
For your team
Teams by Function
Module · Fast enough that nobody routes around you
The IT Team AI Check
IT is the team everyone blames for saying no and nobody thanks for saying yes safely. With AI, the stakes are sharper: if the sanctioned path is slow, people reach for a browser tab and a private account, and your data walks out with them. This module checks the five things that decide whether IT is the fast lane or the roadblock: how quickly you provision, whether there is a catalogue people can pick from, how much friction an access request carries, whether you can see the tools you never approved, and whether the AI tooling you do run is actually current.
What the five levels look like
Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.
Provisioning is fast
- 1Weeks or never
- 2Many days
- 3A few days
- 4Same day
- 5Self-serve, minutes
At the low end: If getting an AI tool takes weeks, you are training your whole company to bypass you. Find the one slowest step in your provisioning and cut it this month; speed here buys you more security than any policy. What good looks like: Self-serve provisioning in minutes is what makes the sanctioned path the obvious one. Keep the catalogue behind it curated so fast access never means ungoverned access.
A tool catalogue exists
- 1No catalogue
- 2Ad hoc approvals
- 3Short list, stale
- 4Current catalogue
- 5Curated, with guidance
At the low end: With no catalogue, every request restarts the same argument and your people cannot tell allowed from forbidden. Publish even a rough list of what is sanctioned; a short list beats no list every time. What good looks like: A curated catalogue with guidance on what each tool is for turns IT from gatekeeper into guide. Keep adding the tools people keep asking for, or the catalogue drifts from what they actually need.
Access has low friction
- 1Heavy, manual
- 2Many approvals
- 3Some hoops
- 4Light, quick
- 5Frictionless, governed
At the low end: A heavy manual access process does not stop risky AI use, it just moves it out of your sight. Strip the request down to the fewest steps that still give you the control you need. What good looks like: Frictionless access that stays governed is the whole goal: right and easy become the same path. Keep watching where friction creeps back in; it always tries to.
Shadow IT is visible
- 1Blind to it
- 2Anecdotes only
- 3Occasional scans
- 4Regular discovery
- 5Continuous visibility
At the low end: If you are blind to unsanctioned AI, you are defending a perimeter with holes you cannot see. Run a discovery pass on network and expense data this quarter; the tools you find will tell you where your catalogue falls short. What good looks like: Continuous visibility into what your people actually run is rare and worth guarding. Feed what you find back into the catalogue, so discovery leads to sanctioned options rather than just blocklists.
AI tooling stays current
- 1Never updated
- 2Rarely, reactive
- 3Occasional patching
- 4Regular updates
- 5Current, monitored
At the low end: AI tooling you never update is accumulating both stale capability and unpatched risk. Put your provisioned AI tools on the same update discipline as the rest of your stack, starting with the ones that touch sensitive data. What good looks like: Current, monitored AI tooling is what keeps a useful tool from quietly becoming a liability. Keep watching the vendors' release notes; in this space, a quarter of neglect is a long time.