Discover shadow AI use without criminalizing experimentation
A review groups tools by use case, data sensitivity, duplication, owner, and safe enablement path.
The problem
Employees adopt AI tools faster than security, procurement, and data guidance can respond.
What you get
A working system with the steps, tools, checkpoints, and expected return made explicit.
- Setup
- 75 minutes
- Back each week
- 3 hours
- Difficulty
- assisted
Expected return
The working case
A planning estimate, not a guaranteed result. Measure the first four weeks against your own baseline.
144
hours returned per year
At 3 hours/week across 48 working weeks.
1
week to earn back setup
Compare the setup estimate with the weekly time returned.
Operating contract
Input
The source material, constraints, and examples a human would need to do this work well.
Checkpoint
A person reviews judgment calls, sensitive content, unfamiliar tools, and irreversible actions.
Success signal
Track time returned, corrections required, and exceptions. Keep it only if the measured result compounds.
Before you start
- ·A named AI governance lead
- ·An approved source-of-truth and review template
The steps
- 01
Name AI governance lead as the accountable owner and define the decision this workflow is allowed to support.
- 02
Collect SSO inventory, expense data, employee disclosure, and approved-tool policy; preserve source links, timestamps, and access controls before any synthesis.
- 03
Produce a risk-ranked AI tool inventory using the approved template. Do not infer misconduct or inspect private content.
Copy this prompt
Create a risk-ranked AI tool inventory from the supplied evidence. Separate facts, assumptions, and missing inputs. Cite every material claim. Do not infer misconduct or inspect private content. Evidence: [approved inputs]
- 04
AI governance lead reviews the draft, records the decision or next action, and corrects the source system before distribution.
What it runs on
Where this goes wrong
- Do not let the model act beyond do not infer misconduct or inspect private content.
- Keep sensitive fields out of unapproved tools and retain a human-readable evidence trail.
Definition of done
Run it for four weeks. Then make it earn its place.
- □ Baseline the manual time before launch.
- □ Keep a human approval step for consequential output.
- □ Record corrections and exceptions, not just successes.
- □ Expand, revise, or retire it after the first review.
Build the system around it
Related workflows
If this one stops working, tell us. Three reports in a month and it leaves the library until a person has looked at it again.