All articles
Associate
15 min read

CCA-F Domain 6 Study Guide: Governance, Risk, and Responsible Use

Domain 6 (15%, ~9 items) — appropriate and inappropriate use cases, data sensitivity and privacy, organisational AI policy, and when to stop or escalate.

Domain weight: 15% (approximately 9 of 60 items). Based on Exam Guide Version 1.0, effective July 2026; study-guide edition updated August 1, 2026.

Domain purpose

Domain 6 tests judgment before and during Claude use: whether a use case is appropriate, what data may be used, which rules apply, who could be affected, and when work must be restricted, anonymized, reviewed, or stopped.

This guide does not repeat output bias testing from Domain 2 or connector setup from Domain 5. It focuses on permission, purpose, policy, data classification, accountability, and ethical consequence.

Official objectives

Candidates are expected to:

  • Identify appropriate and inappropriate use cases.
  • Apply data sensitivity, regulatory, and privacy considerations.
  • Follow organizational AI policies and governance standards.
  • Understand the ethical implications of AI usage.

Responsible-use framework: GUARD

GUARD is a study framework, not an official Anthropic acronym. It organizes the questions an Associate should ask before and during any use of Claude.

LetterElementKey question
GGoalIs the purpose legitimate, beneficial, and permitted?
UUsers and affected peopleWho supplies data, receives the output, or bears the consequence?
AAuthority and applicable rulesWhat law, contract, policy, role, consent, and access permission apply?
RRisk controlsWhat minimization, anonymization, review, restriction, or escalation is required?
DDocumentation and decisionRecord the approved purpose, source, control, reviewer, and outcome.

Appropriate and inappropriate use cases

  • Generally appropriate: drafting from approved facts
  • Generally appropriate: summarizing non-sensitive documents
  • Generally appropriate: brainstorming low-risk ideas
  • Generally appropriate: organizing information
  • Generally appropriate: creating agendas, templates, and plans
  • Generally appropriate: research support using permitted sources
  • Higher-risk: legal, medical, financial, safety, or regulatory work
  • Higher-risk: employment or access decisions
  • Higher-risk: work involving children or vulnerable people
  • Higher-risk: customer commitments
  • Higher-risk: regulated or confidential data
  • Higher-risk: automated external actions
  • Higher-risk: surveillance or profiling
  • Higher-risk: decisions with irreversible consequences

Inappropriate use is determined by the purpose, data, action, policy, and applicable terms - not only by the topic. Consult the current Anthropic Usage Policy and organizational rules; do not rely on a memorized list.

An Associate should escalate when the use case needs legal interpretation, security architecture, specialized professional judgment, or an exception to policy.

Data sensitivity and minimization

Before entering or connecting data, classify it according to organizational policy. Common categories include public, internal, confidential, personal, regulated, and highly restricted data.

  • Is this data necessary for the purpose?
  • Am I authorized to use it here?
  • Is the chosen account and product approved?
  • Can identifiers be removed or replaced?
  • Does the output expose sensitive information?
  • Who can access the chat, Project, file, connector, or shared artifact?
  • How long should the information remain available?

Data minimization means using the least data necessary. For trend analysis, aggregate or anonymized data may be sufficient. Do not upload names, account numbers, health data, credentials, or confidential material merely because Claude can technically process files.

Anonymization must be effective. Removing a name may not be enough if combinations of location, role, date, and unique events re-identify a person.

Product and account context matters

Do not generalize one privacy statement across every Claude product. Anthropic's current Privacy Center distinguishes consumer products from commercial products. It states that commercial-product inputs and outputs are not used to train models by default. Consumer-product model-improvement use depends on the user's setting and current policy.

Retention, administrative access, enterprise controls, and contractual terms can also differ. Verify:

  • consumer versus work/enterprise account;
  • organization agreement;
  • training or model-improvement setting;
  • retention setting;
  • Project or chat sharing;
  • connector permissions;
  • administrator access;
  • applicable region and regulation.

Never promise “Claude does not retain data” or “no one can access this chat” without checking the actual product, setting, agreement, and current official policy.

Follow organizational governance

Organizational policy may be stricter than product capability. Technical access is not business approval. Governance may specify:

  • approved accounts and products;
  • prohibited data classes;
  • allowed use cases;
  • required review and disclosure;
  • connector and sharing restrictions;
  • retention and recordkeeping;
  • intellectual-property handling;
  • incident reporting;
  • procurement and vendor review;
  • monitoring and audit.

When uncertain:

  • stop before entering data or taking action;
  • consult the current policy;
  • ask the named data owner, manager, privacy, security, legal, or compliance contact;
  • document the decision.

Do not bypass a policy by using a personal account, copying data manually, removing a label, or instructing Claude not to retain information.

Permissions, connectors, and actions

Connectors can retrieve data and may perform actions within connected services. They inherit user permissions, but permission to access a record does not automatically mean it is appropriate to use for a new purpose.

Before use:

  • confirm the connector is approved and trusted;
  • review read/write capabilities;
  • use least privilege;
  • restrict consequential actions;
  • confirm the user understands what will happen;
  • review output destinations and sharing.

For browser or computer actions, prefer review and approval where consequence exists. Anthropic's current permissions guidance warns that modes skipping approvals should be used only when every action, connector, file, and app involved is completely trusted.

Ethical implications

Ethical review extends beyond legal compliance. Consider:

DimensionKey question
FairnessAre comparable people treated consistently?
TransparencyShould recipients know AI assisted the work? Follow organizational and contextual disclosure rules.
AccountabilityWho owns the final decision and correction?
AutonomyDoes a person retain meaningful choice and ability to challenge the result?
PrivacyIs the data use proportionate to the purpose?
Human impactCould the workflow disadvantage, exclude, manipulate, or harm someone?
ReliabilityIs the system being used beyond what evidence supports?
Intellectual propertyAre source rights, confidentiality, and attribution respected?
Workforce impactAre role changes, training, workload, and oversight addressed honestly?

Ethics is not solved by adding a disclaimer after a harmful design. Controls must shape the workflow itself.

Incident response

If sensitive data is entered, shared, or exposed incorrectly:

  • stop further sharing or action;
  • preserve necessary facts without spreading the data;
  • follow organizational incident policy;
  • notify the appropriate privacy/security owner promptly;
  • do not conceal or independently improvise remediation;
  • document what happened, where, when, and who may be affected.

Deletion may be useful but does not replace required reporting or prove that every copy has disappeared.

Common traps

  • “Internal use” means any data is allowed.
  • Technical access equals authorized purpose.
  • Telling Claude not to retain data satisfies policy.
  • Removing names always anonymizes a dataset.
  • Consumer and commercial privacy terms are identical.
  • A connector can be trusted because it is convenient.
  • Legal compliance is the complete ethical test.
  • A disclaimer removes accountability.
  • Human review is meaningful without authority or criteria.
  • Using a personal account bypasses a work restriction.
  • Sharing an Artifact exposes only its title.
  • Deleting a chat automatically resolves an incident.
  • Product capabilities are fixed and policy never changes.

Seven-day study plan

  • Day 1: Classify ten use cases by purpose, risk, and escalation.
  • Day 2: Practice data classification and minimization.
  • Day 3: Compare current consumer and commercial privacy guidance.
  • Day 4: Map organizational governance roles and approval routes.
  • Day 5: Threat-model connector, sharing, and action scenarios.
  • Day 6: Analyze ethical impact and incident cases.
  • Day 7: Complete nine questions and review current Usage Policy and privacy pages.

Use governance blogs as explanations, never as substitutes for current policy, legal guidance, or organizational instructions.

Readiness checklist — rate your confidence on each item below.

  • 0Not confident
  • 1Somewhat confident
  • 2Fully confident
StatementYour score
I assess purpose, people, authority, risk, and documentation.
I minimize and anonymize data appropriately.
I distinguish technical access from authorized use.
I verify product/account-specific data terms.
I follow organizational policy and escalation routes.
I consider fairness, transparency, accountability, autonomy, and impact.
I know the first steps in a data incident.

Your total

0 / 14

Score all 7 statements to see your verdict — 7 left.

TotalVerdictNext action
06Not readyRevisit the GUARD framework and data-sensitivity sections before attempting practice questions.
710Getting thereFocus on the weakest checklist items and re-review governance and incident-response sections.
1114Exam readyProceed to the nine-question quiz and the seven-day study plan for final review.

Sources

Keep reading