Synapse — acceptable use policy
Change history
| Version | Date | Author | Summary of changes |
|---|---|---|---|
| 1.0 | April 2026 | Richard Atkin | Initial issue |
Contents
- Purpose and scope
- Who this policy applies to
- Permitted uses
- Prohibited uses
- Data handling obligations
- User responsibilities
- Monitoring and privacy
- Reporting obligations
- Policy compliance and review
1. Purpose and scope
This policy governs the acceptable use of Synapse by all Conscia UK employees. It describes what Synapse may and may not be used for, the obligations that apply when using it, and the responsibilities that come with access.
This policy should be read alongside the Synapse Security Policy, which describes the technical controls that protect the platform.
2. Who this policy applies to
This policy applies to every Conscia UK employee who has been granted access to Synapse, regardless of their role, seniority, or how they access the platform (web UI or Webex bot).
Access to Synapse is a privilege extended by Conscia UK for business purposes. It may be withdrawn at any time.
3. Permitted uses
Synapse is provided to support Conscia UK employees in their day-to-day work. Permitted uses include, but are not limited to:
Research and knowledge - Researching Cisco products, technologies, and competitive positioning - Searching the Conscia knowledge base for service descriptions, capabilities, and case studies - Looking up current CVEs, bugs, or technical advisories - Searching the web for up-to-date technical or commercial information
Commercial and sales support - Looking up Cisco orders, contracts, part codes, and deal details in CCW - Generating ITGL quote documents from Cisco CCW deals - Querying NetSuite sales and purchase records - Researching project history and client deployments
Productivity and document work - Drafting, reviewing, editing, and improving documents, proposals, and emails - Summarising long documents or extracting key information from attachments - Creating presentations, reports, and structured outputs - Translating or reformatting content
Technical assistance - Troubleshooting technical problems with Cisco, Microsoft, or other vendor products - Writing, reviewing, and explaining code - Running data analysis or file processing tasks in the code sandbox - Generating scripts, configurations, or automation
Internal systems - Searching and reading your own Microsoft 365 email, calendar, and files - Querying Autotask support tickets - Searching the internal projects database
Professional development - Discussing career development, communication, and professional skills - Practising presentations or preparing for meetings
4. Prohibited uses
The following uses of Synapse are prohibited.
4.1 Prohibited data — security-classified and regulated client data
This is the most important restriction in this policy.
You must not input into Synapse any data relating to clients or projects that require background checks, security clearance, or other regulatory approval processes. This includes:
- Any information classified or protectively marked under UK government classifications or equivalent frameworks (OFFICIAL-SENSITIVE, SECRET, TOP SECRET, or equivalent)
- Any data relating to defence, intelligence, law enforcement, or other regulated engagements where specific data handling or security controls apply to the work
- Any information about individuals who are subject to, or undergoing, vetting or security clearance processes
- Any commercially sensitive data provided by a client under a non-disclosure agreement that explicitly prohibits processing by AI or cloud services
If you are working on an engagement that involves — or may involve — security clearances, protective markings, or other regulatory data handling requirements, you must not use Synapse in connection with that work unless you have received explicit written authorisation from the policy owner confirming that its use is appropriate.
If you are unsure whether a particular piece of data falls into this category, do not submit it, and seek guidance from the policy owner before proceeding.
4.2 Prohibited data — sensitive personal data
You must not submit the following categories of personal data to Synapse:
- Health or medical information about identifiable individuals
- Biometric or genetic data
- Criminal conviction or offence data
- Religious, political, or philosophical belief data about identifiable individuals
General personal data (names, job titles, email addresses, professional context) arises naturally in the course of normal use and is acceptable where it is relevant to the business task.
4.3 Prohibited uses — conduct
You must not use Synapse to:
- Generate content intended to deceive, defraud, harass, or harm any individual or organisation
- Impersonate a colleague, client, or any other person
- Create or distribute content that is offensive, discriminatory, or in breach of Conscia's employment policies
- Circumvent any technical, legal, or contractual restriction
- Conduct personal business that is unrelated to your Conscia UK employment
- Test, probe, or attempt to exploit the security of the platform
4.4 Prohibited uses — commercial actions
Synapse provides read access to commercial systems but cannot and must not be used as a substitute for proper commercial process. You must not rely on Synapse outputs alone to:
- Commit Conscia UK to a commercial obligation
- Submit an order or accept a quote
- Make a customer-facing commitment about pricing, availability, or contract terms
All such actions must go through the established commercial process regardless of what Synapse has produced.
4.5 Accuracy reliance
Synapse can and does make mistakes. You must not submit Synapse-generated content to a client, use it to inform a technical action, or make a business decision based on it without appropriate validation. The degree of validation required should be proportionate to the risk — a customer-facing proposal or a technical configuration deserves more scrutiny than an internal draft.
5. Data handling obligations
5.1 Minimise what you share
Share only the data that Synapse needs to complete the task. If a document contains more information than is required, consider extracting the relevant sections rather than uploading the full document.
5.2 Your data is yours
Your conversations, uploaded files, and AI memory are stored under your own account and are not visible to other users through normal platform operation. You are responsible for the data you submit and the outputs you act on.
5.3 AI-generated outputs
Outputs produced by Synapse are generated by an AI model. They may contain inaccuracies, outdated information, or plausible-sounding but incorrect statements. You are responsible for reviewing and validating any output before acting on it or sharing it externally.
Synapse outputs used in customer-facing documents, proposals, technical designs, or communications must be reviewed for accuracy by a suitably qualified person before delivery.
5.4 Retention
Conversation history is retained in Synapse until you delete it. You should periodically review and delete conversations that are no longer needed, particularly those containing sensitive commercial or personal information.
6. User responsibilities
6.1 Account security
- You are responsible for keeping your Microsoft credentials secure. Your credentials govern your access to Synapse.
- Do not share your Synapse session or allow another person to use Synapse under your account.
- If you believe your Microsoft account has been compromised, follow Conscia's account security procedures immediately and notify a Synapse platform administrator.
6.2 Appropriate use
- Use Synapse for legitimate Conscia UK business purposes.
- Apply reasonable judgement about the appropriateness of data you submit.
- When in doubt about whether a use is permitted, ask the policy owner before proceeding.
6.3 Staying informed
- It is your responsibility to read and understand this policy.
- You should be aware that this policy is a living document and may be updated. Material changes will be communicated by the policy owner.
7. Monitoring and privacy
Conscia UK monitors Synapse usage for the purposes of security, operations, and policy compliance. Monitoring includes:
- CloudWatch logs of tool usage, file interactions, authentication events, and sandbox activity, associated with your user identity
- CloudWatch metrics tracking message volume by user
- AWS CloudTrail logs of all API calls, including Bedrock inference calls and the region in which each inference was processed
Monitoring is carried out for legitimate operational and security purposes and in accordance with applicable law. Users should have no expectation that their use of Synapse is private.
Synapse does not log the full content of your messages or AI responses in an accessible form for routine review — but conversation content is stored in S3 under your account and may be accessed by platform administrators in the course of a security investigation or incident response.
8. Reporting obligations
8.1 Suspected security incidents
If you suspect that Synapse has been accessed without authorisation, that your account has been compromised, or that platform security has been breached in any way, you must notify a platform administrator as soon as possible.
8.2 Policy violations
If you become aware that this policy is being violated by another user, you should report this to the policy owner.
8.3 Unexpected or harmful outputs
If Synapse produces an output that appears to be factually dangerous, harmful, or in breach of this policy, do not act on it and report it to the policy owner. Include the conversation context where possible.
8.4 Feature requests
Feature requests and suggestions for improving Synapse are welcome. You can submit a feature request directly in the Synapse chat: "Please log a feature request for..."
9. Policy compliance and review
9.1 Compliance
All users within scope of this policy are required to comply with its requirements. This policy does not replace or supersede any other Conscia UK employment, conduct, or data protection policy — it applies in addition to them.
9.2 Reporting violations
Policy violations should be reported to the policy owner. The policy owner will assess the nature and severity of any reported violation and determine an appropriate response in accordance with Conscia's standard procedures.
9.3 Exceptions
Exceptions to this policy may be granted in writing by the policy owner, with a documented business justification. Exceptions will not be granted where doing so would conflict with Conscia's legal or regulatory obligations.
9.4 Policy review
This is a living document. It will be updated as the platform evolves or as new risks, use cases, or regulatory requirements arise. All updates will be recorded in the change history table. The policy owner is responsible for communicating material changes to all users.