Policies are set by org admins and enforced server-side. Members don't have to remember the rules — the product simply behaves accordingly.
The five policies
Sharing
Whether members can share library items outside the org (e.g. via Knowledge Gifts). Off by default for regulated teams.
Export
Whether members can export prompts, skills and outputs to file. Tied to your data-handling rules.
EU-Model restriction
Forces AI calls to EU-resident models only. Currently enforced server-side in 5 of ~14 AI edge functions — the admin UI shows the truthful rollout status.
Strict BYOK
Hard-fails any AI call that cannot use your own API key. No silent fallback to platform models. Daily admin digest summarises failures.
Prompt Sanitiser
Teach-first rulebook. Inline coaching nudges members when their draft trips a rule. Anonymous 30-day metrics; no per-person reporting.
Today, 5 of about 14 AI edge functions enforce the EU-only policy. We surface that number in the admin UI and we mean it. Don't tell members "all AI is EU-only" until that count is 14/14.
Policy changes are written to the audit log with who, when and the new value. See the Audit trail page for what's captured.