6.1 · Lesson 1 of 4
Appropriate vs Inappropriate Use
What you need to know
Domain 6 is Governance, Risk, and Responsible Use (15%). Lesson 6.1 draws the line between what Claude can do and what you may do. Capability is not permission. Know appropriate use, stop when policy or stakes say no, and escalate needs that go beyond the claude.ai chat product.
Appropriate vs inappropriate
- Appropriate — drafting, summarising, analysing material you are permitted to use, brainstorming, and editing, with review proportional to the stakes.
- Inappropriate — pasting data you may not share, making unreviewed decisions about people, and treating output as authoritative where accuracy is critical without review.
Classify before you act
Useful triage: appropriate, appropriate with conditions (for example remove names or add human review), or escalate. Conditions must be specific and checkable. Escalations name a destination — security, legal, or the integrations team — not a vague “someone.”
Worked example
Ten requests: summarise a public article (appropriate), rewrite a performance review (conditional — human review and care with people data), connect Claude to the CRM (escalate), draft medical advice for customers (escalate / qualified review). Each conditional item gets a named condition; each escalation gets an owner.
Exam traps
It can do it, so it is allowed
Capability is not permission. Policy, law, and contracts decide.
Proceed on unclear cases and apologise later
When a use case is new or unclear, ask before doing.
Treat CRM or pipeline integrations as a chat-user decision
Escalate to security, legal, or the team that builds integrations.
Blame Claude for an inappropriate outcome
Responsibility for the output stays with you.
Practice scenario
A colleague asks you to connect Claude to the company CRM from the chat product so it can update customer records automatically. Claude could draft the messages. What should you do?
Build exercise
Classify Requests as Appropriate, Conditional, or Escalate
6.1 · Beginner · ~25 min · claude.ai
What you will practise
- Why being able to do something is not permission to do it.
- Which uses are fine, which need conditions, and which need escalation.
- When a request needs a developer or architect because it involves integrations.
- How to explain your classification to a colleague.
Classify ten requests on the Domain 6 exercise with specific conditions and named escalations.
Open Domain 6 exercisesPath: /learn/claude-associate/exercises/6-governance-risk-responsible-use
Sources
- CCAO-F Exam Guide v1.0 — Domain 6 task statement 6.1 — Appropriate vs Inappropriate Use
- preporato/claude-certification-guide — CCAO-F Ch.3 — capability vs permission (rewritten)
- Amey-Thakur associate-foundations — practice/mock governance items — distilled into site voice
- docs/ccao-f-implementation-plan.md — Domain 6 lesson map