Phase 1
Discover
Find tools and habits already in use before writing rules nobody will follow.
- Shadow AI Discovery Survey
- Manager Briefing One-Pager
- Data Classification Quickstart
Method
Most AI policies fail because they start with rules and skip reality. The kit is sequenced the other way: find what’s already in use, make bounded decisions, then run a light operating cadence.
Operational templates only. Not legal, compliance, privacy, security, HR, or professional advice. Review with your stakeholders before adopting.
Each phase maps to concrete kit files. You edit examples; you don’t invent a program from a blank page.
Phase 1
Find tools and habits already in use before writing rules nobody will follow.
Phase 2
Score risk, then Conditionally approve, restrict, promote later, or reject — Conditional-first, not soft Approve. Checklist + living register keep Approved ≠ unrestricted.
Phase 3
Give employees plain guidance, an incident path, and a light quarterly review.
Illustrative pace for an SMB IT owner or MSP delivery lead. Your environment and stakeholders set the real calendar.
Day 1 — first session
Manager briefing → launch Shadow AI survey → share Employee FAQ draft
Days 2–7 — contain the obvious
Triage survey hits; Conditionally approve one low-risk path (Low ≠ auto-Approve); publish employee-facing approved list
Weeks 2–3 — tool-by-tool answers
Run playbooks for Copilot, public AI, meeting bots, writing/research/coding agents as needed
Week 4 — lock the cadence
Incident path live; schedule first quarterly review; keep the sample calendar as a reference
Time estimates are illustrative, not a guarantee. Sixteen completed sample artifacts show what “done” looks like at each stage.
See sample output on the product page → · Try the free checklist →
SMB / internal IT
One organization owns Discover → Decide → Operate end-to-end. Start with Day-1 Quick Start, then the rollout checklist.
MSP / consultant
You facilitate the same phases as a client engagement — pitch, discovery agenda, scope language, and handoff included.
No. Day 1 often overlaps: brief managers, start the survey, and draft the policy in parallel. The rule is don’t publish hard bans before you’ve seen what’s already in use — or people will route around you.
Many teams can stand up a usable first version in 2–4 weeks part-time. Regulated environments take longer because of stakeholder review — the kit still shortens the drafting work, not the legal calendar.
No. It’s editable templates and workflows. It does not certify SOC 2, HIPAA, ISO, GDPR, or any other framework, and it is not legal or compliance advice.
Usually no. The kit is Conditional-first: prefer Conditionally approved for first intake / pilots — including Low band. Standing Approved is a later Promote when scope is stable and controls are live. Approved ≠ unrestricted.
Start with the free AI Tool Approval Checklist Lite. If you need a full program (policy + register + employee path + quarterly review), the kit is cheaper than assembling those pieces ad hoc.
Yes — the MSP Pack adds pitch, discovery, scope, and handoff materials under a practitioner license for client delivery (not for reselling the source kit as a product).
Local stub → thank-you page. Live email delivery when Gate 2 / 5B is wired.