A policy nobody reads is a policy nobody follows
Most AI policies end up as a PDF in a shared drive. Staff hit a question mid-task — can I put this in Copilot? — and either guess, or email someone and wait two days.
This sits between those two outcomes. It answers in seconds, strictly from your documents, and hands off to a named person the moment it isn't certain.
See it working
The demo runs on a fictional nonprofit — Riverside Community Trust — with a complete AI policy and an approved tools list behind it.
Yes. Drafting a newsletter is writing assistance, which is an approved use, and Copilot is the Trust's primary approved tool. Newsletters are published material, so this is fine — just make sure a person reviews the draft before it goes out.
Per: AI Use Policy · Approved AI Tools List
AI meeting transcription is approved for internal meetings only, but explicitly not for supervision or one-to-one meetings. Supervision often touches on personnel matters, which is why it's excluded.
Per: Approved AI Tools List
Please contact Alex Rivera, Operations Director, before proceeding.
The second answer is the one worth noticing. That rule sits in the approved tools list rather than the policy itself — the assistant finds it, says which document it came from, and stops rather than guessing.
Try asking it:
- “Can I paste a client's case notes into ChatGPT to summarise them?”
- “Can I use AI to help score job applications?”
- “Can I use AI to translate our housing leaflet into Polish?”
Reading the source policy alongside the answers is worth a few minutes. Every verdict traces back to a clause you can find, which is the whole basis for trusting it — and it makes obvious how much the quality of the answers depends on the quality of the policy.
The admin side
The half nobody sees in a demo, and the half that makes it worth building. Whoever owns the policy gets a dashboard: every question asked, filterable by Green, Yellow or Red and by date, with the documents editable in the browser.
You can log into the demo's dashboard and look around. It is a view-only account, so the documents and the log are read-only — everything else works exactly as it does for a real administrator.
Demo dashboard
aipolicy.bridgesstrategy.com/demo/admin/login
Email: [email protected]
Password: SeeTheDashboard
The question log fills up with whatever visitors to this page have asked, which makes it a reasonable illustration of the real thing: a pile of unfiltered questions, some of them revealing. That is what the policy owner reads once a month.
What makes it trustworthy
It only knows your documents
No general knowledge about AI, no advice from the internet, no filling gaps with something plausible. If your policy doesn't cover it, it says so.
A verdict, not an essay
Green, Yellow or Red, then two sentences of plain English and the document it came from. Readable on a phone between meetings.
It knows when to stop
Anything ambiguous, prohibited or beyond the documents ends with a named person to contact. It removes hesitation; it doesn't replace judgement.
It keeps a record
Every question is logged. Reviewed monthly, that log is a live map of where your policy is unclear — written by the people who actually have to follow it.
Two ways to do this
One you can put together this afternoon with no help from anyone. One that is a proper application, hosted at your own web address — which is what the demo above actually is.
| Build it yourself | Purpose-built | |
|---|---|---|
| Setup | About fifteen minutes | About a day |
| Cost | Free, using seats you already pay for | Around $10 a month, all in |
| Staff access | Anyone with a paid AI account | Anyone with the link — no login at all |
| Question log | None | Every question, automatically and anonymously |
| Documents | Pasted into the assistant's instructions | Managed in a browser by whoever owns the policy |
| Lives | Inside your AI tool | At your own web address |
Option 1 — build it yourself
An assistant your staff can ask, that hands off to a named person when it isn't sure. No log, no admin side, no developer. You need your AI policy as text you can copy, and someone willing to be the contact for anything unclear.
- Open the AI tool your organisation already uses and create a new custom assistant — a Custom GPT in ChatGPT, a Project in Claude, a Gem in Gemini, or an agent in Copilot.
- Copy the prompt below into its instructions.
- Replace the highlighted placeholders with your organisation's name, your policy owner, and their email.
- Paste your full policy text where the prompt says to.
- Save it, then share the link — in Teams, on your intranet, or in an email signature.
You are the AI Policy Assistant for [ORGANISATION]. Answer only from the policy below. Never use outside knowledge about AI tools, vendors, or best practice — if it is not in the policy, you do not know it. Reply in this format every time: **[GREEN / YELLOW / RED]** Two or three sentences, plain language, explaining why. *Source: [section or heading you relied on]* GREEN = clearly allowed RED = clearly prohibited YELLOW = ambiguous, not addressed, or depends on specifics If the policy does not clearly cover the question, say so and answer YELLOW. Never fill a gap with general knowledge or a reasonable guess. End every YELLOW or RED answer with: "Please check with [NAME] at [EMAIL] before proceeding." Do not ask for or repeat real names, client records, donor details, or other personal information. If a question contains them, answer the general question and remind the person to leave personal details out. --- POLICY BEGINS --- [PASTE THE FULL POLICY TEXT HERE] --- POLICY ENDS ---
Paste the policy into the instructions rather than attaching it as a file. Attached files get searched in fragments, so the assistant sometimes misses a relevant clause. Pasted text is always fully in view. For policies under about twenty pages this makes a real difference to accuracy.
Got more than one document? Most real questions turn on the detail in an approved tools list or a data guide rather than the policy itself. Paste those in too, and add this line above them so the assistant knows which one wins: “These sources are listed in order of authority. The AI Use Policy governs — if a supporting document conflicts with it, follow the policy and say you noticed the conflict.”
Option 2 — a purpose-built assistant
A small web application that lives at your own address — aipolicy.yourorganisation.org — and does the job properly. This is what you tried at the top of this page.
Nobody has to log in
Staff click a link and ask. No account, no seat, no password. That matters more than it sounds: in most nonprofits only some people have a paid AI licence, and the ones most likely to have a policy question are often the ones without one.
Every question is logged, anonymously
Nothing to fill in, nothing to remember. The question and the answer are recorded automatically, with no name attached to either. Anonymity isn't an oversight — it's the point. People ask the awkward question when it can't be traced back to them, and the awkward questions are the ones you most need to see.
An admin dashboard for whoever owns the policy
They log in and see every question asked, filterable by Green, Yellow or Red and by date. They can add, edit and retire documents in the browser — no redeploying anything — and update the named contact staff are pointed at. Change the policy in the morning and the answers change immediately.
What it takes
Around $10 a month for hosting and AI usage combined, an account with an AI provider, and about a day to set up. It runs on infrastructure you own and pay for, so it stays yours — and if you ever want to move it, everything exports as a single file.
I can build it with you or for you. If you have someone technical in-house, it is a genuinely small application — the version behind the demo on this page was built in an afternoon with an AI coding tool, which is rather the point.
Using the log — the part most people skip
The answers help one person for one minute. The log is what improves the policy, and it's worth putting a recurring half hour in the diary for it. This applies whether you're reading a dashboard or a handful of forwarded emails.
- Read the month's questions in one sitting. Themes are obvious in a batch and invisible one at a time.
- Look for repeats. The same question asked three times is a gap in the policy, not three confused people.
- Edit the document, not the assistant. Add the missing clause to your policy and the assistant improves immediately — and stays auditable, because every answer still traces back to an approved document.
- Tell people what changed. Staff who see their question turn into policy ask more questions. That's the flywheel.
Don't let the assistant learn from its own answers. It's tempting, but a policy tool has to be auditable — you need to be able to say why it gave an answer and point at the clause. Keep the humans in the loop and the documents as the single source of truth.
Which one you need
Start with Option 1. It costs nothing, it takes an afternoon, and a policy your staff can actually ask questions of beats a better plan you haven't built. You'll also learn what people ask, which is worth knowing before you spend anything.
Three things tend to push organisations to Option 2. You want to see everything being asked rather than only what reaches you. Staff without a paid AI licence need it too. Or the person who owns the policy wants to manage the documents themselves, without going back to whoever set the assistant up.
Be aware of one limit either way: a prompt asks an AI tool for consistency, where an application enforces it. Expect the DIY version to drift from its format occasionally. It's a fair trade at zero cost, and it's the main thing you're buying out of when you move up.
Or we can do it together
I help nonprofits put this in place — from a single working session to a hosted version running on infrastructure you own, with your documents loaded and your team shown how to keep it current.
Stay current on AI in the nonprofit sector
A weekly digest of curated news and use cases for nonprofit leaders. Sent every Monday.
No spam. Unsubscribe anytime. We do not share subscriber data.