitlement writes through an order/support-aware service and compare to contract state. Record the resulting subscription/entitlement version.

#### Exception / approval

Approval covers tenant, exact entitlement delta, value and expiry; permanent exceptions must be reflected in the commercial system of record.

#### Test fixtures

- Should remain permitted: Apply a documented, low-value support extension within delegated authority.
- Should be blocked or held: Grant uncontracted premium access, remove contracted features or split extensions around limits.

#### Implementation references

- [NIST · AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

## Rollout checklist

- [ ] Inventory authoritative resource IDs, environments, classifications and owners.
- [ ] Map every entry point: IDE, agent, CLI, MCP, API, browser and direct console.
- [ ] Put the hard deny or least-privilege boundary in the destination system.
- [ ] Test permitted, held and denied fixtures using synthetic data in a sandbox.
- [ ] Test aliases, APIs, batch operations, changed approvals, retries and unknown scope.
- [ ] Observe matches, tune false positives and then enforce a bounded production scope.

Coverage: https://tracelet.ai/platform#coverage
