Mosaic Acceptable Use Policy
Last updated: 5 October 2026
This policy is part of the Mosaic Terms of Service between your organisation and Campainless Pty Ltd. It exists to keep the Service safe for everyone who shares its infrastructure — and because an AI coworker with access to your tools deserves clearer rules than a generic "don't do bad things" clause.
1. The short version
Use Mosaic on content your organisation is entitled to use, for your organisation's own work, in ways that don't harm others or the Service. Don't use the coworker to do things a responsible employer wouldn't let an employee do.
2. You must not use the Service to:
Break the law or others' rights - Violate any applicable law, or infringe anyone's intellectual property, privacy, or contractual rights — including connecting data sources you are not entitled to connect (Section 3 of the Terms). - Process personal information in ways your own privacy obligations do not permit.
Harm people - Generate or distribute content that is defamatory, harassing, discriminatory, or exploitative, or that targets private individuals. - Make automated decisions with legal or similarly significant effects on individuals (employment, credit, insurance, housing) without meaningful human review — the Service's approval gates exist for exactly this.
Deceive - Generate content designed to mislead about its origin — impersonating people or organisations, fabricating records presented as genuine, or publishing AI output as the verified work of a person when it is not. - Remove or bypass the Service's honesty controls (citations, review annotations, unverified-content labels) in content shown to people who rely on it.
Attack systems — ours or anyone's - Probe, scan, or test the vulnerability of the Service except through a coordinated disclosure we have agreed to (write to security@mosaicailab.ai — we welcome reports). - Attempt to access another organisation's tenant, escalate privileges, or interfere with the Service's operation. - Use the coworker or its connectors to conduct attacks, scraping in breach of a source's terms, spam, or malware distribution. - Introduce content deliberately crafted to manipulate the coworker into ignoring its instructions or exceeding its authorisations against your own organisation's interest (prompt injection as an attack, not as security research on your own tenant).
Abuse the shared infrastructure - Circumvent usage metering, rate limits, or the credit system. - Resell, sublicense, or provide the Service to third parties as a service bureau without a written agreement with us. - Use the Service to develop a competing product, or to systematically extract its non-customer content (prompts, skill definitions, model routing) for that purpose.
3. High-risk configurations are yours to govern
The Service lets your organisation configure autonomous behaviour — scheduled skills, standing automations, connector write-backs. These are powerful and legitimately useful, and they are your organisation's responsibility to configure safely:
- Keep a human approval gate on anything that publishes externally, spends money, or changes records of consequence.
- Scope connector access to what the automation needs, not everything it could have.
- Review your scheduled work periodically; an automation nobody remembers is a risk nobody owns.
We may require additional safeguards for configurations we reasonably consider high-risk, and will tell you when we do.
4. What we do about violations
Proportionate response, fastest where harm is live: for most issues we will notify you and ask you to remedy; where a violation threatens other customers, individuals, or the Service itself, we may suspend the affected workspace, skill, or connection first and notify you immediately after. Repeated or deliberate violations are a material breach of the Terms.
We do not read your content looking for violations — our review is triggered by reports, security signals, and the abuse-detection systems of our AI providers, as the Privacy Policy describes.
Report abuse or security issues: security@mosaicailab.ai