# People, legal & corporate records: enterprise AI policy pack

Support drafting, research and administration while protecting restricted records and preserving human authority over employment, signature, payroll and legal-hold actions.

Implementation guidance, not executable Tracelet configuration or legal advice. Tool names identify places where the control may apply; they do not claim shipped connector coverage. Confirm actual tool/action coverage and enforce destination permissions. Replace example thresholds, IDs and approval windows with your approved values.

## Control scope

- Protected assets: Candidate and employee records, payroll, contracts, privileged matters and regulated corporate records
- Consequential actions: Employment decision, compensation change, signature, external disclosure, hold change and disposal
- Applicable systems: HRIS, ATS, payroll, document management, e-signature and legal matter systems
- Context to resolve: Resolve operator role, subject/cohort, matter, classification, signatory authority, document hash, active hold, jurisdiction and required approvers.
- Enforcement boundary: Use field-level permissions, matter walls, e-signature authority and records-management holds at the system of record. Agent approvals cannot substitute for statutory or corporate authority.

## Owners

People systems owner + legal operations + records owner

## Configure first

- Restricted HR and legal matter classifications, cohorts, matters and ethical walls
- Employment decision makers, authorised signatories, payroll approvers and delegation limits
- Retention schedules, active legal holds, record custodians and disposal workflow

## Shared decision baseline

### Resolve the real target

Decide on immutable IDs and effective context: principal, tenant/account, environment, resource, data classification and destination. Names and local profiles are hints, not authority.

### Fail closed on consequential ambiguity

If the target, blast radius, tenant or data classification cannot be resolved, hold the action. Do not treat missing metadata as non-production or low risk.

### Bind approval to the exact action

An approval covers the actor, operation, target set, content or artifact digest, value and expiry. Material changes invalidate it; the requester cannot approve their own action.

### Keep an evidence-grade decision record

Record resolved context, policy version, matched rule, decision, approver and downstream result. Minimise captured sensitive content and protect the record from the acting identity.

## Policies

### PL-01: Block autonomous employment decisions

- Severity: Critical
- Decision: Block
- Owner: People leader + HR operations

#### Policy statement

Deny agents from making or executing final hire, reject, promotion, compensation, performance, disciplinary or termination decisions. Agents may prepare evidence for an accountable human decision maker.

#### Covered operations

- Advance/reject candidate as a final decision
- Change performance rating or disciplinary status
- Approve promotion, compensation or termination
- Send final consequential notice without human decision

#### Evaluation rules

- Distinguish preparation/recommendation from authoritative status change and outbound notification.
- Resolve subject, role, decision maker, approved decision record and exact communication.
- Block when the agent is the sole decision source or when required human evidence is absent.

#### Example decisions (illustrative; do not run against live systems)

- **ATS:** `Reject 120 applicants solely from model ranking`. Block final status changes.
- **HRIS:** `Mark employee for termination and send notice`. Block agent execution.

#### Applicable tools and systems

- Workday
- SAP SuccessFactors
- BambooHR
- Greenhouse
- Lever
- Ashby
- Microsoft 365 / Google Workspace

#### Enforcement

Give assistants draft/read capabilities only for consequential stages. Require a named human decision record in the HR/ATS workflow before any status change or final communication.

#### Exception / approval

None for autonomous decisions. The accountable human must decide and the system of record must capture that ownership.

#### Test fixtures

- Should remain permitted: Summarise interview evidence or draft a notice for authorised human review.
- Should be blocked or held: Set the final status, bulk reject from model score or send the decision without a verified human owner.

#### Implementation references

- [NIST · AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### PL-02: Block access to restricted HR and legal matters outside assigned scope

- Severity: Critical
- Decision: Block
- Owner: HR data owner or matter owner

#### Policy statement

Deny retrieval, summarisation or disclosure of restricted personnel, medical, payroll, investigation, privileged or legal-matter records outside the user’s role, cohort or matter assignment.

#### Covered operations

- Read restricted employee/candidate fields
- Search or summarise privileged matter content
- Cross-cohort or broad people analytics with direct identifiers
- Attach restricted record to unrelated matter or conversation

#### Evaluation rules

- Derive subject cohort and matter membership from the system of record, including ethical walls and field permissions.
- Enforce permission on every retrieved item and related-object expansion; search results must not leak titles or snippets.
- Fail closed when matter, subject or operator scope is missing.

#### Example decisions (illustrative; do not run against live systems)

- **HRIS:** `Retrieve executive compensation using a general HR service account`. Block unless the acting user has the restricted role.
- **Document system:** `Summarise a privileged acquisition matter for a non-member`. Block.

#### Applicable tools and systems

- Workday
- SAP SuccessFactors
- BambooHR
- Greenhouse
- iManage
- NetDocuments
- Microsoft 365 / SharePoint
- Google Drive

#### Enforcement

Use subject/field permissions, matter walls, scoped search and separate credentials at source. Do not index restricted content into a broadly accessible assistant corpus.

#### Exception / approval

A formal investigation/matter-access workflow grants named data classes and duration; it does not create broad reusable access.

#### Test fixtures

- Should remain permitted: Retrieve permitted fields for an assigned employee case or an explicitly assigned legal matter.
- Should be blocked or held: Use global search, guess record ID or follow links into an unassigned restricted cohort or matter.

#### Implementation references

- [NIST SP 800-207 · Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final)
- [Microsoft Purview · Data loss prevention](https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp)

### PL-03: Require two-person approval for payroll and compensation changes

- Severity: Critical
- Decision: Require two-person approval
- Owner: Payroll owner + people operations

#### Policy statement

Hold changes to salary, bonus, bank details, tax withholding, payroll runs and mass compensation imports until validated against approved HR events and reviewed by eligible people/payroll owners.

#### Covered operations

- Change employee bank or tax details
- Change salary, bonus or equity data
- Import mass compensation update
- Approve, release or rerun payroll

#### Evaluation rules

- Resolve employee/legal entity, effective date, current/proposed value, currency, source HR event and payment destination fingerprint.
- Aggregate multiple changes and flag outliers, duplicate payroll and changes near approval thresholds.
- Require two eligible approvers for bank-detail and payroll-release actions; requester cannot approve.

#### Example decisions (illustrative; do not run against live systems)

- **Workday:** `Import salary increases for 800 employees`. Hold for HR and payroll approval.
- **Payroll platform:** `Change bank details and rerun the same pay cycle`. Hold as high-risk sequence.

#### Applicable tools and systems

- Workday
- SAP SuccessFactors
- ADP
- Dayforce
- Rippling
- BambooHR payroll integrations
- Banking/payment files

#### Enforcement

Use payroll-native maker-checker, validated HR-event linkage, anomaly detection and file/payment controls. Keep payroll-release credentials outside the assistant.

#### Exception / approval

Emergency correction still requires two eligible approvers and binds to named employees, pay cycle, amount and destination.

#### Test fixtures

- Should remain permitted: Prepare a compensation-change file and show aggregate validation without revealing unnecessary individual data.
- Should be blocked or held: Release payroll without dual approval, change bank details and immediately pay, or edit values after approval.

#### Implementation references

- [NIST · AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### PL-04: Require authorised signatory approval for binding agreements

- Severity: Critical
- Decision: Require two-person approval
- Owner: Legal matter owner + authorised signatory

#### Policy statement

Hold signature, acceptance or dispatch of contracts and binding legal instruments unless the exact document is approved and the signatory has authority for its entity, value and instrument type.

#### Covered operations

- Send agreement for signature
- Apply signature or click acceptance
- Change signatory, counterparty or entity
- Replace attachment or terms after approval

#### Evaluation rules

- Resolve legal entity, counterparty, document hash/version, value, term, signatory and delegated authority.
- Require legal/matter owner review plus an authorised signatory where the authority matrix demands it.
- Invalidate approval on any document, party, value or signatory change.

#### Example decisions (illustrative; do not run against live systems)

- **DocuSign:** `Send a $2M supplier agreement under the AU entity`. Hold for legal review and authorised signatory.
- **Browser:** `Accept online terms using a shared company account`. Hold when acceptance binds the organisation.

#### Applicable tools and systems

- DocuSign
- Adobe Acrobat Sign
- Ironclad
- Icertis
- Microsoft 365 / SharePoint
- Google Drive
- Browser procurement portals

#### Enforcement

Use e-signature roles, contract workflow and an authority matrix tied to entity/value. The agent can prepare envelopes but cannot impersonate or reuse a signatory credential.

#### Exception / approval

Only the corporate delegation-of-authority process can approve; agent or chat consent is never a substitute for signatory authority.

#### Test fixtures

- Should remain permitted: Prepare a draft envelope with the authorised signatory for review, without sending.
- Should be blocked or held: Send or sign a changed document, swap counterparty/signatory or rely on a prior generic approval.

#### Implementation references

- [NIST · AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### PL-05: Block legal-hold removal and premature record disposal

- Severity: Critical
- Decision: Block
- Owner: Records manager + legal hold owner

#### Policy statement

Deny agent removal of legal holds, retention locks or protected custodians and deny deletion of records that are held or have not reached an approved disposal event.

#### Covered operations

- Remove/disable legal hold or retention lock
- Delete held mailbox, file, chat, case or audit record
- Shorten retention below schedule
- Remove custodian, location or matter from hold scope

#### Evaluation rules

- Resolve record class, jurisdiction, retention schedule, active holds, custodian and disposition approval.
- Hold status and retention lock are authoritative even when the source owner requests deletion.
- Correlate hold-scope edits followed by deletion and keep hold administration outside the acting agent identity.

#### Example decisions (illustrative; do not run against live systems)

- **Microsoft Purview:** `Disable retention lock then delete a custodian mailbox`. Block.
- **Document management:** `Remove a folder from litigation hold to permit bulk deletion`. Block.

#### Applicable tools and systems

- Microsoft Purview / Microsoft 365
- Google Vault
- iManage
- NetDocuments
- Slack Enterprise Grid
- Box
- ServiceNow
- Archive platforms

#### Enforcement

Use immutable retention lock and records-manager roles separated from content owners and agents. Disposal runs from the records system only after hold and schedule checks.

#### Exception / approval

No agent exception. Hold release requires the authorised legal matter process; disposal requires the records owner and preserved evidence.

#### Test fixtures

- Should remain permitted: Generate a disposition review list for records whose schedule has matured and have no active hold.
- Should be blocked or held: Remove a hold, shorten retention or delete any held record even through a different connected system.

#### Implementation references

- [Microsoft Purview · Retention Lock](https://learn.microsoft.com/en-us/purview/retention-lock)

## Rollout checklist

- [ ] Inventory authoritative resource IDs, environments, classifications and owners.
- [ ] Map every entry point: IDE, agent, CLI, MCP, API, browser and direct console.
- [ ] Put the hard deny or least-privilege boundary in the destination system.
- [ ] Test permitted, held and denied fixtures using synthetic data in a sandbox.
- [ ] Test aliases, APIs, batch operations, changed approvals, retries and unknown scope.
- [ ] Observe matches, tune false positives and then enforce a bounded production scope.

Coverage: https://tracelet.ai/platform#coverage
