Hands-on Lab1,918 words

Governance, Risk, and Responsible Use — practice exercise

Governance, Risk, and Responsible Use — practice exercise

Difficulty: intermediate · Estimated duration: 45–60 minutes

This is a written exercise. No code is involved, and nothing needs to be sent to Claude, so it works on any plan. You may use Claude to discuss your answers, but do not paste the invented personal details below into a real chat. The scenario is invented for practice: you are the operations lead at a mid-sized lettings and property-management agency that has just adopted Claude on a Team plan.

Every answer can be worked out from the rules card below. Most rows restate the course pages; the rows marked as house practice are this course’s advice.

RuleFrom
Scams, fake reviews, falsified documents, misuse of private information, impersonating real organizations, bypassing guardrails and ban evasion are prohibited for everyoneUsage Policy
Consumer-facing legal, healthcare, insurance, finance, employment and housing, academic admissions, and automatically generated content published externally are high-risk: professional review before release, and disclosure at a minimum at the beginning of each sessionUsage Policy
Consumer-facing chatbots must tell users they are talking to AI at the start of each chat session, whether or not the use is high-riskUsage Policy
Safety filters are not failsafe. A mistaken warning is raised by email with your details; a wrong suspension is appealed by logging in with that account and using the appeal formHelp center
Be thoughtful with financial details, health records, passwords and confidential documents; at work, your organization’s policy decidesHelp center (consumer products)
Share only what the task needs; never share a passwordHouse practice
Incognito: not in history or memory, not used for training, still retained for a period, included in Owners’ data exports on work plansHelp center
Protected health information needs the HIPAA-ready configuration, which is for Enterprise plans only; Team and individual plans can’t enable itHelp center
Only the Primary Owner can accept the BAA (click-to-accept in organization settings); enabling it is a one-way decision; PHI goes only through covered featuresHelp center
Organization instructions are prompt-level guidance and cannot disable safety policies; capabilities such as web search and file creation are switched on or off by Owners in organization settingsHelp center
Once web search is enabled for the workspace, each member switches it on per chat, where the chat has a web-search toggle (in the new Claude experience there is none; Claude searches when it helps)Help center
When a capability is off, ask an Owner; don’t route work through a personal accountHouse practice
Public projects are open to the whole organization, private ones to invited members; when sharing is off, contact your adminHelp center
Keep a qualified person in the loop, verify against primary sources, document AI useHouse practice, modelled on Anthropic’s legal-work article
Never present AI output as a person’s; a custom AI persona must not claim to be human when sincerely askedUsage Policy, Claude’s constitution
Report inaccurate, biased or harmful output through the report feature where available, or to the user-safety emailUsage Policy

Stage 1 — Sort the requests

Skills: CCAOF-U6.T1.LO1.S1, CCAOF-U6.T1.LO1.S2, CCAOF-U6.T1.LO1.S3 Minutes: 12

Label each request prohibited, high-risk, extra guidelines or ordinary, and give the rule in one line:

  1. A negotiator wants Claude to write an email that looks as if it came from the local council, telling a tenant to leave.
  2. The agency wants a public chat on its website that tells applicants whether they qualify for a tenancy.
  3. A manager wants a checklist for the annual fire-alarm test.
  4. A staff member wants a copy of a tenant’s passport with the date of birth altered.
  5. The website will get a chat that answers questions about viewing times.

Then answer: a property manager’s legitimate question about gas-safety rules is blocked by a filter, and the next day she gets a warning she thinks is a mistake. What should she do, and what should she not do?

Stage 2 — Handle the data

Skills: CCAOF-U6.T1.LO2.S1, CCAOF-U6.T1.LO2.S2, CCAOF-U6.T1.LO2.S3 Minutes: 12

A colleague drafted this prompt:

Summarize the rent arrears for flat 4B. Tenant: J. Rahman, bank sort code 00-00-00, account 00000000, portal password Lettings!2026. She has told us she is in hospital for surgery next month. Arrears: January £400, February £400, March £0.

  1. Rewrite the prompt so that it carries only what the summary needs, and say why each detail you removed can go.
  2. The colleague suggests using an incognito chat “so nothing is kept”. Write two sentences on what incognito would and would not change.
  3. A sister company, a physiotherapy clinic group in the United States, is also on a Team plan. It wants to use its account to summarize patients’ treatment notes. Write what must be in place first, and who can put it in place.

Stage 3 — Set up governance

Skills: CCAOF-U6.T2.LO3.S1, CCAOF-U6.T2.LO3.S2, CCAOF-U6.T2.LO3.S3 Minutes: 14

  1. Draft two lines of organization instructions for the agency, one on tone and one on personal data, and then one line you would like to add but cannot. Say why the last one would not work.
  2. The partners want file creation unavailable to everyone while a data audit runs. Say which lever does that and who pulls it.
  3. A negotiator needs Claude to check a current rule online, but web search is missing from her chats. Write what she should do today and whom she should ask.
  4. Choose public or private for two projects, with the reason: (a) the agency’s house style guide; (b) the partners’ draft salary review.
  5. A negotiator uses Claude to draft a notice to a tenant that cites housing legislation. Write the three-line record the agency should keep about how the notice was produced and checked.

Stage 4 — Use it honestly

Skills: CCAOF-U6.T2.LO4.S1, CCAOF-U6.T2.LO4.S2, CCAOF-U6.T2.LO4.S3 Minutes: 12

  1. Write the opening line the website’s maintenance-request chat should show at the start of each session.
  2. Marketing proposes that the chat introduce itself as “Tom from Maintenance” and, if asked, say it is a real person. Say which part can go ahead and which cannot, and why.
  3. The agency’s weekly tenant newsletter is written by Claude and published on the website automatically, with nobody reviewing it. This week it included a biased line about one group of tenants. The tool has no report button. Write the report you would make and the change to the agency’s process.

Reference solution

Stage 1.

  1. Prohibited: impersonating a real organization to mislead someone.
  2. High-risk, and extra guidelines too: a consumer-facing decision about eligibility for housing needs professional review before release and disclosure at a minimum at the beginning of each session, and because it is a public chat it must also tell users it is AI at the start of each chat session.
  3. Ordinary.
  4. Prohibited: a falsified document, and misuse of private information.
  5. Extra guidelines: it is not high-risk, but as a consumer-facing chatbot it must tell users it is AI at the start of each chat session.

For the blocked question: filters are not failsafe, so the block may be a false positive. She should email about the mistaken warning, with her details and account information, as the help center directs; if her account were ever suspended, she would log in and use the appeal form. She should not reword the question to trick the filter or move to another account.

Stage 2.

  1. For example: Summarize the rent arrears for flat 4B: January £400, February £400, March £0. The bank details go because the task does not need them, and the password goes because a password is never shared. The health detail goes because it is a health record the summary does not need. The tenant’s name goes too: the flat identifies the account, and, as house practice, a summary carries only what the task needs.
  2. Incognito keeps the chat out of history and memory and out of training. It is still retained for a period and, on a work plan, included in the data exports Owners can access, so it is not a way to share what should not be shared.
  3. The HIPAA-ready configuration, which is for Enterprise plans only: on a Team plan it can’t be enabled at all, so the clinic group would first need an Enterprise plan. Then only its Primary Owner can accept the BAA, which is click-to-accept in organization settings, and enabling it is a one-way decision. After that, treatment notes go only through covered features. Until then, they stay out.

Stage 3.

  1. For example: Write in plain, courteous British English. / Never include tenants’ bank details, dates of birth or health information in responses or files. The line that cannot work is anything that switches off Claude’s safety guidelines or content policies: organization instructions cannot disable them. The personal-data line is prompt-level guidance, so test it and do not treat it as a hard control.
  2. A capability setting: an Owner turns code execution and file creation off in organization settings. An instruction would only ask Claude not to.
  3. Work within it today, for example by pasting the official text she already has and asking Claude to work from that. Ask an Owner or the Primary Owner, who enables web search for the workspace; once it is on, she switches it on in her chat where the chat has a web-search toggle (in the new Claude experience, Claude searches when it helps). She should not move the work to a personal account.
  4. (a) Public: everyone should use it. (b) Private, with only the partners invited.
  5. For example: Drafted with Claude on [date] by [negotiator]. / Legislation citations checked against the primary source by [name]. / Reviewed and approved by [qualified person] before sending.

Stage 4.

  1. For example: You’re chatting with an AI assistant. A member of our team will pick up anything it can’t handle.
  2. The name can go ahead as a custom AI persona, as long as the chat says it is AI at the start of each session. Saying it is a real person cannot: presenting AI output as a person’s is prohibited, and Claude will not claim to be human when directly and sincerely asked.
  3. Report the output by email to the user-safety address the Usage Policy gives, since there is no report button. The process change: automatically generated content published for external consumption is a high-risk use, so a qualified person reviews each issue before it is published, readers are told AI helped, and the policy names who reviews and reports problems for the tool.

Sources

Ready to study Claude Certified Associate - Foundations (CCAO-F)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free