Version 2026.08.06 ยท Effective 2026-08-06
AI and Automated Actions Policy
1. Scope
This policy governs Pam AI, Pam Agent, model provider integrations, and other automated features in the Pamphlet Services. It supplements the Terms of Service and Acceptable Use Policy.
2. Pam AI and Pam Agent
Pam AI provides recommendations, drafts, research summaries, and analysis for operator review. Pam Agent executes configured actions within policy boundaries, including approval gates, sending limits, send windows, and emergency stop controls.
Pam AI recommends. Pam Agent executes within policy. Customers configure which actions require human approval before sending or updating records.
3. Human oversight
Customers remain responsible for all messages, record updates, and outbound actions sent from their Pam Pods, whether initiated by humans or automation. Customers must review AI-generated content for accuracy, legality, and appropriateness before relying on it for regulated or high-risk decisions.
Pamphlet does not guarantee that AI output is correct, complete, unbiased, or suitable for any particular use case.
4. Model providers and BYOK
Pamphlet supports customer-owned API credentials ("BYOK") for supported model providers, currently Anthropic and OpenAI. Credentials are stored encrypted using AES-256-GCM in the Customer's Pam Pod configuration.
When a Customer configures BYOK credentials, requests are sent directly to that provider under the Customer's provider agreement. When BYOK is not configured, Pamphlet may use platform-managed provider credentials where enabled in the environment. Platform-managed AI provider usage is disclosed in the Subprocessor List.
If no credentials are available, AI features may return template or fallback responses without external model calls.
5. Training and data use
Pamphlet does not use private mail, conversation transcripts, or CRM Customer Content to train general-purpose foundation models unless expressly agreed in a written agreement with the Customer.
AI usage metadata, such as token counts and model identifiers, may be logged in the ai_usage_ledger for billing, abuse prevention, and reliability.
6. Prohibited AI uses
Customers must not use AI features to:
- Generate unlawful, deceptive, or harassing content
- Impersonate individuals without authorization
- Automate outreach that violates anti-spam or privacy laws
- Attempt to extract credentials, bypass isolation, or probe model safety systems
- Process special category data without lawful basis and appropriate safeguards
7. Availability and changes
AI features depend on third-party model providers and may change, degrade, or be limited by rate limits, plan tier, or provider outages. Pamphlet may update supported models, providers, and safety controls with notice where practicable.
8. Contact
AI policy questions: cs@pamphlet.io
