checklist

Small-team AI security setup review checklist

A practical checklist for reviewing a small team's AI security setup across tools, data rules, accounts, connectors, browser extensions, meeting bots, developer AI, incidents, and a 30-day action plan.

Audience: Small-team founders, operators, technical leads, IT owners, and security-conscious managers preparing an AI security setup review Risk: Medium Evidence: NIST AI RMF, NIST Generative AI Profile, NIST Cybersecurity Framework 2.0, NIST Privacy Framework, and Cybergiz small-team AI security checklists

Use this checklist when a team already uses AI tools and needs a practical setup review before the sprawl gets worse.

The goal is not to create a formal audit. The goal is to find the obvious gaps: unmanaged tools, unclear data rules, broad connectors, AI browser extensions, meeting transcripts, developer AI access, missing owners, and no incident path. Start with the AI Tool Risk Checker, then store the results in the Small Team AI Security Checklist.

Bottom line

A small-team AI security setup review should answer seven questions:

  1. Which AI tools are actually used for work?
  2. Which accounts, browser extensions, bots, agents, and connectors can access company data?
  3. What customer, employee, source-code, meeting, financial, or regulated data can enter each workflow?
  4. Which tools are approved, restricted, in pilot, or blocked?
  5. Who owns admin settings, offboarding, incidents, and policy exceptions?
  6. What can be fixed in the next 30 days?
  7. What evidence proves the review happened?

If the team cannot answer those questions, it is not ready for broader AI rollout.

Review scope

AreaIncludeExclude from lightweight review
AI toolsChat tools, coding assistants, meeting bots, browser extensions, AI agents, AI writing tools, and embedded SaaS AI features.Full vendor due diligence or SOC 2 review.
DataCustomer data, source code, credentials, transcripts, files, CRM/helpdesk records, HR/finance/legal records, and confidential plans.Raw customer exports, passwords, API keys, private keys, regulated records, or private contracts.
AccountsManaged workspaces, personal accounts used for work, shared accounts, admins, guests, and departed users.Password collection or account takeover testing.
IntegrationsGmail, Drive, Docs, Slack, GitHub, CRM, helpdesk, calendar, meeting platforms, browser extensions, and custom automations.Penetration testing or source-code review of vendors.
OutputCustomer-facing content, support replies, code changes, summaries, decisions, and records created or changed by AI.Legal, compliance, certification, or security assurance opinions.

If you need a fixed-scope external review, the AI Security Setup Review page defines what Cybergiz’s pilot offer includes and what it deliberately excludes.

Setup review checklist

CheckPass conditionEvidence to collect
Owner namedOne business owner and one admin owner are responsible for AI usage.Owner names and backup owner.
Tool inventory existsAll known AI tools, bots, extensions, agents, and embedded AI features are listed.Inventory table or export.
Data rules existEmployees know which data is allowed, restricted, or prohibited.Policy page or checklist.
Managed accounts preferredWork data uses managed company workspaces where practical.Workspace admin screenshot or notes.
No shared AI accountsShared logins and shared API keys are blocked.Account list and key owner list.
MFA is requiredAI workspaces and connected systems require MFA where available.Admin settings note.
Connectors are approvedEmail, Drive, Docs, Slack, GitHub, CRM, helpdesk, calendar, and meeting connectors have owners.Connector register.
Browser extensions are reviewedAI extensions are scored for permissions, site access, and offboarding.Extension allowlist and risk score.
Meeting bots have rulesConsent, transcript storage, retention, and sharing rules exist.Meeting bot policy or approval record.
Developer AI has boundariesSource code, secrets, terminal commands, repositories, and production workflows are controlled.Developer AI inventory and PR rules.
Incident path existsAccidental paste, upload, recording, connector, or secret exposure has a named response path.Incident contact and first-hour checklist.
30-day plan existsFixes are ranked by owner, urgency, and business risk.Action plan table.

Intake questions

Ask these before reviewing the setup:

QuestionWhy it matters
Which AI tools are approved today?Reveals whether approval is real or assumed.
Which AI tools do employees use without approval?Finds shadow AI before it touches sensitive data.
Which tools use personal accounts for work?Personal accounts are harder to offboard and govern.
Which systems are connected to AI tools?Connectors often expose more data than prompt boxes.
Which browser extensions can read work pages?Extensions can see data across Gmail, Docs, CRM, password managers, and admin consoles.
Which meetings are recorded or summarized by AI?Transcripts need consent, storage, retention, and sharing rules.
Which AI tools can change code, tickets, CRM records, or customer messages?Action-taking workflows need human review and rollback.
Who handles mistakes?Fast reporting is only useful when the owner is known.

Do not ask employees to send raw customer files, source code, passwords, API keys, or private contracts to complete the review.

Tool inventory review

Start with a simple inventory. Use the developer AI tool inventory template for engineering-heavy teams.

ToolTypeAccount modelData exposedIntegrationsOwnerStatus
ChatGPT / Claude / Gemini / CopilotChat workspaceManaged or personalPrompts, files, project dataOptional connectorsOperations or ITApproved / Restricted / Pilot / Blocked
Cursor / Copilot / code assistantDeveloper AIManaged or localSource code, repo context, promptsGitHub, IDE, terminalEngineeringApproved / Restricted / Pilot / Blocked
Meeting botMeeting AIManaged or personalAudio, transcript, summary, attendeesCalendar, CRM, Slack, DriveSales/CS/PeopleApproved / Restricted / Pilot / Blocked
Browser extensionExtensionBrowser profilePage content, selected text, clipboard, cookies, host dataOAuth or vendor cloudIT/adminApproved / Restricted / Pilot / Blocked
Embedded SaaS AIProduct featureExisting SaaS accountApp-specific recordsNative app dataApp ownerApproved / Restricted / Pilot / Blocked

Every row needs an owner. Tools without an owner should default to “needs review” or “blocked” for sensitive data.

Data handling review

Use this table to decide what the review must test.

Data classReview questionDefault action
Public contentIs the AI tool used only with public material?Allow in approved tools.
Internal notesCould outputs reveal confidential plans?Allow in managed tools with review.
Customer dataAre identifiers, tickets, CRM records, contracts, or transcripts involved?Use the customer data approval form.
Source codeDoes the tool see private repos, secrets, incidents, or production code?Use developer AI rules and secret scanning.
Meeting transcriptsAre external, customer, hiring, or sensitive calls recorded?Use meeting bot consent and retention rules.
Browser page dataCan an extension read Gmail, Docs, CRM, password manager, or admin pages?Score it with the extension risk matrix.
Credentials and secretsCould API keys, tokens, private keys, cookies, or recovery codes appear?Prohibit and prepare rotation steps.
HR, finance, legal, health, payment, government, child, or regulated dataCould the workflow process regulated or high-impact records?Escalate outside this lightweight review.

NIST’s Generative AI Profile describes risks such as data privacy, human-AI configuration, information integrity, information security, and value-chain/component integration. For a small team, those risks show up as everyday workflow decisions: what employees paste, which apps they connect, and what AI output is allowed to change.

Connector review

Connectors deserve separate review because they can pull data without a user copying and pasting it.

ConnectorReview checkBlock until resolved if
Gmail / emailWhich mailboxes, labels, attachments, and historical messages can the tool access?It can scan broad customer or employee mail without owner approval.
Drive / Docs / filesWhich folders, shared drives, and file types are exposed?It can access broad company or customer folders without scope limits.
Slack / TeamsWhich channels, DMs, files, and history are exposed?Private channels or customer incident channels are included by default.
GitHub / GitLabWhich repos, issues, pull requests, secrets, and workflows are exposed?It has write access without branch protection and human review.
CRM / helpdeskWhich customer records, tickets, notes, contracts, and exports are exposed?Bulk customer data can be analyzed or exported without approval.
Calendar / meetingWhich meeting titles, attendees, recordings, transcripts, and summaries are exposed?External or sensitive meetings are recorded by default.

For ChatGPT connector workflows, pair this section with the ChatGPT connector approval template.

Browser extension review

AI browser extensions need their own pass because they sit between employees and the web apps that contain business data.

CheckPass condition
Extension ID recordedThe exact extension and vendor are identified.
Permission score recordedPage access, host permissions, and sensitive APIs are reviewed.
Sensitive hosts listedGmail, Docs, CRM, password manager, SSO, admin, source-control, finance, and HR sites are considered.
OAuth scopes reviewedConnected-account access is reviewed separately from browser permissions.
Role-based approvalThe extension is approved for a user group, not every employee by default.
Offboarding path existsRemoval covers extension install, OAuth app, vendor account, and browser profile.

Use the AI browser extension risk scoring matrix for the detailed scoring pass.

Meeting bot review

Meeting bots create retained records that employees may treat as informal notes even when they contain customer, candidate, or internal strategy data.

CheckPass condition
Meeting categories definedSales, support, hiring, internal, legal, finance, security, and customer escalations have different rules.
Notice script existsHosts know how to tell attendees when AI recording or summarization is used.
Retention rule existsRaw audio, transcript, summary, and CRM sync have retention/deletion rules.
Sharing rule existsSummaries are not auto-shared externally or broadly internally by default.
Human review requiredCustomer-facing notes and CRM updates are reviewed before use.
Incident path existsAccidental recording or sharing has a containment workflow.

Start with the meeting transcript retention policy template if the team records many calls.

Developer AI review

Developer AI often becomes higher risk when it can see secrets, operate on private repositories, or run terminal commands.

CheckPass condition
Tool inventory existsCoding assistants, IDE extensions, PR bots, code search, and terminal agents are listed.
Repository rules existSensitive repos have AI usage rules before tools index or edit them.
Secret controls exist.env, keys, tokens, certificates, and production credentials are excluded and scanned.
PR review remains human-ownedAI suggestions do not bypass code review, CI, or branch protection.
Terminal commands are tieredRead-only, local write, network, deploy, and destructive commands have different approval rules.
Incident plan existsBad AI-assisted code, leaked secrets, and production changes have response steps.

For terminal-capable agents, use How to approve AI agents that can run terminal commands.

Admin control review

This section maps the review to practical controls a small team can actually maintain.

ControlMinimum evidence
MFAMFA enabled for AI workspaces and connected systems where available.
Admin ownershipEach AI workspace has a named admin and backup admin.
User lifecycleJoiner, mover, and leaver steps cover AI tools, bots, extensions, and connected apps.
Workspace settingsTraining, retention, sharing, connector, export, and guest settings are documented.
Access reviewUsers, guests, projects, bots, extensions, API keys, and connected apps are reviewed monthly while the program is new.
Logs and recordsApproval decisions and incidents live outside the AI tool itself.
Backups and recoveryImportant business data remains recoverable outside AI-generated summaries.

This matches the operating spirit of NIST CSF 2.0: govern who owns risk, identify assets and data, protect access, detect problems, respond to incidents, and recover.

Evidence packet

Collect a lightweight evidence packet so the review is useful later.

Small-team AI security setup review
Review date:
Reviewer:
Business owner:
Admin owner:
Tools reviewed:
Tools approved:
Tools restricted:
Tools blocked:
Personal accounts found:
Shared accounts found:
Connectors reviewed:
Browser extensions reviewed:
Meeting bots reviewed:
Developer AI tools reviewed:
Highest-risk data class:
Top 3 gaps:
30-day actions:
Next review date:
Evidence links:
Notes:

Do not put secrets, private customer records, source code, payroll data, legal files, or regulated records in the evidence packet.

30-day action plan

PriorityActionOwnerDue
1Freeze new AI tools until the inventory is complete.Operations or ITDay 2
2Move work AI use into managed workspaces where practical.Admin ownerDay 7
3Publish allowed/prohibited data rules.Business ownerDay 7
4Review connectors to Gmail, Drive, Slack, GitHub, CRM, helpdesk, calendar, and meeting platforms.Admin ownerDay 10
5Review AI browser extensions and remove high-risk unmanaged installs.IT ownerDay 14
6Set meeting bot notice, retention, and sharing rules.Sales/CS/People ownerDay 14
7Add developer AI repository and terminal-command rules.Engineering ownerDay 21
8Run the top five tools through the Risk Checker.Tool ownersDay 21
9Create an incident contact path for AI data exposure.Founder or operatorDay 25
10Re-review exceptions and publish final approve/restrict/block list.Business ownerDay 30

Evidence checked

FAQ

Is this checklist a security audit?

No. It is a practical setup review for small teams. It helps identify gaps and next actions, but it is not a penetration test, legal opinion, compliance certification, vendor due diligence report, or security assurance.

How long should the review take?

A small team can complete a first pass in 60-90 minutes if the tool list is short. The hard part is usually not the checklist; it is finding all the personal accounts, browser extensions, meeting bots, and connected apps employees already use.

Who should own the review?

Use two owners: a business owner who decides what risk is acceptable, and an admin owner who can change settings, remove users, revoke connectors, and enforce offboarding.

What should be blocked immediately?

Block shared AI accounts, shared API keys, AI workflows that process secrets, unmanaged extensions with broad access to sensitive work apps, and tools that connect to customer systems without a named owner.

Should every AI tool get the same review?

No. Low-risk tools that only touch public content can use a lighter record. Tools that touch customer data, source code, meeting transcripts, browser page data, email, Drive, CRM, HR, finance, or legal records need a deeper review.

What should we do after this checklist?

Pick the top five tools employees already use, run each through the AI Tool Risk Checker, and copy the final approve/restrict/block decisions into the Small Team AI Security Checklist. If you want an outside fixed-scope pass, review the AI Security Setup Review scope before sending any non-sensitive intake information.