checklist

AI tool exception register template for small teams

A practical exception register template for tracking temporary AI tool approvals, owners, risk level, data classes, guardrails, due dates, review evidence, and closure decisions.

Audience: Founders, operators, IT owners, engineering leads, support managers, and workspace admins who approve temporary AI tool exceptions Risk: Medium Evidence: NIST AI RMF, NIST Cybersecurity Framework, NIST Privacy Framework, and Cybergiz AI security operating checklists

Use this exception register when an AI tool or workflow is not fully approved, but the team needs a temporary path with clear limits.

The register is designed for small teams that already have a baseline AI policy, tool inventory, or monthly AI tool access review. If the workflow is new or unclear, run it through the AI Tool Risk Checker first, then copy the decision into the Small Team AI Security Checklist.

Bottom line

An AI exception should never mean “approved forever but undocumented.” It should mean:

  1. A named owner accepts the business need.
  2. The data class and tool access are written down.
  3. Guardrails are active before use.
  4. The exception expires on a specific date.
  5. Someone reviews, closes, renews, restricts, or escalates it.
  6. Evidence is stored without customer records, secrets, source code, or regulated data.

If the owner, guardrails, or expiry date are missing, the exception is not ready.

When to use an exception

SituationUse an exception?Better default
A team needs a new AI tool for a short pilot.Yes.Pilot with limited users, limited data, and a 30-day review.
A customer workflow needs AI before formal approval is complete.Sometimes.Use the customer data approval form and restrict real customer data until approved.
A browser extension needs broad page access for one role.Yes.Score it with the AI browser extension risk scoring matrix and limit hosts.
A meeting bot needs to record a sensitive call.Sometimes.Require notice, storage, retention, and sharing rules first.
A developer AI agent needs terminal or repo access.Yes.Require command tiers, repo scope, secret controls, and human review.
A vendor cannot answer basic security or privacy questions.No.Block or escalate until the vendor risk is understood.
The workflow touches secrets, private keys, passwords, payroll, legal files, regulated records, or production credentials.No for lightweight exception.Escalate outside the small-team exception path.

Exceptions are useful when they make risk visible and temporary. They are dangerous when they hide permanent drift.

Exception decision table

Risk levelExampleApproval pathMaximum duration
LowPublic-content AI writing tool with no connector.Business owner approval.90 days.
MediumManaged AI chat tool for internal non-sensitive work.Business owner plus admin owner.60 days.
HighCustomer data, source code, meeting transcripts, broad browser access, or connector access.Business owner, admin owner, and data/source-system owner.30 days.
CriticalSecrets, regulated records, HR/legal/finance records, production actions, or broad automation.Do not approve through this lightweight path.Escalate.

When in doubt, choose the higher risk level and shorten the review window.

Exception register template

Copy this table into your tracker.

FieldValue
Exception IDAI-EX-YYYY-MM-###
Request date
Requested by
Business owner
Admin owner
Data or source-system owner
Tool or workflow
Vendor or product
Account modelManaged workspace / personal account / vendor account / browser extension / API
User group
Business need
Data classPublic / internal / customer / source code / transcript / HR / finance / legal / regulated / secrets
Systems connectedEmail / Drive / Docs / Slack / Teams / GitHub / CRM / helpdesk / calendar / meeting / browser / other
Access requestedRead / write / export / record / summarize / send / update / delete / deploy
Risk levelLow / Medium / High / Critical
Guardrails required
Guardrails verified
Approval decisionApprove temporarily / restrict / pilot / reject / escalate
Expiry date
Next review date
Closure decisionClose / renew / convert to standard approval / remove access / escalate
Evidence links
Notes

Do not paste raw customer records, source code, credentials, contracts, medical/payment data, or regulated records into the register.

Required fields

FieldWhy it mattersReject if missing
Business ownerSomeone must accept the business need and tradeoff.Yes.
Admin ownerSomeone must be able to change settings or remove access.Yes.
Data classThe risk depends on what the tool can see or generate.Yes.
Connected systemsConnectors often expose more than the visible prompt.Yes for connectors.
User groupExceptions should not silently apply to everyone.Yes.
GuardrailsTemporary approval needs limits before use.Yes.
Expiry dateExceptions decay into permanent access without a date.Yes.
EvidenceThe next reviewer needs to know what was checked.Yes.

Use shorter records for low-risk public-content tools. Use full records for anything that touches customers, code, transcripts, browser data, or connectors.

Approval workflow

StepActionOutput
1Requester explains the business need and exact workflow.Request note.
2Admin owner identifies account model, users, connectors, extensions, bots, API keys, and settings.Access summary.
3Data owner classifies the data and blocked data types.Data decision.
4Reviewer runs the workflow through the Risk Checker if risk is unclear.Risk result.
5Owners choose approve temporarily, restrict, pilot, reject, or escalate.Decision record.
6Admin owner applies guardrails before use.Guardrail evidence.
7Review owner schedules the expiry and next review.Calendar or ticket.
8Reviewer closes, renews, converts, removes, or escalates before expiry.Closure decision.

The exception should not start until guardrails are active.

Guardrails by risk level

Risk levelMinimum guardrails
LowNamed owner, approved users, no sensitive data, human review of outputs, expiry date.
MediumManaged account where practical, MFA, no shared accounts, limited sharing, documented settings, monthly review if new.
HighData owner approval, connector scope review, retention rule, offboarding step, incident path, human review gate, 30-day expiry.
CriticalDo not approve through lightweight exception. Escalate to formal legal, security, compliance, engineering, or executive review.

For ChatGPT connectors, pair the exception with the ChatGPT connector approval template. For developer AI, pair it with the developer AI tool inventory template.

Review cadence

Exception typeReview cadence
Low-risk public-content workflowBefore 90 days.
Internal non-sensitive workflowBefore 60 days.
Customer data, source code, transcripts, browser page data, or connectorsBefore 30 days.
Meeting bot recording or transcript exceptionAfter the first sensitive meeting and before 30 days.
Browser extension broad host accessBefore 30 days and after major extension permission changes.
Developer AI terminal, repo, or automation accessBefore 30 days and after any incident or permission change.
Incident-related exceptionSame week.

The monthly access review should include all open exceptions due in the next 30 days.

Closure checklist

CheckClose when
Business needThe use case is complete, converted to standard approval, or no longer needed.
UsersTemporary users, guests, admins, and groups were removed or converted intentionally.
ConnectorsOAuth apps, integrations, source-system permissions, and tokens were revoked or scoped.
Browser extensionExtension install, OAuth access, vendor account, and browser profile were cleaned up.
Meeting dataRaw transcript, audio, summary, clips, and CRM sync follow the retention decision.
Developer accessRepo access, terminal permissions, API keys, PR bots, and code indexes match the final decision.
EvidenceThe register shows close, renew, restrict, convert, remove, or escalate.
Next ownerAny remaining approved workflow has an owner and next review date.

Do not mark an exception closed just because the calendar reminder expired.

Escalation triggers

Escalate instead of approving through this lightweight path when the workflow involves:

TriggerWhy
Secrets or credentialsExposure may require rotation and incident response.
Regulated or high-impact recordsLightweight review is not enough for legal or compliance risk.
Production changesAI can create outages, data loss, or irreversible changes.
Broad write accessSending, deleting, updating, merging, deploying, or exporting needs stronger controls.
Customer bulk exportsVolume changes the risk even if individual records seem low sensitivity.
Unknown vendor behaviorUnclear retention, training, sharing, or subprocessors can invalidate the approval.
No ownerNo one can remove access or answer questions later.
Repeated renewalsThe exception is becoming a standard workflow and needs formal approval.

Escalation is not failure. It is the correct decision when the lightweight path is too small for the risk.

Example entries

Exception IDTool or workflowRiskGuardrailDecision
AI-EX-2026-06-001Support team uses AI to draft replies from redacted tickets.MediumNo names, account IDs, or attachments; human review required.Pilot for 30 days.
AI-EX-2026-06-002Sales meeting bot records two customer calls.HighNotice script, internal-only summary, 30-day transcript deletion.Approve temporarily.
AI-EX-2026-06-003AI browser extension with all-sites access for one analyst.HighOnly approved host list; OAuth reviewed; extension reviewed after 14 days.Restrict.
AI-EX-2026-06-004AI coding agent can run deploy commands.CriticalNot enough for lightweight exception.Escalate.

These examples are patterns, not legal, compliance, or security assurance advice.

Evidence packet

Use this text block for a single exception.

AI tool exception evidence packet
Exception ID:
Review date:
Reviewer:
Business owner:
Admin owner:
Data/source-system owner:
Tool or workflow:
Business need:
Data class:
Connected systems:
Access requested:
Risk level:
Risk Checker result:
Guardrails applied:
Approval decision:
Expiry date:
Next review date:
Closure decision:
Evidence links:
Notes:

Store evidence outside the AI tool being reviewed. Avoid storing raw customer data, source code, passwords, API keys, private keys, regulated records, legal files, or private contracts.

Metrics to track

MetricWhat it tells you
Open exceptionsWhether temporary approvals are accumulating.
Overdue exceptionsWhether the review process is decaying.
Exceptions by risk levelWhether high-risk work is using temporary paths too often.
Exceptions renewed twiceWhich workflows need standard approval or removal.
Exceptions closed on timeWhether owners can remove access when promised.
Exceptions escalatedWhether the lightweight process is stopping at the right boundary.
Incidents tied to exceptionsWhether guardrails are strong enough.
Risk Checker completionsWhether approvals use a consistent decision aid.

If high-risk exceptions keep growing, stop approving new ones until old ones are closed or converted.

Evidence checked

FAQ

Is an exception the same as approval?

No. An exception is a temporary, limited approval with an expiry date. Standard approval should have a stable owner, policy fit, settings record, offboarding path, and review cadence.

Who can approve an AI exception?

At minimum, use a business owner and admin owner. Add a data owner for customer data, an engineering owner for source code or terminal access, and a source-system owner for connectors.

How long should an exception last?

Keep high-risk exceptions to 30 days or less. Medium-risk exceptions can often use 60 days. Low-risk public-content tools can use 90 days if they have no sensitive data or connectors.

What should never be approved through this lightweight path?

Secrets, private keys, passwords, session cookies, regulated records, production deployment actions, broad write access, sensitive HR/legal/finance records, or unclear vendor behavior should be escalated outside this lightweight exception process.

What if the same exception keeps getting renewed?

Convert it to standard approval or remove it. Repeated renewal means the workflow is no longer a temporary exception.

How does this connect to monthly review?

Every monthly AI access review should check open exceptions, overdue exceptions, repeated renewals, and exceptions tied to incidents. The monthly AI tool access review checklist gives the broader review process.