Colorado repealed its AI Act — the ADMT law that replaced it starts January 1, 2027See what changed →
🛠️ IT management

You can't secure the tools you don't know about

AI arrived through expense reports and browser extensions, not through procurement. Before you can set rules, you need the list — and a way to keep it current without chasing people.

A server hall with the chrome lion watching five live dashboards
The inventory

One record per tool, and it stays true

Every entry carries an owner

An ID, the person accountable, the data it touches, and the date you'll look at it again.

New tools come in through intake

Requests are screened at the door, so the list doesn't rot between audits.

Renewals arrive before the invoice

Sixty days ahead, so a subscription is a decision rather than a surprise line item.

What a record looks like

The list, kept current

Every entry carries an ID, an owner, the data it touches, and the date you’ll look at it again. Requests for new tools come in through the same intake, so the list doesn’t rot.

UC-004
Meeting-notes assistant
Owner: Ops director · Data: internal meetings, occasional client names · Review: Nov 04
UC-011
Support-reply drafting
Owner: Support lead · Data: customer tickets · Review: Sep 30
Sample records. Placeholder for a real product screen.
🤖 Agents that act on their own

The newest thing on your network has credentials

An AI agent isn’t a chatbot. It has an identity, reaches into systems, and takes actions without a person watching each one. Treat it like staff: give it a scope, check what it can reach, and test it before it goes live.

Identity

Who it runs as, and who owns it.

Reach

The systems and data it can touch.

Limits

A zero-trust checklist of what it may not do.

Testing

When it was last checked, and by whom.

Start with what's actually in use

The free scorecard takes ten minutes and tells you how big the blind spot is.

Take the free scorecard →