1. Scope
This policy applies to AI models, agents, robots, devices, plugins, SDKs, API clients, and human operators that read data from, write data to, or take actions through Bippsi.
2. Operator Responsibility
The account holder and, where applicable, organization are responsible for selecting the agent, granting access, reviewing capabilities, funding activity, and responding to harmful or incorrect behavior. An agent is not a separate legal account holder and cannot expand its own authority.
3. Authority and Account Context
- Every action must carry an explicit tenant and account context.
- Agents may use only granted scopes, connected resources, approved tools, and valid credentials.
- Revocation, suspension, budget limits, legal holds, privacy gates, and safety controls override model instructions.
- A user prompt cannot weaken platform, security, privacy, legal, payment, or physical-safety rules.
4. Data and Memory
Agents receive only data the user or organization has authorized for the active context. Memory, Mail, Drive, Locker, contacts, Commerce, and device data remain separately permissioned. Bippsi Managed routes must use approved providers and evidence-backed privacy settings. Agents must not infer that a fallback, summary, or memory is current truth when a live authoritative source is required.
5. Actions and Confirmation
High-impact, irreversible, regulated, financial, external-communication, and physical actions require the platform's policy and confirmation gates. Retries must be idempotent. Agents must verify outcomes and initiate corrective action when they cause a recoverable error.
6. Prohibited Agent Conduct
- Credential theft, privilege escalation, prompt-injection propagation, hidden data exfiltration, or cross-account access.
- Bypassing payment, consent, age, identity, business, sanctions, tax, or product-eligibility controls.
- Representing generated information as verified fact without the required evidence.
- Making deceptive purchases, disputes, signatures, messages, listings, or reviews.
- Continuing an action after revocation, budget exhaustion, safety stop, or a provider response that leaves the result uncertain.
7. Economic Activity
Paid agent activity uses the current published price, approved Action Credit or payment authority, and transaction-specific evidence. Sandbox and promotional credits follow their grant terms and have no cash value. Refunds and reversals follow the Refund Policy and Commerce Settlement Kernel.
8. Monitoring and Enforcement
Bippsi may retain content-minimized receipts, hashes, provider references, risk decisions, and audit events needed to secure and reconcile agent activity. Bippsi may pause or revoke an agent, key, device, connection, route, or account when activity is unsafe, unauthorized, abusive, or unreconciled.