# Approved AI Use Case Card

Publish an internal operating card that defines one allowed AI-assisted writing use case, safeguards, owner, permitted data, and prohibited behavior.

## Usage note

Issue a card only after the use case and vendor are reviewed under the applicable process. The card authorizes only its stated scope and does not extend to similar tools, data, audiences, or automated decisions.

## How to use this template

1. Link the approved assessment and copy its exact task, tool, data, and audience boundaries.
2. Translate safeguards into clear steps, named roles, evidence requirements, and examples.
3. Define prohibited behavior, escalation, incident, suspension, and revocation paths.
4. Obtain governance and operational approval, then publish a controlled card version.
5. Train users, sample actual use, and renew or withdraw the card at its trigger date.

## Blank template

### Authorization

- **Use case ID and title:** [Enter]
- **Business purpose:** [Describe]
- **Allowed AI task:** [One bounded operation]
- **Eligible users or roles:** [List]
- **Approved service, feature, and account:** [Enter]
- **Intended output and audience:** [Enter]
- **Risk assessment reference:** [Enter]
- **Card owner and version:** [Name/version]

### Permitted workflow

- **Permitted data classes:** [Define with examples]
- **Sources required:** [List]
- **Approved prompt or context pattern:** [Reference]
- **Output may be used for:** [Internal draft / Alternatives / Other]
- **Required factual checks:** [Who checks what against which evidence]
- **Required subject review:** [Role and trigger]
- **Final approval:** [Role]
- **Provenance and disclosure:** [Requirements]

### Prohibited and escalation cases

- [ ] Do not enter credentials, secrets, or unapproved personal information.
- [ ] Do not use the output as proof of facts, citations, or authorship.
- [ ] Do not automate publication or consequential decisions outside this card.
- [ ] Do not imitate a real person or create deceptive identity claims.
- **Additional prohibited inputs:** [List]
- **Additional prohibited outputs:** [List]
- **When to stop and escalate:** [List]
- **Escalation owner and route:** [Enter]

### Control and lifecycle

- **Training required:** [Module/owner]
- **Monitoring sample and owner:** [Define]
- **Incident reporting route:** [Enter]
- **Suspension authority:** [Role]
- **Approval names and date:** [Enter]
- **Effective date:** [YYYY-MM-DD]
- **Review or expiry date:** [YYYY-MM-DD]
- **Reassessment triggers:** [Tool, data, audience, scale, policy, incident]
