Decision inputs
Facts that change the policy answer
Here the tool receives private repositories and development history, while someone ultimately relies on a model adapted to company code. The policy must evaluate the whole path between them.
- 1Task and owner
- Machine learning engineer wants to train an external model on company source code. Name who owns the finished a model adapted to company code; ownership should not disappear because AI helped produce it.
- 2Information involved
- Private repositories and development history. Look beyond pasted text: files, integrations and retrieval connections can expose the same material.
- 3Tool and account
- An approved company account. The request should identify the exact account because product-level approval leaves important controls unknown.
- 4Intended result
- The expected result is a model adapted to company code. Record the audience and the next system in the chain, rather than describing the output only as a draft.
- 5Consequence if it is wrong
- The training transfer can expose intellectual property and retain secrets outside company control. A familiar task still needs escalation when this consequence becomes plausible.
- 6Human review
- security, legal and engineering owners should inspect, change, reject or stop the result. A final glance after an automatic action would not give that owner meaningful control.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
The lower-friction route begins when the exact account is approved, only the minimum proprietary source code and secrets is used, a model adapted to company code remains within the stated purpose, and security, legal and engineering owners reviews it before use.
Approval may be required
A named reviewer should take over when the account or data handling is uncertain, the training transfer can expose intellectual property and retain secrets outside company control, or a model adapted to company code reaches people or systems beyond the requester’s authority.
The request may need to stop or change
The proposed use should pause if restricted information would enter an unapproved service, the output would act before security, legal and engineering owners can intervene, or do not upload code until contractual, security and retention controls are approved cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Does the selected account retain or reuse anything supplied while trying to train an external model on company source code?
- 02
Who is permitted to expose private repositories and development history to this tool and for this purpose?
- 03
Will a model adapted to company code remain working material, reach another person or make another system act?
- 04
What evidence will security, legal and engineering owners use to accept, correct or reject the result?
- 05
Would another region, audience or frequency activate a different company rule?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- machine learning engineer
- task
- Use AI to train an external model on company source code.
- information
- private repositories and development history
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Train an external model
- impact
- External model training
- review
- Complete human review
- owner
- security, legal and engineering owners
Useful safeguards
Controls that fit this request
- ✓
Do not upload code until contractual, security and retention controls are approved
- ✓
Separate source material from the request record and expose only what the tool needs for a model adapted to company code.
- ✓
Write the boundary around a model adapted to company code clearly so later users do not expand the approval by assumption.
- ✓
Record the request and reviewer without copying unnecessary parts of private repositories and development history into the audit trail.
Questions people ask
About this AI use
Is using AI to train an external model on company source code automatically allowed?
Permission depends on the facts submitted for this request. A different tool, information class, region or use of a model adapted to company code can produce another route.
Which facts should be submitted before work begins?
Describe a model adapted to company code, identify private repositories and development history, name the exact tool and account, explain who will receive or rely on the output, and state how security, legal and engineering owners will review it.
How should a later reviewer understand this decision?
Record the request and reviewer without copying unnecessary parts of private repositories and development history into the audit trail. A classification and controlled reference may be enough when copying private repositories and development history would create unnecessary risk.