What is a Gem?
A Gem is a customized AI assistant based on Google Gemini. You can define its role, permanent instructions, response style, and information sources to help with recurring tasks such as:
- Drafting and summarizing documents.
- Preparing drafts and templates.
- Finding information from approved documents.
- Answering professional questions.
- Assisting in training, research, or administrative work processes.
A Gem is not an authorized decision-making system and does not replace professional review and judgment.
Access and Usage
Gems must be used exclusively through Technion’s organizational account.
- Log in to Google Gemini using your Technion account.
- Open the Gems menu.
- Select New Gem.
- Define a clear name describing the purpose of the Gem.
- Write the instructions by which it will operate.
- If necessary, attach approved documents from Google Drive.
- Test the Gem with several sample questions before use or sharing.
- Save the Gem.
A Gem created in the web version may also be available in the Gemini app and in the Gemini panel within Google Workspace services, depending on licensing and organizational settings.
How to Write Instructions for a Gem?
It is recommended to include the following in the instructions:
- Role: “You are a professional assistant helping to…”
- Task: “Your role is to summarize, explain, compare, or prepare…”
- Allowed Sources: “Rely only on the documents attached to the Gem and the information provided by the user.”
- Limitations: “Do not guess information that does not appear in the sources. When there is insufficient information, state so explicitly.”
- Response Structure: “Provide a concise, professional response in English, including headings and practical recommendations.”
- Quality Control: “Indicate assumptions, uncertainties, or information requiring verification.”
Example
You are a professional assistant helping unit employees locate information in the attached procedures. Rely only on the documents provided to you. Do not invent requirements or details that do not appear in them. When a contradiction exists between documents, present it. At the end of each answer, state the name of the document relied upon.
Information Security and Privacy Rules
Permitted
A Gem may be used to process public information or internal organizational information that the user is authorized to access, provided that the use complies with the information classification and work purpose.
Forbidden to Enter or Attach Without Appropriate Authorization
- Passwords, encryption keys, API keys, or login credentials.
- Security information or information on vulnerabilities, architecture, and defenses not intended for exposure.
- Sensitive personal information about students, employees, candidates, patients, or research participants.
- Medical, biometric, financial information, or information regarding disciplinary proceedings.
- Grades, diagnoses, personal evaluations, or employee and student files.
- Exam questions, solutions, or evaluation materials that have not yet been published.
- Unpublished research, information subject to a non-disclosure agreement (NDA), or third-party information without authorization.
- Information whose classification or terms of use are unknown.
Do not remove identifying details and assume the information automatically becomes anonymous. When the use of personal or sensitive information is required, prior approval must be obtained from the information owner, CISO, and DPO.
Attaching Documents and Knowledge Sources
Before attaching a document to a Gem, verify:
- That the user is authorized to view the document and process it using AI tools.
- That the document contains no information unnecessary for the Gem’s purpose.
- That the document is updated, accurate, and valid.
- That its sharing permissions in Google Drive are restricted to authorized users only.
- That old or unneeded documents are removed from the knowledge sources.
A Gem does not bypass the access permissions defined in Google Workspace. However, the content owner and the Gem owner are responsible for checking who has been granted access to the information.
Sharing a Gem
The recommended default is to keep the Gem private.
When an organizational need for sharing exists:
- Share only with users or groups who require the Gem for their work.
- Prefer Viewer permission.
- Editor permission should only be granted to those authorized to modify instructions and knowledge sources.
- Do not allow public access or sharing via an open link.
- Do not share outside Technion without explicit permission.
- Re-check the list of authorized users whenever there is a change in roles or content.
A user with edit permissions can modify or delete the Gem’s instructions and associated files, thereby affecting the answers other users receive.
Particularly Important: Google Drive documents included as knowledge sources in a Gem may also be shared with anyone who receives access to the Gem. Therefore, before sharing, check all attached documents and their permissions.
Output Verification
Answers generated by artificial intelligence may be incorrect, incomplete, or out of date. Therefore:
- Facts, numbers, names, quotes, and references must be verified.
- Do not publish or send output without human review.
- Do not rely on a Gem for legal, medical, disciplinary, academic, or employment decisions.
- Do not allow a Gem to determine an individual’s eligibility, grade, admission, rejection, or evaluation.
- Code, system commands, and formulas must undergo review and testing in a safe environment.
- In case of doubt, consult the qualified professional.
The final responsibility for the output remains with the user.
Gem Owner Responsibilities
The Gem owner is responsible for:
- Defining a clear objective.
- Ensuring information sources are approved and up to date.
- Managing sharing permissions.
- Periodically reviewing answer quality.
- Updating instructions and sources when a procedure or process changes.
- Removing users who no longer require access.
- Deleting the Gem when it is no longer needed.
It is recommended to conduct a periodic review at least once every six months, as well as during any major change in content, systems, or workflows.
Reporting an Incident
Stop use and report to the CISO team when:
- Information is exposed to an unauthorized user.
- Personal, sensitive, or confidential information was attached by mistake.
- The Gem repeatedly provides misleading or dangerous answers.
- Instructions or knowledge sources were changed without authorization.
- There is concern of misuse, data leakage, or privacy infringement.
When reporting, include the Gem’s name, owner, users with whom it was shared, type of information involved, and a description of the incident. Do not send additional sensitive information in screenshots that is not required for handling the issue.
Contact the Information Security Team
To report a security incident, request guidance, or ask questions related to information security,
please contact the Information Security Team at ciso-team@technion.ac.il
Reminder
Before creating, uploading, or sharing, ask:
- Am I authorized to use this information?
- Is all attached information actually necessary?
- Are sharing permissions restricted to the minimum required?
- Will the output undergo human review before use?
If the answer to any of these questions is unclear — do not upload or share the information until guidance is received.