Choosing Your Tools & Accounts
On editors, languages, frameworks, and which approved assistant you prefer, we have no opinion — use what makes you productive. On accounts, assessment, and what gets installed, we do. Here's where the lines are and why.
The account rule
The models can be identical; what differs is where the data goes. Your ND account keeps data flows inside the university's agreements, keeps audit and support unified, and keeps you inside policy by default. “Just a quick question with my real code” on a personal account means university data crossed the boundary.
How ND classifies AI tools
| Tier | Meaning | Use |
|---|---|---|
| T1 — Enterprise Approved | Contracts and data protection agreements in place. | All work, when data and risk align. |
| T2 — Assessed (no DPA) | Risk-reviewed; contractual protections incomplete. | Public and Internal data only. |
| T3 — In Assessment | Time-boxed evaluation underway. | Controlled experimentation — not production. |
| Not Permitted | No assessment, or a failed one. | Not for ND work. |
The honest answer to “can I use this new tool?” is always two questions: what tier is it, and what data are you putting in it? Both matter. The approved AI tools page is the living list.
Extensions deserve the same scrutiny
Anything that gives an AI tool new capabilities deserves the same care as adopting a new vendor — because functionally, it is one:
- IDE plugins — check before installing; some send file contents off-machine automatically.
- MCP connectors — understand what data they expose and what actions they can take on your behalf.
- Agent skills — powerful and silent; review a skill before you trust it.
- Custom GPTs and agents — if they read ND data, they're a governance event, not a productivity tweak.
So what should I actually use?
Most ND developers standardize on VS Code with GitHub Copilot or Codex, and there are solid options from zero-install browser coding up through agentic harnesses and gateway API access. The full landscape — what's standard, what's on request, what's bring-your-own — lives on its own page: