Decision inputs
Facts that change the policy answer
The request sits in it and security and connects network or application-discovery telemetry with a list of possible shadow AI use. That context distinguishes it from a generic permission to use AI.
- 1Task and owner
- Security architect wants to identify unapproved AI tools in company traffic. The request needs an accountable owner for a list of possible shadow AI use, even when the tool prepares most of the first draft.
- 2Information involved
- Network or application-discovery telemetry. Check uploads, history and connected systems before describing the request as low sensitivity.
- 3Tool and account
- An approved company account. Approval must cover the account and its settings, not merely the product name.
- 4Intended result
- The expected result is a list of possible shadow AI use. The policy needs to know what happens after generation, including publication, communication and automated use.
- 5Consequence if it is wrong
- Traffic data can be ambiguous and may expose individual employee activity. Use this consequence to distinguish a routine request from one needing specialist approval.
- 6Human review
- security and privacy owners should inspect, change, reject or stop the result. The reviewer needs the source material and must be able to reject the output before it takes effect.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
A routine route is easier to justify when the exact account is approved, only the minimum employee and network telemetry is used, a list of possible shadow AI use remains within the stated purpose, and security and privacy owners reviews it before use.
Approval may be required
A named reviewer should take over when the account or data handling is uncertain, traffic data can be ambiguous and may expose individual employee activity, or a list of possible shadow AI use reaches people or systems beyond the requester’s authority.
The request may need to stop or change
The company may need a safer design when restricted information would enter an unapproved service, the output would act before security and privacy owners can intervene, or verify the service and context before contacting a user or restricting access cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Will identify unapproved AI tools in company traffic run inside the approved company environment from start to finish?
- 02
What is the most sensitive element in network or application-discovery telemetry, and does the tool need it?
- 03
Who receives a list of possible shadow AI use, and what will they do with it?
- 04
Will security and privacy owners review before the result is sent, published or acted upon?
- 05
Does the intended use extend beyond the region and audience covered by the current policy?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- security architect
- task
- Use AI to identify unapproved AI tools in company traffic.
- information
- network or application-discovery telemetry
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Analyse
- impact
- Security policy enforcement
- review
- Complete human review
- owner
- security and privacy owners
Useful safeguards
Controls that fit this request
- ✓
Verify the service and context before contacting a user or restricting access
- ✓
Reduce network or application-discovery telemetry to the smallest useful extract and remove fields unrelated to a list of possible shadow AI use.
- ✓
Write the boundary around a list of possible shadow AI use clearly so later users do not expand the approval by assumption.
- ✓
Preserve who accepted a list of possible shadow AI use, when they did so and which rule version they applied.
Questions people ask
About this AI use
Is using AI to identify unapproved AI tools in company traffic automatically allowed?
The company policy supplies the answer after it receives the real tool, data, purpose, impact and review plan. This page only prepares those facts.
What belongs in the employee’s request?
Describe a list of possible shadow AI use, identify network or application-discovery telemetry, name the exact tool and account, explain who will receive or rely on the output, and state how security and privacy owners will review it.
How should a later reviewer understand this decision?
Preserve who accepted a list of possible shadow AI use, when they did so and which rule version they applied. A classification and controlled reference may be enough when copying network or application-discovery telemetry would create unnecessary risk.