Appendix D — Safety, data handling, and responsible AI
- Use only the mock documents provided for the training.
- Never paste secrets, tokens, credentials, card numbers, patient data, real customer PII, or production configuration into prompts.
- Review every Copilot and agent output before sharing or acting on it.
- Apply the highest classification of the source material to any generated content.
- Treat correlation as a hypothesis; validate before presenting it as cause.
- For agents, enforce grounding, least privilege for actions, and explicit refusal rules; red-team before sharing.
- If a response seems unsupported, ask the tool to show its sources or method, then verify manually.
- For real Contoso Group work, follow approved company policy and tenant configuration.
- Treat any Copilot forecast, projection, or what-if result as a scenario built from the data you supplied, not a prediction of what will happen; state the assumptions, keep the projection inside the periods the source data covers, and have a finance or business owner review it before it informs a decision.
Synthetic training materials. No real Contoso Group confidential information, patient, customer, employee, financial, or supplier data is included.