checklist

Monthly AI tool access review checklist for small teams

A practical monthly checklist for reviewing AI tool access, users, connectors, browser extensions, meeting bots, developer AI, data retention, incidents, exceptions, and next actions.

Audience: Founders, operators, IT owners, workspace admins, engineering leads, and managers responsible for recurring AI tool access reviews Risk: Medium Evidence: NIST AI RMF, NIST Cybersecurity Framework, NIST Privacy Framework, and Cybergiz post-30-day AI security rollout assets

Use this monthly checklist after the first AI security rollout is live.

The goal is not to restart the whole program every month. The goal is to catch drift: departed users, stale guests, personal accounts, broad connectors, risky browser extensions, meeting bots that keep too much data, developer AI tools with repo or terminal access, and exceptions that quietly became permanent. If you are still setting the baseline, start with the 30-day AI security rollout plan and the Small Team AI Security Checklist.

Bottom line

A small team should review AI tool access monthly while the program is new. The review should answer:

  1. Which AI tools, bots, extensions, agents, and embedded AI features are still approved?
  2. Which users, guests, shared accounts, API keys, and personal accounts need removal?
  3. Which connectors can reach email, files, chat, code, CRM, helpdesk, calendar, meetings, or admin systems?
  4. Which workflows touch customer data, source code, transcripts, browser page data, or regulated records?
  5. Which incidents, near misses, and exceptions need follow-up?
  6. Which decisions should be keep, restrict, pilot, remove, or escalate?
  7. What evidence proves the review happened?

If the team cannot remove unused access during the review, the review is only paperwork.

Review cadence

SituationCadenceWhy
New AI programMonthlyThe first 90 days usually reveal shadow tools, personal accounts, and broad connectors.
High-risk workflowMonthlyCustomer data, source code, transcripts, browser page data, connectors, and automation drift quickly.
Stable low-risk toolQuarterlyPublic-content tools with no connectors and no sensitive data can use a lighter cadence.
Employee departure or role changeSame weekAI workspaces, extensions, connectors, bots, and API keys are easy to miss during normal offboarding.
Incident, near miss, or vendor setting changeImmediateThe access model may no longer match the approval decision.
Major new AI featureBefore rolloutNew connector, memory, agent, automation, or sharing behavior can change the risk profile.

For a team under 50 people, the first monthly review should fit in 30-60 minutes if the inventory is current.

Access review scope

AreaReviewEvidence
AI workspacesUsers, admins, guests, shared projects, sharing settings, retention settings, and export access.User list, admin notes, and setting screenshots or links.
Personal accountsWork usage in unmanaged ChatGPT, Claude, Gemini, Cursor, meeting bot, or extension accounts.Exceptions list and migration plan.
ConnectorsGmail, Drive, Docs, Slack, Teams, GitHub, CRM, helpdesk, calendar, meetings, password manager, and admin apps.Connector register and owner approval.
Browser extensionsExtension ID, host access, permissions, OAuth scopes, sensitive hosts, install source, and user group.Allowlist, risk score, and offboarding status.
Meeting botsRecording default, notice, consent, transcript storage, CRM sync, external sharing, and retention.Bot settings and meeting policy notes.
Developer AIIDE tools, repo access, code search, PR bots, terminal agents, API keys, and production-adjacent workflows.Developer inventory and repo rules.
Data handlingCustomer, employee, source-code, transcript, finance, HR, legal, health, payment, government, child, and regulated data.Approval records and data class decisions.
Incidents and exceptionsAccidental paste, upload, recording, connector, secret exposure, bad AI output, and overdue exceptions.Incident log and exception register.

Run any uncertain tool through the AI Tool Risk Checker before renewing approval.

Monthly checklist

StepTaskOwnerEvidence
1Confirm the AI business owner, admin owner, engineering owner, and incident owner are still current.Review ownerOwner map.
2Compare the current tool inventory against expense records, browser extensions, GitHub apps, meeting bot invites, Slack/Teams apps, and employee reports.Admin ownerUpdated inventory.
3Remove departed users, guests, shared accounts, stale admins, unused API keys, and personal accounts used for work.Admin ownerAccess removal notes.
4Review connectors to email, Drive, Docs, Slack, GitHub, CRM, helpdesk, calendar, meetings, password managers, and admin tools.Source-system ownersConnector register.
5Review AI browser extensions against the allowlist and risk score.IT ownerExtension decision table.
6Review meeting bot recording, sharing, transcript storage, retention, and CRM sync.Sales, CS, or people ownerMeeting bot settings notes.
7Review developer AI tools with repo, terminal, PR, code search, or API-key access.Engineering ownerDeveloper AI register.
8Check customer-data workflows against the approval form and data rules.Data ownerApproval records.
9Review incidents, near misses, support tickets, and employee questions from the last month.Incident ownerIncident log.
10Close, renew, restrict, or escalate every exception due this month.Business ownerException register.
11Pick the top three fixes for the next month.Review ownerAction list.
12Save the evidence packet outside the AI tool being reviewed.Review ownerReview record.

Do not collect raw customer exports, source code, payroll data, legal files, regulated records, passwords, API keys, private keys, recovery codes, or session cookies as evidence.

Tool access review

Use this table for each approved or in-pilot AI tool.

QuestionKeep ifRestrict or remove if
Is there a named business owner?The owner still accepts the use case and risk.The tool has no active owner.
Are users still correct?Users match current job roles and business need.Departed users, stale guests, broad groups, or shared logins remain.
Are admins limited?Only required admins have admin rights.Admin rights are broad, inherited, or unmanaged.
Is work use in a managed account?Work data stays in a company-controlled workspace where practical.Employees use personal accounts for customer data, code, transcripts, or internal records.
Are settings documented?Retention, training, sharing, export, connector, and guest settings are recorded.Settings changed without review.
Does the tool still match its approval?Data classes, user groups, and workflows are unchanged.New data, automation, connector, or sharing behavior appeared.

Decision labels should be plain: keep, restrict, pilot, remove, or escalate.

Connector review

Connectors often create broader exposure than prompts because they can reach historical records.

Connector typeMonthly checkEvidence
EmailWhich mailboxes, labels, attachments, and history can the AI tool access?Mailbox scope and owner.
Drive or DocsWhich folders, shared drives, file types, and external shares are exposed?Folder scope and source-system owner.
Slack or TeamsWhich channels, DMs, files, and history are available?Channel list and app permissions.
GitHub or GitLabWhich repos, issues, pull requests, actions, and secrets-adjacent workflows are available?Repo scope and permission level.
CRM or helpdeskWhich customer records, tickets, notes, contracts, exports, and attachments are available?Data owner approval.
Calendar or meeting platformWhich meeting titles, attendees, recordings, transcripts, and summaries are available?Meeting category rule.
Password manager, SSO, or admin appWhether the connector can expose credentials, recovery data, sessions, or admin configuration.Escalation record.

For ChatGPT connector workflows, use the ChatGPT connector approval template before renewing broad access.

Browser extension review

AI browser extensions need a monthly pass when they can read work pages or connect to cloud accounts.

CheckRenew approval ifRemove or restrict if
Exact extension IDThe extension ID matches the allowlist.The employee installed a lookalike or unreviewed extension.
Host accessHost access is limited to approved sites or user action.The extension can read all sites or sensitive hosts without business need.
Sensitive pagesGmail, Docs, CRM, password manager, SSO, admin, source-control, finance, HR, and support tools are considered.Sensitive hosts are included by default.
OAuth scopesOAuth access is reviewed separately from browser permissions.OAuth scopes exceed the approved workflow.
Vendor/update statusThe vendor, privacy documentation, and recent update pattern still look acceptable.Ownership, listing, or update behavior changed materially.
OffboardingRemoval covers extension install, OAuth app, vendor account, and browser profile.The team cannot remove access completely.

Use the browser extension allowlist template and the AI browser extension risk scoring matrix for the detailed record.

Meeting bot review

Meeting bots create retained records from conversations that may feel informal to employees.

CheckMonthly question
Recording defaultAre external, customer, hiring, legal, finance, HR, security, and escalation meetings recorded only when approved?
NoticeDo hosts use the correct notice or consent language before recording or summarizing?
StorageWhere do raw audio, transcript, summary, and clips live?
SharingAre summaries auto-shared externally, to Slack/Teams channels, or into CRM records?
RetentionAre deletion rules working for raw transcripts and summaries?
AccessCan only the right host, team, manager, or customer owner view the record?
Incident pathIs there a first-hour path for accidental recording, sharing, or transcript exposure?

Use the meeting transcript retention policy template when the team cannot answer storage or deletion questions.

Developer AI review

Developer AI review should focus on access and change paths, not just vendor names.

AreaMonthly checkBlock until resolved if
IDE assistantsWhich repos, files, and extensions are included?Secrets, production configs, or restricted repos are exposed without rules.
Repo appsWhich repos, issues, PRs, actions, and code search indexes are connected?Broad org access exists without owner approval.
Terminal agentsWhich commands can be suggested, run, or approved?Network, deploy, destructive, or credential commands lack approval tiers.
API keysWhich user or service keys power the workflow?Shared keys or stale keys remain.
PR workflowCan AI output merge, label, close, comment, or change code?Human review, CI, or branch protection is bypassed.
Incident evidenceWere there bad AI code suggestions, leaked secrets, or production issues this month?No one owns remediation.

Use the developer AI tool inventory template and terminal-agent approval rules from How to approve AI agents that can run terminal commands.

Data and retention review

Monthly access review should refresh the data decision, not only the user list.

Data classMonthly action
Public contentKeep in approved tools if outputs are still reviewed.
Internal notesConfirm the tool is managed and sharing remains narrow.
Customer dataRe-check owner approval, redaction, retention, and downstream sharing with the customer data approval form.
Source codeConfirm repository rules, secret scanning, and branch protection.
Meeting transcriptsConfirm notice, storage, sharing, retention, and deletion.
Browser page dataConfirm extension permissions and sensitive host rules.
HR, finance, legal, health, payment, government, child, or regulated dataEscalate outside the lightweight review before renewal.
Secrets and credentialsProhibit in AI tools and prepare rotation steps for any exposure.

NIST’s AI RMF frames AI risk management as a way to improve trustworthy use of AI, while the Privacy Framework focuses on managing privacy risk. For a small team, those ideas become recurring access, data, and evidence decisions.

Incident and exception review

Do this even if there were no major incidents.

ItemQuestionAction
Accidental paste or uploadDid anyone paste customer data, secrets, source code, or regulated records into an unapproved tool?Contain, document, rotate if needed, and update the rule.
Connector exposureDid a connector expose broader email, Drive, Slack, GitHub, CRM, helpdesk, or calendar data than approved?Revoke or scope down, then re-approve.
Meeting bot mistakeWas a meeting recorded, summarized, synced, or shared incorrectly?Remove access, notify owner, and adjust bot defaults.
Browser extension issueDid an extension read sensitive pages or request new permissions?Remove or rescore.
Bad AI outputDid AI-generated content, code, or summaries create a customer, security, or operational issue?Add human review gate.
Overdue exceptionIs a temporary exception older than its review date?Close, renew, restrict, or escalate.

Incidents should improve the next rule. Do not let the same failure repeat because the review record stayed vague.

Decision register

Copy this register into your review notes.

Tool or workflowOwnerData classAccess reviewedDecisionDue dateEvidence
Example AI chat workspaceOpsInternal notesUsers, guests, admins, sharing, retentionKeepNext monthUser list and settings note
Example customer support workflowSupportCustomer dataHelpdesk connector, redaction, approval formRestrict7 daysConnector register
Example browser extensionITBrowser page dataExtension ID, all-sites access, OAuth scopesRemoveTodayAllowlist update
Example meeting botSalesCustomer transcriptsRecording default, CRM sync, retentionPilot30 daysBot settings note

Every row needs an owner and a next review date.

Evidence packet

Keep the packet short and non-sensitive.

Monthly AI tool access review
Review date:
Reviewer:
Business owner:
Admin owner:
Engineering owner:
Incident owner:
Tools reviewed:
Users removed:
Guests removed:
Shared accounts removed:
Personal accounts found:
API keys reviewed:
Connectors reviewed:
Connectors revoked or scoped down:
Browser extensions reviewed:
Extensions removed:
Meeting bots reviewed:
Transcript or retention changes:
Developer AI tools reviewed:
Customer-data workflows reviewed:
Incidents or near misses:
Exceptions closed:
Exceptions renewed:
Top 3 next actions:
Next review date:
Evidence links:
Notes:

Store this outside the AI tool being reviewed. Do not include raw customer records, source code, credentials, regulated records, payroll data, legal files, or private contracts.

Monthly metrics

Track only numbers that influence the next review.

MetricGood signalBad signal
Approved toolsStable list with owners.More tools than owners can review.
Restricted or blocked toolsDecisions are enforced.Same blocked tools keep reappearing.
Personal accounts used for workDecreasing.Personal accounts touch customer data, code, or transcripts.
Connectors reviewedAll high-risk connectors have owners.Broad connectors have no source-system owner.
Browser extensions reviewedAll work AI extensions are allowlisted or removed.All-sites access is common.
Meeting bots reviewedRetention and sharing rules are documented.Auto-sharing or permanent transcript retention is unclear.
Developer AI tools reviewedRepo and terminal rules are current.AI tools can change code or run commands without approval tiers.
Risk Checker completionsHigh-risk tools are re-scored before renewal.Decisions are made without a current risk record.
Incidents and near missesReported quickly and converted into fixes.No reporting path or repeated incidents.
Overdue exceptionsLow and shrinking.Temporary exceptions become permanent.

If the monthly review only adds metrics and never removes access, simplify it.

Evidence checked

FAQ

Who should run the monthly AI access review?

Use one review owner, usually the founder, operations lead, IT owner, or security-minded manager. They need help from workspace admins, engineering, support, sales, and people operations when the review touches connectors, code, customer data, or meeting records.

Is monthly too often for a small team?

Monthly is appropriate while the AI program is new or while tools touch customer data, source code, browser page data, meeting transcripts, connectors, or automation. Stable low-risk tools can move to quarterly after the team has reliable inventory and offboarding.

What should be removed first?

Remove departed users, stale guests, shared AI accounts, shared API keys, personal accounts used for sensitive work, broad connectors without owners, unapproved all-sites browser extensions, and meeting bots with unclear transcript retention.

Do we need screenshots for every setting?

No. Keep enough evidence to prove the review happened and support the next decision. A user export, connector list, setting note, ticket, or short decision record is often enough. Avoid storing sensitive records as evidence.

What if an employee still needs an unapproved tool?

Move it into an exception record with owner, business need, data class, allowed workflow, restrictions, due date, and next review. If the tool touches customer data, use the customer data approval form.

How does this connect to the Risk Checker?

Use the AI Tool Risk Checker whenever a tool gets a new connector, new user group, new data class, new automation capability, or overdue exception. Copy the result into the Small Team AI Security Checklist so decisions remain visible.