This FAQ may be updated as our tools, processes, or guidance evolve. Always refer to the most recent version on the Employee Portal.
1) What Is Different From the Old AI Chatbot Rules?
2) Does This New Guidance Also Apply to Nexus AI, ChatGPT Enterprise, or Microsoft Copilot?
3) Can I Use Personal or Public Claude Accounts for Nexthink Work?
5) What Can I Generally Use Claude For?
6) What Information Can I Share With Nexthink Claude?
7) Does “Confidential” Mean “Not Allowed in Claude”?
8) What Must Never Be Put Into Claude?
9) Do I Need to Redact or Pseudonymize Information First?
10) Can I Use Personal Data in Claude?
11) Does Anthropic Use Our Prompts or Files to Train Its Models?
12) Can Claude Make Decisions or Take Actions for Me?
13) Can I Use Claude With Outlook, Teams, OneDrive, or Another Business System?
14) How Should I Use the Claude/Cowork Folder?
15) Are Claude Outputs Always Accurate?
16) Who Is Responsible for Claude's Output?
17) Special Rules for P&T / People & Talent
a) What P&T May Use Claude For
b) What P&T Information May Be Provided to Claude
c) What P&T Must Not Use Claude to Do
d) When P&T Should Use the Dedicated P&T AI System Instead
18) What About Legal, Finance, Engineering, Security, or Other Specialized Functions?
b) Finance / General Administration
19) What if I Accidentally Share Confidential Information With Nexthink Claude?
20) What if I Am Not Sure Whether a Use Is Allowed?
Claude is Nexthink's company-wide AI assistant. It is intended to make everyday work faster and easier: drafting, summarizing, analyzing information, creating working documents, preparing presentations, assisting with spreadsheets, brainstorming, research, and similar productivity tasks.
Nexthink has assessed Claude centrally from a privacy, security, confidentiality, and AI-governance perspective. The goal is that employees should not have to perform a separate privacy or confidentiality assessment every time they use Claude.
That does not mean every possible AI use is permitted. This FAQ explains the company-wide baseline and the additional rules that apply to some functions.
This FAQ applies only to Nexthink's managed Claude Enterprise environment. Different rules may apply to other AI services - see Question 2.
For questions not covered by this FAQ, contact dl-privacy@nexthink.com.
1) What Is Different From the Old AI Chatbot Rules?
The previous Nexthink AI chatbot guidance required employees to carefully distinguish between Public, Restricted, and Confidential information before using an AI chatbot. In particular, Confidential information generally required additional approval.
That is not the rule for Nexthink's managed Claude Enterprise environment.
Nexthink has assessed Claude and implemented enterprise controls so that Public, Restricted, and Confidential information can be processed for approved business purposes.
The important questions are now:
- Am I authorized to use this information?
- Is the information actually needed for my task?
- Is the task itself an approved use of Claude?
- Does a department-specific restriction apply?
The confidentiality label alone does not determine whether Claude may be used.
These more permissive rules apply only to Nexthink's managed Claude environment. They do not automatically change the rules for public AI tools or other AI services.
2) Do This New Guidance Also Apply to Nexus AI, ChatGPT Enterprise, or Microsoft Copilot?
No. This FAQ applies only to the Nexthink-managed Claude Enterprise environment made available to Nexthinkers by Nexthink.
The current initiative, assessments, and risk-acceptance decisions specifically covered Claude and the functionality approved as part of the Claude rollout.
The rules in this FAQ therefore do not automatically apply to Nexus AI, ChatGPT Enterprise, Microsoft Copilot, or any other AI tool.
Until Nexthink formally decides to extend these rules - in whole or in part - to another approved AI service, the existing rules and restrictions for that service continue to apply.
In particular, do not assume that information or a use case permitted in Claude is automatically permitted in another chatbot simply because both tools are enterprise AI services.
3) Can I Use Personal or Public Claude Accounts for Nexthink Work?
Do not use a personal or consumer Claude account as a substitute for Nexthink's approved enterprise environment.
The permissions in this FAQ apply to the company-managed Nexthink Claude Enterprise environment.
They do not mean that Restricted or Confidential Nexthink information may be entered into:
- personal Claude accounts;
- consumer/public AI services;
- personal ChatGPT or Gemini accounts; or
- another AI tool that Nexthink has not approved for that information.
Continue to follow the Nexthink Acceptable Use Policy and applicable guidance for other AI tools.
Claude does not currently have direct access to your Microsoft 365 environment.
In particular, Claude cannot independently search or retrieve information from:
- Outlook;
- Teams;
- OneDrive;
- SharePoint; or
- your Microsoft 365 mailbox or files generally.
The Microsoft 365 connector is not being deployed at this time.
For ordinary Claude chat, Claude only receives what you deliberately provide to it - for example, through your prompt or a file you deliberately upload or open through an approved Claude feature.
For Cowork, Nexthink provides a dedicated Claude/Cowork working folder. Cowork has read and write access within that approved folder only. If you want Cowork to work with a file, place the file in that folder deliberately.
This folder is an important control: Claude should not be given unrestricted access to your normal OneDrive, department folders, email, Teams, or other corporate information repositories.
Do not attempt to bypass this model by enabling your own connector, MCP, browser extension, synchronization, or other integration.
5) What Can I Generally Use Claude For?
Typical approved uses include:
- drafting emails and other communications;
- rewriting text for tone, clarity, grammar, or structure;
- summarizing deliberately selected documents;
- comparing documents or versions;
- extracting action items or key points;
- creating first drafts;
- brainstorming;
- preparing meeting materials;
- preparing presentations;
- spreadsheet assistance and analysis;
- translation;
- research;
- creating checklists, tables, timelines, FAQs, and templates;
- analyzing business information relevant to your role;
- creating or modifying non-authoritative working files in the dedicated Cowork folder;
- scripting, coding, or data work where the applicable Engineering/Security guidance permits it; and
- similar productivity assistance.
Claude's output is assistive. The person using Claude remains responsible for the work product.
6) What Information Can I Share With Nexthink Claude?
You may use Public, Restricted, and Confidential information in Nexthink Claude when:
- you are authorized to access and use the information;
- using it is necessary for a legitimate Nexthink business task;
- the Claude use case is permitted; and
- no department-specific or data-specific restriction applies.
Examples may include:
- internal policies and procedures;
- internal correspondence;
- business plans and working documents;
- contracts and commercial information where relevant to your role;
- pricing or financial information where your function is authorized to process it;
- ordinary personal data such as names, business contact information, roles, and work-related information;
- confidential working documents;
- presentations, spreadsheets, reports, and similar materials;
- other information classified as Restricted or Confidential under the Nexthink Confidentiality Policy where it is genuinely needed for the approved task.
You do not need to remove names, prices, contract terms, or other relevant information merely because the information is Restricted or Confidential.
However, normal data minimization still applies: do not give Claude information that has nothing to do with the task.
Example: If you need Claude to compare an entire contract, you may provide the contract if you are authorized to do so. You do not need to remove relevant commercial terms merely because they are Confidential.
If you need Claude to rewrite one paragraph, do not provide a 100-page file containing unrelated information simply because you have access to it.
7) Does “Confidential” Mean “Not Allowed in Claude”?
No.
“Confidential” is a Nexthink information-classification level. It means the information requires strong protection because unauthorized disclosure could cause serious harm, or because Nexthink has a legal or contractual confidentiality obligation.
It does not mean the information can never be processed by an approved enterprise service.
Nexthink's managed Claude environment has been assessed specifically so that Confidential information can be used where necessary for approved work.
You therefore do not need separate compliance and security approval merely because a document is marked Confidential.
You must still respect:
- need-to-know restrictions;
- contractual restrictions;
- legal or professional duties;
- department-specific rules;
- approved purposes; and
-
the hard exclusions in this FAQ (see Question 8).
8) What Must Never Be Put Into Claude?
a) Credentials and secrets
- Never provide secrets or credentials that could be used to gain access to a system or account, including:
- passwords;
- MFA codes;
- authentication tokens;
- API keys;
- private cryptographic keys;
- signing keys;
- recovery codes;
- access secrets;
- PINs;
- CVVs;
- full payment-card credentials; or
- similar authentication or security secrets.
Claude is a productivity tool, not a credential vault.
b) Customer-environment data
Also, do not use the general Claude rollout to process data originating from a customer's Nexthink environment unless the specific use has been separately approved. Examples include:
- endpoint/user activity data;
- raw product logs;
- customer-environment exports;
- screenshots of customer consoles containing customer data;
- device/user identifiers from customer environments;
- customer configurations; and
- similar product/environment data.
Ordinary commercial information about a customer - for example, contracts, account correspondence, pricing, invoices, or business contacts - is different, and may be used where your role and applicable department guidance allow it.
If a dedicated Nexthink tool or workflow has been approved for customer-environment data, follow the rules for that tool.
9) Do I Need to Redact or Pseudonymize Information First?
Not as a general requirement.
You do not need to redact or pseudonymize information solely because you are using Nexthink Claude, or because the information is Restricted or Confidential.
You should nevertheless remove information that is not needed for the task.
Pseudonymization can still be useful where it is easy and does not reduce the usefulness of the task, but employees should not spend significant time sanitizing information that Claude has already been approved to process.
The simple rule is: Give Claude what it needs for the task - not everything you happen to have access to.
10) Can I Use Personal Data in Claude?
Yes, where the personal data is necessary for an approved business task and you are authorized to use it.
Personal data is classified at least Restricted under the Nexthink Confidentiality Policy, but that classification does not prevent its use in Nexthink Claude.
Examples of ordinary permitted uses may include:
- drafting a business communication involving named colleagues or business contacts;
- summarizing a document containing ordinary professional contact details;
- reorganizing work-related information;
- preparing a document or presentation using relevant employee or external-contact information.
However, the fact that personal data can be processed does not mean every decision about a person may be delegated to Claude.
Do not use Claude as an automated decision-maker or as the sole basis for a consequential decision affecting an employee, candidate, customer, partner, or other individual.
Use by P&T or those involved in the recruiting process (including hiring managers and other employees) has additional restrictions - see Question 17.
11) Does Anthropic Use Our Prompts or Files to Train Its Models?
Nexthink uses an enterprise Claude environment with contractual and technical protections for company data.
Nexthink prompts, files, and outputs submitted through the approved enterprise environment are not used by Anthropic to train its general models.
This is one of the reasons why these rules are different from the rules applicable to public or personal AI accounts.
12) Can Claude Make Decisions or Take Actions for Me?
Claude may assist you with analysis, recommendations, drafts, or working materials, but it must not replace required professional or managerial judgment.
Do not treat Claude output as automatically correct.
For consequential matters, verify the underlying facts and apply the review required by your function.
Examples:
- Claude may draft a communication; the responsible employee decides whether to send it.
- Claude may analyze a spreadsheet; Finance remains responsible for the financial conclusion.
- Claude may help prepare a legal draft; Counsel remains responsible for the legal judgment.
- Claude may help P&T prepare an administrative communication; P&T remains responsible for the underlying employment action.
- Claude must not independently determine whether an employee should be promoted, disciplined, terminated, or receive a particular compensation outcome.
Use only the actions and automation features that Nexthink has approved and enabled for your department.
13) Can I Use Claude With Outlook, Teams, OneDrive, Salesforce, NetSuite, or Another Business System?
Not unless Nexthink has specifically approved and enabled that integration.
At the time of this FAQ:
- the general Microsoft 365 connector is not enabled;
- Claude does not automatically search Outlook, Teams, or OneDrive;
- employees must not enable their own corporate connectors or MCPs; and
- a connector being technically available from Anthropic does not mean Nexthink has approved it.
Additional integrations are assessed separately before rollout. If Nexthink later enables an approved connector for your department, specific guidance for that connector will apply.
14) How Should I Use the Claude/Cowork Folder?
Treat the dedicated Claude/Cowork folder as a working area.
Place into it only the files needed for the task you want Cowork to perform.
Cowork may read files from, and create or modify files within, that dedicated working area.
The folder controls access, not approval. A file does not become permissible for Claude simply because you copy it into the Claude/Cowork folder. The information itself and the task you want Claude to perform must still comply with this FAQ and any applicable department-specific rules.
Do not:
- copy entire repositories or department drives into the folder “just in case”;
- use the folder as the permanent system of record;
- keep unnecessary sensitive files there indefinitely; or
- move data there merely to bypass restrictions applying to another system.
When the task is complete, make sure authoritative records are stored in the appropriate Nexthink system or repository.
15) Are Claude Outputs Always Accurate?
No.
Claude can:
- misunderstand a document;
- overlook relevant context;
- give an incomplete answer;
- make an incorrect inference;
- invent a fact or source;
- perform a calculation incorrectly; or
- produce confident language even when the answer is wrong.
Always review the output at a level appropriate to the risk of the task.
The more consequential the task, the more carefully you should verify the result against the underlying source material.
You remain responsible for work you use or share.
16) Who Is Responsible for Claude's Output?
You are.
Claude assists you; it does not assume your professional, managerial, or legal responsibility.
Claude and Cowork outputs are working materials, not authoritative records merely because Claude created them. Where a document, figure, decision, or other output must become part of Nexthink's official record, store the reviewed final version in the appropriate authoritative system or repository.
Before using important output:
- read it;
- check the material facts;
- verify important calculations, citations, or source material;
- apply your professional judgment; and
- obtain any approval that would have been required if you had created the work without AI.
Do not use “Claude said so” as the basis for a business decision.
17) Special Rules for P&T / People & Talent
P&T may use Nexthink Claude for general productivity and administrative P&T work.
The restriction is not that “HR data cannot go into Claude.” The key restriction is that Claude must not become the system that evaluates people or determines consequential employment outcomes.
Members of P&T may use Public, Restricted, and Confidential information in Claude for the permitted P&T uses below, provided they are authorized to use the information and provide only what is needed for the task.
a) What P&T May Use Claude For
Examples include:
- drafting or improving general employee communications;
- drafting P&T policies, procedures, FAQs, training materials, and manager guidance;
- preparing presentations;
- creating P&T templates and checklists;
- restructuring or summarizing general P&T documents;
- translation and language improvement;
- preparing onboarding or offboarding materials;
- preparing neutral job descriptions or recruiting communications;
- drafting general interview guides or administrative recruiting materials that do not evaluate a particular candidate;
- brainstorming communication approaches;
- summarizing or restructuring information for administrative purposes where Claude is not asked to evaluate the employee or candidate;
- working with aggregated or genuinely anonymized P&T information;
- preparing routine administrative communications reflecting a decision that authorized humans have already made.
The last example is permitted because Claude is drafting the communication after the compensation decision has already been made. Claude must not determine or recommend the compensation outcome.
b) What HR Information May Be Provided to Claude
For an approved P&T productivity task, P&T may provide relevant:
- ordinary employee identification and contact information;
- job title, department, manager, work location, and similar employment information;
- P&T policies and procedures;
- routine P&T correspondence;
- internal P&T working documents;
- approved compensation information where needed for an administrative task after the underlying decision has been made;
- other Confidential P&T information where the task is administrative and does not use Claude to evaluate or make a decision about the person.
Again, Confidential classification alone does not prohibit the use.
However, especially sensitive individual case files must not be put into Claude for general-purpose analysis.
This includes, unless a specific approved use says otherwise:
- disciplinary investigations;
- misconduct allegations;
- grievances;
- whistleblowing matters;
- detailed performance case files;
- termination case files;
- medical information;
- disability or accommodation case files;
- detailed sickness/absence case files;
- DEI or protected-characteristic files;
- trade-union or works-council case information;
- criminal-allegation information;
- employee investigations; and
- similar highly sensitive employee case files.
Where AI assistance is needed for such a matter, use the dedicated approved P&T system where one exists, or follow the established P&T/Legal process.
Candidate-specific application materials, interview recordings, interview notes, scorecards, candidate rankings, and other candidate-evaluation information must not be processed through general-purpose Claude for screening or evaluation. Where Nexthink has approved the relevant functionality in the dedicated P&T recruitment system, use that system instead. Until such functionality has been approved and rolled out, continue using the established recruitment process.
c) What P&T Must Not Use Claude to Do
Claude must not be used to:
- screen, rank, score, or compare candidates;
- decide which candidates should progress;
- evaluate interviews or candidate suitability;
- make hiring recommendations about identifiable candidates;
- rank or score employees;
- evaluate employee performance for employment decisions;
- recommend promotions;
- recommend termination;
- recommend disciplinary action;
- decide or recommend compensation outcomes;
- decide bonuses, salary increases, or equity awards;
- allocate work based on employee profiling;
- monitor employee behavior or productivity for employment evaluation;
- infer an employee's health, personality, emotions, honesty, engagement, or similar characteristics;
- decide accommodation or absence-management outcomes;
- determine whether an employee committed misconduct or fraud;
- analyze grievances or complaints for the purpose of deciding an employment outcome; or
- otherwise make or materially support a consequential employment decision.
Claude can help with routine drafting and administration around a decision made by the appropriate human decision-makers. It must not become the decision-maker or evaluator.
d) When P&T Should Use the Dedicated HR AI System Instead
For recruitment-specific AI use that involves screening, ranking, matching, interview analysis, or other candidate evaluation, use the dedicated P&T recruitment system where and once Nexthink has approved the relevant functionality rather than recreating the use case in general-purpose Claude.
Depending on the scope ultimately approved, this may include:
- interview recording and transcription;
- AI interview notes;
- candidate sourcing;
- candidate matching or ranking;
- application review or screening;
- candidate comparison;
- recruitment-specific candidate evaluation;
- application-integrity/fraud indicators;
- recruiting analytics; and
- recruiting outreach functionality.
Do not recreate these high-risk recruitment functions in Claude simply because Claude is technically capable of doing so.
If an P&T use case involves employee performance, promotion, termination, compensation decisions, discipline, monitoring, grievances, accommodations, or another consequential employee decision, and no dedicated AI system has been approved for that use, continue using the established P&T process. Contact dl-privacy@nexthink.com before introducing AI decision support.
e) Simple Rule
Claude can help P&T write, summarize, organize, and prepare.
Claude must not be the tool that judges, ranks, scores, monitors, or decides about employees or candidates.
For recruitment AI evaluation, use the dedicated P&T recruitment system only where the relevant functionality has been approved and rolled out by Nexthink.
18) What About Legal, Finance, Engineering, Security, or Other Specialized Functions?
The company-wide baseline applies to everyone, but some departments have additional approved uses or restrictions because of the information they handle.
Always follow function-specific training or guidance where it exists.
Legal may use Claude/Cowork for approved drafting, summarization, comparison, research, document analysis, and preparation of non-authoritative Legal working materials. Legal is not subject to a blanket prohibition on Confidential or privileged information: Counsel may deliberately provide privileged or professionally confidential material through the approved Cowork workflow where this is appropriate for the matter. Counsel must exercise professional judgment and must not use Claude where applicable law, professional rules, client/matter restrictions, or other confidentiality requirements make third-party AI processing inappropriate.
Whistleblower reports and investigations, underlying P&T investigations involving sensitive personal data, and matters primarily involving criminal-offense data are not part of ordinary Legal Claude use and require specific consideration before Claude is used.
Claude does not replace Counsel's professional judgment. Material legal conclusions, citations, deadlines, and factual assertions must be checked against authoritative sources.
b) Finance / General Administration
Finance may use Claude/Cowork for approved Finance administration and analysis, including invoices, billing, collections, reconciliation, forecasting, budgeting, reporting, audit support, payroll administration, and expense reimbursement.
Payroll, benefits, tax, and expense records may contain sensitive personal data. Such information may be processed where it is genuinely necessary for an approved payroll, tax, benefits, or reimbursement task, but Claude must not be used to search for, infer, classify, compare, or report on employees according to health, disability, trade-union membership, religion, or another sensitive characteristic.
Claude/Cowork must not determine compensation, benefits, expense approval, misconduct, fraud, performance, or another employment outcome.
Underlying medical documentation, union correspondence, and P&T case files remain outside ordinary Finance use.
Claude/Cowork must not execute or approve payments, change bank or supplier-master data, submit payroll, post journal entries, submit tax filings, approve invoices or expenses, or make external commitments.
All material Finance figures, bank details, dates, and accounting conclusions must be verified against the authoritative source.
Marketing may use Claude for approved campaign and creative content, marketing collateral, brand/style materials, market research, and campaign-performance analysis. Ordinary individual-level campaign or business-contact data may be used where it is necessary for the approved Marketing task and the user is authorized to process it.
Marketing must not use Claude with customer Nexthink-environment/end-user telemetry or other customer product data covered by the general exclusion in Question 8.
Marketing must not provide payment credentials or other access secrets.
Do not use improperly obtained competitor information.
Unreleased financials, M&A information, detailed non-public corporate budgets, or other highly sensitive corporate information that is not necessary for an approved Marketing task must not be provided merely because the user can access it.
Confidential agency, partner, or third-party information may be used only where Nexthink is authorized to process it for the specific task and no contractual or other restriction prohibits the AI use. Do not assume that access to third-party confidential material automatically authorizes submission to Claude.
Do not create scripts, browser extensions, live feeds, or workaround connections into Salesforce, Marketo, or another business system. Manually exported information may be used only where the underlying data and task are otherwise permitted.
IT may use Claude for ordinary administrative, documentation, scripting, and routine ticket-related work where permitted by applicable Security guidance.
Never provide credentials, passwords, MFA codes, API keys, tokens, private/signing keys, or other access secrets.
Customer-environment data remains subject to Question 8.
Security incidents, highly sensitive vulnerability information, exploit material, or other specialized security content must follow Security-specific guidance rather than being assumed to fall within the ordinary company-wide baseline.
Department-specific training and approved-use guidance take precedence over the general examples in this FAQ where they impose a narrower rule.
19) What if I Accidentally Share Confidential Information With Nexthink Claude?
If the information was permitted for your task under this FAQ, the fact that it was Confidential does not make the use an incident.
For example, deliberately providing an authorized Confidential contract to Nexthink Claude for an approved contract-analysis task is not an accidental disclosure merely because the contract is Confidential.
However, report the matter through the normal Security/Privacy incident process if you:
- provided information you were not authorized to use;
- exposed credentials or authentication secrets;
- entered Restricted or Confidential Nexthink information into an unapproved/public AI service;
- shared customer-environment data outside an approved workflow;
- used a prohibited integration or account; or
- believe information has been disclosed to an unauthorized party.
Early reporting helps Nexthink contain and assess the issue.
20) What if I Am Not Sure Whether a Use Is Allowed?
First ask:
- Am I using Nexthink's managed Claude account?
- Am I authorized to use the information?
- Is the information actually needed for my task?
- Am I asking Claude to assist with work, or am I asking it to make a consequential decision?
- Does my department have additional guidance?
- Am I trying to connect Claude to a system or feature that Nexthink has not approved?
If the answer remains unclear, contact dl-privacy@nexthink.com.
For security-sensitive questions or incidents, follow the standard Security process.
1. USE THE NEXTHINK ACCOUNT
Use Nexthink's managed Claude Enterprise environment for Nexthink work.
2. PUBLIC, RESTRICTED, AND CONFIDENTIAL ARE ALLOWED
The classification label alone does not prevent use in Claude. You must still be authorized to use the information and need it for an approved task.
3. GIVE CLAUDE ONLY WHAT IT NEEDS
No unnecessary data. Never provide passwords, tokens, API keys, private/signing keys, or other access secrets. The Claude/Cowork folder controls technical access — putting a file there does not make an otherwise prohibited use permissible.
4. CLAUDE ASSISTS - NEXTHINKERS REMAIN RESPONSIBLE
Review important outputs. Do not delegate consequential decisions to Claude.
5. DO NOT BUILD YOUR OWN INTEGRATIONS
Claude does not currently have general access to Outlook, Teams, OneDrive, or other corporate systems. Only use connectors, MCPs, automation, browser access, and other integrations that Nexthink has expressly approved and enabled for your role.
***