Glucode Glucode Handbook

Use of AI

1. Purpose

Glucode encourages responsible use of artificial intelligence to improve software delivery, product design, quality assurance, documentation, research, operations, and project management.

AI can help us work faster and better, but it can also create security, privacy, legal, accuracy, cost, ethical, and client-trust risks.

This policy explains how Glucode team members may use AI safely and responsibly while protecting Glucode, our clients, our team members, end users, and project information.

AI must always be used in a way that complies with applicable laws, client agreements, security standards, internal policies, and South Africa’s Protection of Personal Information Act, where relevant.

2. Scope

This policy applies to:

  • All Glucode employees, contractors, consultants, learners, and approved third parties.
  • All Glucode work, client work, internal projects, proposals, codebases, documentation, research, operations, and business activities.
  • All AI tools, whether accessed through a browser, API, IDE, plugin, coding agent, meeting tool, design tool, productivity tool, or embedded product feature.
  • All AI use involving Glucode data, client data, source code, project information, personal information, confidential information, or company resources.

This policy applies whether the AI tool is free, paid, enterprise-managed, locally installed, API-based, browser-based, or built into another product.

3. Key Terms

AI tool means any software that uses artificial intelligence to generate, review, transform, search, classify, summarise, code, test, reason, or take action.

Examples include ChatGPT Enterprise, OpenAI Codex, Claude, Claude Code, GitHub Copilot, Cursor, Windsurf, Gemini, Perplexity, Notion AI, AI browser agents, AI meeting tools, AI design tools, and AI plugins or extensions.

Approved AI tool means an AI tool approved by Glucode for company or client work.

Enterprise AI tooling means AI tools approved and managed by Glucode for business use. Glucode’s managed enterprise AI workspace is the preferred environment for company and client work.

Public AI tool means an AI service used through a personal account, unmanaged workspace, trial account, browser extension, unofficial proxy, shared credential, or tool that Glucode has not approved.

Agentic AI tool means an AI tool that can take actions, not only produce text. Examples include tools that edit files, run terminal commands, create branches, open pull requests, install packages, access repositories, call APIs, browse websites, or interact with connected apps.

Sensitive data means information that requires protection. Examples include personal information, health information, payment data, client data, contracts, credentials, source code, internal strategy, unreleased product information, legal information, HR information, financial information, and commercially confidential information.

Personal information means information protected under POPIA or similar privacy laws.

Secrets means credentials such as API keys, access tokens, private keys, passwords, certificates, SSH keys, database URLs, OAuth secrets, webhook secrets, session cookies, and similar credentials.

Tokens means the units AI models use to process input and output. Token usage affects cost, speed, context length, and the amount of information shared with an AI tool.

Autonomous or YOLO mode means any setting that lets an AI tool take actions without human approval. This includes automatic terminal execution, automatic file editing, automatic pull request creation, automatic dependency installation, or broad allow rules in tools such as Claude Code, Cursor, Codex, or similar agents.

4. Core Principles

Glucode follows these principles when using AI.

Human accountability

A person remains responsible for all AI-assisted work. AI output must not be treated as final without human review.

Security by default

AI tools must not expose secrets, private repositories, client data, regulated information, or confidential information.

Privacy by design

Team members must limit the data shared with AI tools and avoid unnecessary use of personal information.

Transparency

Clients must receive clear information about AI use when required by contract, regulation, project risk, or reasonable client expectation.

Fairness and non-discrimination

AI must not be used in ways that create unfair, biased, deceptive, discriminatory, or harmful outcomes.

Least privilege

AI tools must only receive the access needed for the task.

Cost awareness

AI usage must be purposeful, efficient, and proportionate to the business value of the work.

5. Approved AI Tooling

Team members must use Glucode-approved AI tools for company and client work.

Glucode-managed enterprise tooling is the preferred option for business use, especially when working with:

  • Client information.
  • Source code.
  • Project documentation.
  • Internal business information.
  • Sensitive data.
  • Personal information.
  • Commercially confidential information.
  • Regulated or health-related information.

Personal OpenAI, Claude, Gemini, Copilot, Cursor, or other AI accounts must not be used for Glucode or client work unless approved by a manager, IT, security, or the AI governance owner.

A tool is not automatically approved because it is popular, useful, free, installed locally, or used by another team.

Approval depends on security, privacy, licensing, client obligations, access controls, logging, data handling, and business need.

6. Acceptable Use of AI

AI may be used for approved business purposes, including:

  • Drafting documents, proposals, meeting notes, tickets, test plans, release notes, and technical documentation.
  • Brainstorming product ideas, user flows, architecture options, and project plans.
  • Summarising non-sensitive or approved documents.
  • Writing, explaining, reviewing, refactoring, and testing code.
  • Generating boilerplate code, sample data, test cases, scripts, and documentation.
  • Debugging errors and explaining unfamiliar code.
  • Improving accessibility, usability, grammar, structure, and clarity.
  • Creating internal learning material and training examples.
  • Supporting QA, risk analysis, and security review where a human verifies the result.
  • Supporting project management, estimation, planning, and internal research.

AI must be used as an assistant, not as a replacement for professional judgment, engineering review, QA, security review, legal review, client approval, or management accountability.

7. Prohibited Use of AI

Team members must not use AI to:

  • Make final hiring, disciplinary, financial, legal, medical, clinical, or high-impact decisions without appropriate human review.
  • Replace required engineering, QA, security, design, compliance, or client approval steps.
  • Generate deceptive content, impersonate people, manipulate users, or misrepresent human work.
  • Bypass security controls, licence restrictions, paywalls, client restrictions, or access permissions.
  • Process sensitive data in unapproved public AI tools.
  • Upload secrets, credentials, private keys, production data, or regulated health data to unapproved tools.
  • Use unofficial model proxies, shared API keys, grey-market AI access, scraped AI endpoints, or unauthorised AI services.
  • Create or assist malware, credential theft, unauthorised access, phishing, harmful automation, or other abusive activity.
  • Publish AI-generated content, code, designs, or analysis without suitable human review.
  • Ignore client AI restrictions or contractual requirements.
  • Present AI output as verified fact without review.
  • Use AI-generated legal, medical, financial, or compliance advice as final advice without qualified human review.
  • Misuse Glucode AI accounts, subscriptions, tokens, API credits, or model access for personal, unauthorised, excessive, or non-business purposes.
  • Bypass AI usage limits, cost controls, monitoring, approval workflows, model restrictions, or permission controls.
  • Leave AI agents, coding agents, API workflows, or automated AI processes running unattended in a way that causes unnecessary cost, risk, or operational impact.

8. Enterprise AI Usage

Glucode provides approved enterprise AI tooling for business use.

Team members must use approved Glucode-managed workspaces instead of personal accounts when working with Glucode or client information.

Enterprise AI tools provide stronger administrative, privacy, access, and governance controls than unmanaged personal accounts. These controls reduce risk, but they do not remove the need for careful data handling.

Team members must:

  • Use the approved enterprise workspace for business prompts, documents, code, and project support.
  • Keep work inside approved workspaces, approved projects, and approved integrations.
  • Avoid connecting personal drives, personal email accounts, or unauthorised third-party services.
  • Use approved connectors only when the data source is needed for the task.
  • Check sharing settings before creating or sharing custom GPTs, projects, prompts, files, chats, or outputs.
  • Avoid sharing enterprise workspace content outside Glucode unless the project and client permit it.
  • Report unexpected tool access, unusual model behaviour, data exposure, or suspected account compromise.

Enterprise AI output remains subject to normal Glucode review, QA, security, and client approval processes.

9. Responsible Use of AI Resources

Glucode provides approved AI tools to support legitimate company and client work.

AI access, tokens, model usage, API credits, compute resources, agent runtimes, context windows, file uploads, connected-tool actions, and company-paid AI subscriptions are company resources and must be used responsibly.

Team members must not misuse AI resources, including by:

  • Using Glucode AI accounts, tokens, API keys, subscriptions, or seats for personal projects, side businesses, unrelated study, or non-work experimentation without approval.
  • Running excessive, unfocused, repetitive, speculative, or low-value prompts that have no reasonable business purpose.
  • Asking AI tools to process entire repositories, documents, logs, datasets, inboxes, chat histories, or file systems where a smaller excerpt or narrower scope would be sufficient.
  • Leaving agentic tools running unattended where they consume tokens, execute commands, loop, inspect unrelated files, or generate unnecessary changes.
  • Using high-cost models, deep research tools, large-context workflows, file-heavy workflows, or coding agents for simple tasks that could reasonably be handled with lower-cost tools or smaller prompts.
  • Repeatedly retrying prompts, agent runs, or API calls without changing the instruction, reducing the scope, or adding useful context.
  • Sharing Glucode AI access, API keys, seats, credentials, projects, custom GPTs, or workspaces with unauthorised people.
  • Attempting to bypass usage limits, monitoring, approval workflows, model restrictions, tool permissions, budget controls, or security controls.
  • Using AI tools in a way that creates unnecessary cost, security exposure, client risk, privacy risk, operational burden, or reputational harm.

AI usage must be proportionate to the business value, urgency, and risk of the task. Team members must choose an appropriate tool and model for the work being performed.

Managers may set team, project, client, repository, model, token, API, budget, or workflow limits.

Glucode may monitor AI usage for security, compliance, quality control, cost management, abuse prevention, and operational oversight, subject to applicable law and internal workplace policies.

Suspected misuse, runaway usage, unexpected billing, compromised AI credentials, abnormal token consumption, or unauthorised access must be reported promptly to a manager, IT, security owner, or AI governance owner.

Misuse of AI resources may result in access restrictions, budget controls, corrective action, disciplinary action, client escalation, or other consequences depending on the severity and context.

10. Agentic Coding Tools

Agentic coding tools can inspect codebases, edit files, run commands, install dependencies, create commits, open pull requests, run tests, and interact with development tools.

Examples include OpenAI Codex, Claude Code, Cursor agents, GitHub Copilot coding agents, Windsurf agents, and similar tools.

These tools can improve delivery speed, but they can also delete files, expose secrets, introduce vulnerabilities, change licences, run unsafe commands, or create large unreviewed changes.

Team members must follow these rules:

  • Use agentic coding tools only in approved repositories and approved environments.
  • Review the task prompt before giving an agent access to a repository.
  • Prefer read-only or planning mode before allowing edits.
  • Do not allow broad automatic command execution.
  • Do not enable YOLO mode, bypass permissions, unrestricted auto-run, or permanent allow rules for risky commands.
  • Approve shell commands manually unless the command is clearly safe and project rules allow automation.
  • Deny commands that access secrets, production systems, private user data, unrelated directories, credential stores, browser cookies, SSH keys, password managers, or cloud consoles.
  • Run AI-generated changes through normal local checks, automated tests, code review, and pull request review.
  • Keep commits and pull requests small enough for proper review.
  • Do not let an AI agent merge its own pull request.
  • Do not let an AI agent deploy to production without normal deployment approval.
  • Check generated dependencies, licences, package sources, and scripts before installation.
  • Remove generated code that is unnecessary, insecure, unmaintainable, or not understood by the responsible developer.

For Claude Code and similar terminal tools, use permission settings that ask before file edits and shell commands.

For Codex and similar repository agents, require human review before accepting, committing, merging, or deploying changes.

11. Data Handling and Security

Team members must protect data when using AI.

11.1 Sensitive data

Do not enter sensitive data into an AI tool unless:

  • The tool is approved for that data type.
  • The project permits that use.
  • The client agreement permits that use.
  • The minimum required data is used.
  • Personal information is anonymised, masked, or minimised where possible.

Avoid sending full datasets, full exports, full user records, production logs, or full client documents unless approval exists and the task requires it.

11.2 Personal information

Personal information must only be used with AI where there is a clear business purpose, a lawful basis, appropriate approval, and suitable protection.

Team members must minimise personal information when using AI.

Where possible:

  • Remove names.
  • Remove contact details.
  • Remove IDs.
  • Remove account numbers.
  • Remove addresses.
  • Remove unnecessary context.
  • Replace real data with examples or placeholders.

11.3 Health and regulated data

Health information, clinical information, patient information, and similar regulated data require extra care.

Team members must not use health or regulated data in public AI tools.

Use only approved enterprise tools and approved workflows.

Apply anonymisation or de-identification where possible.

Confirm client requirements before using AI on health-related projects.

AI must not make clinical or medical decisions unless the project has explicit approval, suitable controls, and appropriate professional oversight.

11.4 Secrets

Never paste secrets into prompts, chats, code assistants, custom GPTs, AI agents, or AI debugging sessions.

Team members must:

  • Use environment variables, secret managers, and placeholders.
  • Redact keys, tokens, passwords, private URLs, and credentials before using AI.
  • Check screenshots, logs, stack traces, .env files, config files, and terminal output for secrets before sharing them with AI.
  • Rotate credentials immediately if a secret is exposed to an unapproved tool.
  • Report suspected exposure immediately.

11.5 Source code

Source code may contain confidential logic, client IP, vulnerabilities, credentials, or regulated data.

Use approved enterprise tools for code-related AI tasks.

Do not upload private repositories to unapproved AI services.

Do not use unofficial AI proxies or browser extensions that read repository contents without approval.

11.6 Files, screenshots, and recordings

Before uploading files, screenshots, videos, transcripts, meeting recordings, logs, or exports to AI tools, check for:

  • Sensitive data.
  • Client names.
  • Credentials.
  • Production data.
  • Personal information.
  • Confidential business information.
  • Information not needed for the task.

12. Token Usage and Cost Management

AI usage consumes tokens and other resources.

Tokens represent model input, output, tool calls, file content, code context, conversation history, images, and generated responses.

Token usage affects cost, response speed, context limits, and the amount of information shared with a model.

Team members must use tokens responsibly.

12.1 Token usage rules

Team members must:

  • Use AI for clear work purposes, not unnecessary experimentation with company resources.
  • Keep prompts focused.
  • Avoid pasting entire documents, repositories, logs, or datasets when a smaller excerpt will work.
  • Ask the model to work on specific sections, files, errors, or examples.
  • Remove duplicate content before prompting.
  • Start with summaries or relevant snippets before escalating to large files.
  • Use smaller or faster models when the task does not need advanced reasoning.
  • Use stronger models for high-risk, complex, ambiguous, or architecture-level work.
  • Avoid repeated retries without changing the prompt or adding useful context.
  • Stop long-running agent tasks when they drift, loop, or produce low-value output.
  • Monitor project-level usage where dashboards or reports are available.
  • Report unusual usage spikes, runaway agents, or unexpected billing.

12.2 Prompt structure for efficiency

Good prompts reduce token waste.

A good prompt should include:

  • The goal.
  • Relevant context.
  • Constraints.
  • Expected output format.
  • Specific files, excerpts, logs, or examples.
  • What the model must not do.

Avoid prompts that include broad context without a clear task.

12.3 Coding agent token usage

Coding agents can consume many tokens because they read files, search repositories, inspect dependencies, run tools, and iterate on failures.

Before starting a coding agent:

  • Define the task clearly.
  • Limit the scope to the relevant area.
  • Tell the agent which files or modules to inspect first.
  • Ask for a plan before allowing edits on larger tasks.
  • Require the agent to summarise changes before implementation.
  • Avoid asking the agent to “review the whole codebase” unless the project has approved that cost.
  • Stop the agent if it repeatedly reads unrelated files or loops through failed attempts.

12.4 API token usage

For API-based AI work:

  • Set usage limits where available.
  • Log token usage for production systems.
  • Monitor input tokens, output tokens, cached tokens, failed requests, retries, and tool calls.
  • Use prompt caching or stable prompt prefixes where appropriate.
  • Keep system prompts and reusable instructions consistent.
  • Avoid storing unnecessary conversation history.
  • Truncate, summarise, or retrieve only relevant context.
  • Use batching, caching, retrieval, and model selection to control cost.
  • Treat token logs and prompts as potentially sensitive.
  • Do not use production customer data for testing unless approved.

12.5 Budget ownership

The person or team using AI owns the business justification for that usage.

Managers may set project-level limits for AI usage, especially for agentic coding, large document analysis, bulk generation, testing, or API experimentation.

13. AI in Software Development

AI-generated code must meet the same standards as human-written code.

Developers must:

  • Understand AI-generated code before accepting it.
  • Review all generated code for correctness, security, performance, maintainability, accessibility, and licence risk.
  • Run tests before submitting AI-assisted changes.
  • Add or update tests for AI-generated behaviour.
  • Check for hallucinated APIs, broken assumptions, deprecated libraries, vulnerable packages, and unnecessary complexity.
  • Avoid accepting generated code that the developer cannot explain.
  • Use small pull requests where possible.
  • Note meaningful AI assistance in the pull request when it affects implementation, review, or risk.
  • Follow existing secure development standards.
  • Keep humans responsible for architecture, security, production changes, and client commitments.

AI-generated code must not bypass code review, QA, security scanning, dependency checks, or deployment controls.

14. AI Output Review

AI output must be treated as draft work unless reviewed by a responsible person.

Team members must check AI output for:

  • Accuracy.
  • Missing context.
  • Fabricated information.
  • Security issues.
  • Privacy issues.
  • Legal or contractual risk.
  • Bias or unfairness.
  • Accessibility problems.
  • Licence or copyright concerns.
  • Poor maintainability.
  • Client-specific restrictions.
  • Outdated assumptions.
  • Inappropriate tone or content.

Do not claim that AI output is accurate, secure, unbiased, or production-ready unless it has been properly reviewed.

15. Documentation and Disclosure

Team members must document AI use when it affects project risk, client deliverables, regulated work, or material decisions.

Documentation may include:

  • The tool used.
  • The purpose of use.
  • Whether client or sensitive data was involved.
  • Human review performed.
  • Security checks performed.
  • Known limitations or assumptions.
  • Any AI-generated code, design, research, or content included in a deliverable.

Clients must be informed about AI use when required by contract, project governance, law, regulation, or reasonable client expectation.

Do not overstate AI capabilities to clients.

Do not tell clients that AI output is verified, secure, complete, compliant, unbiased, or production-ready unless the relevant review has actually occurred.

16. Client-Specific Requirements

Client requirements override general AI convenience.

Before using AI on client work, team members must check for:

  • Contractual AI restrictions.
  • Data processing agreements.
  • Security requirements.
  • Health, financial, legal, or regulated data requirements.
  • Client approval requirements.
  • Disclosure requirements.
  • Restrictions on source code, personal information, or production data.
  • Regional data handling or data residency requirements.

If there is uncertainty about whether AI may be used on a client project, ask the project lead, manager, security owner, privacy owner, or AI governance owner before proceeding.

For health-related projects, apply extra review for safety, fairness, privacy, explainability, accessibility, and clinical risk.

17. Risk Management

AI risks must be managed throughout a project.

Team members must check for:

  • Incorrect or fabricated information.
  • Security vulnerabilities.
  • Exposed secrets.
  • Privacy issues.
  • Bias or unfair outcomes.
  • Poor accessibility.
  • Unsafe recommendations.
  • Licence or copyright concerns.
  • Poor maintainability.
  • Excessive token usage or cost.
  • Unapproved tool access.
  • Unapproved data transfer.
  • Agent actions that exceed the intended scope.

Report AI-related concerns early.

Small issues are easier to fix before they become client, security, privacy, or delivery problems.

AI-related incidents must be reported promptly.

Examples include:

  • Accidental data exposure.
  • Leaked credentials.
  • Use of an unapproved AI tool for sensitive work.
  • Unexpected access to files, repositories, emails, drives, or systems.
  • Harmful or unsafe AI output.
  • Biased or discriminatory output.
  • Unsafe or vulnerable generated code.
  • Production impact caused by AI-assisted work.
  • Client concern about AI use.
  • Unexpected AI billing or token usage.
  • A coding agent taking actions outside the intended scope.
  • A compromised AI account, API key, or workspace.

Report suspected incidents to a manager, IT, security owner, project lead, or AI governance owner.

If a secret is exposed, stop using the secret, report it immediately, and rotate the credential as soon as possible.

19. Questions and Escalation

Ask for help if you are unsure whether AI may be used for a task.

Questions about AI tools, enterprise access, Codex, Claude Code, coding agents, token usage, secrets, client restrictions, or this policy should go to a manager, project lead, security owner, IT owner, privacy owner, or AI governance owner.

When in doubt, pause and ask before sharing sensitive information, client information, production data, source code, or secrets with any AI tool.

20. Acknowledgment

All team members must read, understand, and follow this policy.

Failure to follow this policy may lead to corrective action, removal of tool access, client escalation, disciplinary action, or other consequences depending on severity.

Team members may need to confirm acceptance of this policy annually or when material updates occur.

21. Quick Rules to Remember

  1. Use approved AI tools for work.
  2. Do not use personal AI accounts for Glucode or client confidential work unless approved.
  3. Never paste secrets into AI tools.
  4. Minimise personal, sensitive, and client data.
  5. Use enterprise tools for company and client work.
  6. Review all AI output before relying on it.
  7. Do not let AI bypass code review, QA, security review, or client approval.
  8. Do not enable unrestricted autonomous agent behaviour.
  9. Use AI resources responsibly and avoid wasteful token usage.
  10. Ask before using AI in sensitive, regulated, health-related, or client-restricted contexts.