Staff fill in a one-page request: the problem, the tool and plan, the data it will touch, who'll use it, the cost and what they tried already. The AI lead checks it against a short list (need, data, security, contract, cost, exit) and replies within five working days: approved, approved with conditions, or declined with a reason.
The point is speed with a paper trail, not gatekeeping. If asking takes longer than signing up for a free account, staff will skip the asking. A workable target for a small team: low-risk requests answered within a day, everything else within a week, and every "no" accompanied by an alternative.
When a request is needed, and when it isn't
Publish this list alongside the form, so nobody has to guess. A request is needed for:
- Any new AI tool, app, browser extension or add-on, free or paid.
- Upgrading to a paid plan, or adding seats to one.
- Connecting an AI tool to company email, files, calendars, the CRM or accounts.
- Adding an AI meeting recorder or note-taker to calls with customers.
- Using an already approved tool with a new kind of data, such as customer details for the first time.
- Switching on a new AI feature inside software you already use, if it will touch customer or staff data.
No request is needed for everyday uses of approved tools that stay inside your usage policy: drafting an internal email, tidying your own meeting notes, rephrasing a job advert. If you haven't yet decided who approves what, set that up first with AI governance for a small business; this tutorial assumes there's a named AI lead.
The request form
Keep it to one page. Every extra question costs you requests, and the unasked requests turn into personal accounts. A shared form (Microsoft Forms, Google Forms or a page in your intranet) works better than email, because the answers land in one list the AI lead can track.
AI TOOL REQUEST
Your name: Date:
1. What problem will this solve? (one or two sentences)
2. Tool name, website and plan you want:
3. Who will use it, and roughly how often?
4. What information will go into it? Tick all that apply:
[ ] Nothing about customers or staff
[ ] Customer names or contact details
[ ] Job, quote or pricing details
[ ] Staff information
[ ] Financial or bank information
[ ] Photos or recordings of people or their property
5. Will it connect to any company account (email, files, calendar,
CRM, accounts)? Which?
6. Cost: monthly / annual / free. Is there a contract or minimum term?
7. Have you checked whether a tool we already have can do this?
What happened?
8. How will we know in 60 days whether it was worth it?
Question 7 does a lot of work. Many requests turn out to be for something Microsoft 365, Google Workspace or your CRM already includes. Question 8 means the review date is set from day one.
Here is a first attempt at the form from a sales coordinator at a bespoke furniture maker, with the answers that needed a follow-up (illustrative):
1. Problem: I spend ages writing up calls with customers about
their commissions.
2. Tool/plan: [AI meeting recorder], Pro plan
3. Who/how often: me, about 8 customer calls a week
4. Data: [x] Customer names or contact details
[x] Job, quote or pricing details
5. Connects to: my work calendar, so it can join calls automatically
6. Cost: about $17 a month, monthly
7. Tried already: no
8. Success: it saves time
Three answers need another pass before the review can start. "Ages" in question 1 should be a number: the coordinator timed the next three write-ups at 25 minutes each, about three and a half hours a week. Question 7 was "no", and a five-minute look showed that the firm's existing video-call software includes transcripts, though no summaries. And "it saves time" in question 8 became "call write-ups under 10 minutes each, with nothing missing that the customer later disputes". The calendar connection in question 5 also matters: a recorder that joins every meeting automatically will join internal ones too, so the approval has to say which calls it may join.
The reviewer's checklist
Work through these groups in order. If a tool fails the need check, there's no reason to read its privacy terms. Each item says what to check, why it matters, and how to verify it.
A. Need
- The problem is real and recurring. One-off curiosity doesn't need a paid tool. Verify: ask how often the task happens and how long it takes now.
- No existing tool does it. Paying twice for the same capability is an easy way to waste money. Verify: check the AI features in your office suite, CRM and accounting software for the same job.
- There's a success measure. Without one, the 60-day review becomes a matter of opinion. Verify: answer 8 on the form is specific (a number of hours, quotes or replies).
B. Data
- You know what goes in. The data decides the risk more than the tool does. Verify: the ticks on question 4, confirmed in a two-minute chat with the requester.
- The vendor doesn't train on your content, or lets you switch it off. Otherwise your customers' details could end up shaping someone else's model. Verify: read the privacy policy and terms for the plan being requested, not the free plan; what to check in an AI tool's privacy policy and terms lists the exact clauses.
- A data processing agreement exists if personal data is involved. Data-protection rules generally expect a written agreement whenever a supplier handles personal data for you. Verify: look for a "DPA" link in the vendor's legal or trust pages, or ask their support.
- Retention and deletion are clear. You need to know how long they keep your data and how to delete it. Verify: search the terms for "retention" and "deletion".
C. Security and access
- Two-factor sign-in is available, and ideally sign-in with your Microsoft or Google work account. Verify: the vendor's security page or the account settings during a trial.
- There's an admin view if more than one person will use it, so you can remove leavers. Verify: team or business plan feature list.
- Connections ask only for what they need. A note-taker that wants full access to every email and file is asking for more than it should. Verify: read the permissions screen before clicking accept, during a trial with a test account if possible.
- Some evidence of security practice for tools touching customer data, such as a SOC 2 Type II report or ISO 27001 certificate. Verify: the vendor's trust page.
D. Contract and terms
- No surprise lock-in. Annual contracts and auto-renewals are fine once a tool has proved itself, not before. Verify: start on monthly billing where offered.
- You own what you put in and get out. Verify: search the terms for "ownership" or "your content".
- Customer-facing uses are allowed by the terms, if that's the plan. Verify: the acceptable-use policy.
E. Cost
- The real monthly cost is known, including per-seat charges and any usage-based fees. Verify: the pricing page, then a quick calculation for your number of users.
- It fits the budget line and the approver's spending limit. Above the limit, it goes to the owner.
F. Exit
- You can export your data in a usable format if you leave. Verify: find the export option during the trial and try it.
- Someone owns the tool after approval: renewals, users, the 60-day review. Verify: a named owner in the register.
For a tool that will touch customer data, the vendor questions go further; questions to ask an AI vendor before you sign covers the conversation to have before any contract.
The fast lane: low-risk requests answered in a day
Most requests are low risk, and making them wait five days teaches people not to ask. A request qualifies for the fast lane if all of these are true:
- It's free, or under your fast-lane limit (say $25 a month) on monthly billing.
- Question 4 is ticked "nothing about customers or staff".
- It doesn't connect to any company account.
- One person will use it.
Fast-lane requests still go on the register, with a 60-day review date. If the requester later wants to add customer data or connect it to email, that's a new request.
Two requests from the same afternoon show where the line falls. An estimator asks for a free AI image tool to mock up planting schemes from stock photos, for their own use, with no customer photos. All four conditions are true: approved that day. A receptionist asks for a free AI writing extension for the browser, "to tidy up emails", and ticks "no company accounts". But a browser extension of that kind typically can read what's typed on the pages where it runs, and the receptionist types in webmail and the booking system all day. So in practice it touches customer data and every account open in that browser. It leaves the fast lane and gets a full review, and the likely answer is the writing help in the office suite, if your plan includes it. The requester wasn't being careless; the form's question simply doesn't make that connection obvious, so it's worth adding "browser extensions count as connected to everything you use in the browser" as a note under question 5.
AI features that arrive by software update
Plenty of new AI turns up by software update rather than by request. Copilot Chat is included in Microsoft 365 business plans, Gemini is now built into Google Workspace business plans, and CRMs and accounting packages keep adding AI assistants. Nobody asks for these, so no form gets filled in.
Two habits cover it. First, make one person responsible for reading vendors' product-update emails and admin notices, and for flagging any new AI feature that can read customer data. Second, where the admin console lets you, leave new AI features off for users until the AI lead has looked at them; turning something on a week late costs little. Treat a new feature that touches new data as a request, filled in by whoever wants it switched on.
In practice it looks like this. A small insurance broker's CRM sends an admin notice: an AI assistant that summarises every email thread with a client, and suggests replies, will be switched on for all users at the next release unless an admin changes the setting. The office manager, who reads those notices, turns it off for everyone except herself, tries it for a week on her own client threads, and checks three things: where the summaries are stored, whether the vendor's terms for the feature differ from the main CRM terms, and whether a suggested reply ever states a policy detail the thread didn't contain. The first two answers were fine. The third wasn't: one suggested reply confirmed a cover limit the thread never mentioned. The feature went on for the team with a condition written into the register, "summaries yes, suggested replies only after a human checks every figure", and a note to recheck at the next major update.
Reply wording for the three outcomes
A clear reply with a reason keeps people using the process. Copy and adapt:
APPROVED
Hi [name], your request for [tool] is approved. I've added it to the
register with you as owner. Please use your work email to sign up and
turn on two-factor sign-in. We'll review it on [date, 60 days on]
against what you said: [success measure].
APPROVED WITH CONDITIONS
Hi [name], [tool] is approved for [use], with these conditions:
- [e.g. no customer names or addresses in uploads]
- [e.g. model-training setting switched off before first use]
- [e.g. monthly billing only until the review]
We'll review it on [date]. If you need it for anything beyond this,
send a new request.
DECLINED
Hi [name], thanks for the request for [tool]. I'm declining it because
[specific reason, e.g. the vendor trains on uploaded content and has no
way to switch it off]. The problem you described is real, so here's
what I suggest instead: [alternative tool, feature or next step].
Happy to talk it through.
Never decline without an alternative or a next step. "No" on its own sends people to their personal accounts.
Filled in, a decline for a real-looking request might read like this. A contracts administrator at a commercial cleaning firm asked for a free "chat with your PDF" website to summarise client contracts before renewals:
"Hi, thanks for the request. I'm declining the PDF site because its free plan keeps uploaded files and uses them to improve its service, with no way to switch that off, and our client contracts include pricing and named site contacts. The problem is real: you're reading about 15 contracts a quarter. Our ChatGPT Business accounts can do the same job, since uploaded files there aren't used for training by default. I've added you to the team plan; start with one contract, and check the summary's renewal dates and notice periods against the original before relying on it."
The reason is specific, the alternative is ready to use, and the last sentence sets the condition without making it sound like a punishment.
Worked example: a landscaping crew leader's request
An illustration. Say a 16-person landscaping business has an office manager acting as AI lead. A crew leader requests an AI quoting app that estimates areas from site photos and drafts a quote. The app has a monthly plan at $39. Answers on the form: quotes take about 40 minutes each and they write around 12 a week; photos of customers' gardens and addresses will go in; no connection to company accounts; success measure is "quote time under 20 minutes without more pricing errors".
The review takes about 90 minutes:
- Need: passes. Nothing in their current software measures from photos.
- Data: the terms say uploaded images may be used to improve the vendor's models, with an opt-out in account settings on paid plans. No DPA linked; the office manager emails support and receives one within two days.
- Security: two-factor sign-in available; no admin view, which is acceptable for a single user.
- Contract: monthly billing available; the annual plan is cheaper but is declined for now.
- Exit: quotes export to CSV; tested during the free trial.
Outcome: approved with conditions. Training opt-out on before first use, no customer names in photo file names, monthly billing only, and every AI-drafted quote checked against the price list before sending. Review in 60 days against the 20-minute target. Before committing further, the crew leader runs a structured two-week trial on five real quotes.
Rolling the process out
- Explain the why in one message: faster answers and safer customer data, not more rules.
- Offer an amnesty. Ask everyone to list the AI tools they already use within two weeks, with no blame attached. You'll likely find a handful of personal accounts; move the useful ones onto proper plans. Shadow AI in a small business covers how to handle that conversation.
- Pin the form where people will find it: the team chat, the intranet, the office wall.
- Review the process after three months. How many requests came in? What was the average response time? What share were declined? If responses take more than five working days, or more than about a third are declined, the process is too tight and people will route around it.
An amnesty rarely turns up anything alarming, but it nearly always turns up something. In an eleven-person estate agency, the two-week list might hold nine tools. Three were already approved. Two personal ChatGPT accounts were moved onto the business plan. Two were stopped: a free transcription app a negotiator used on valuation visits, which recorded sellers' phone numbers and the times their houses stood empty, and a browser extension with access to the agency's webmail. The remaining two, an image resizer and a spelling tool used on nothing but property descriptions, went on the register as fast-lane approvals. Nobody was disciplined, which is why the next amnesty, a year on, will get honest answers too.
The three-month review is quick if the form's answers land in one list. At the landscaping business in the worked example, the numbers might read: 14 requests, 6 through the fast lane, an average reply time of three and a half working days, and 2 declined, both with alternatives. One outlier took 19 days because the reviewer waited for a vendor's data processing agreement. That led to the only rule change: while a DPA is pending, a tool can be approved for use with no personal data, so the requester isn't left waiting on a vendor's support queue.
Further reads
- What to Do Before You Buy Any AI Tool: A 10-Point Checklist — The owner's own pre-purchase checklist.
- SOC 2 and ISO 27001 Explained: Checking an AI Vendor's Security — What those security badges actually tell a reviewer.
- What to Check in an AI Vendor's Data Processing Agreement — Reading the contract clause that covers your data.
- How to Audit Your AI Subscriptions and Cut Wasted Spend — Catch tools that were approved and then forgotten.
- Where Is Your Data Stored When You Use AI Tools? — Answer the storage question on the checklist.
- Who in Your Team Actually Needs a Paid AI Licence? — Decide who gets a seat once a tool is approved.
- A Simple AI Risk Register for Small Businesses (With Template) — A one-table AI risk register with a scoring scale, a template to copy, twelve filled-in rows from a florist and the triggers for updating it.
- Who Should Own AI in a Small Business? Roles and Responsibilities — The four roles AI needs in any small firm, how they're split in a barber shop, an optician and a garden centre, and a responsibilities chart to copy.
- How to Choose and Support an AI Champion in a Small Team — A weighted scoring sheet for candidates, a one-page remit template, a monthly check-in agenda and a music school example with time costs.
- How to Write an AI Usage Policy for Your Small Business — Section-by-section wording, a data traffic-light table, a one-page template and how a tutoring agency's first draft changed after staff read it.
- How to Roll Out an AI Policy So Staff Actually Follow It — The launch plan for an AI policy: one-page rules, an amnesty for hidden tools, paid accounts that beat free ones, and checks that don't feel like spying.
- Does a Five-Person Business Really Need an AI Policy? — Why a five-person business needs a one-page AI policy rather than a handbook: six triggers, a complete template, and when one page stops being enough.
- AI Acceptable Use Policy for a Small Professional Firm — A clause-by-clause checklist and one-page sample policy for accountants, lawyers and consultants who handle confidential client work.
- How to Set Spending Rules and Approvals for Business Purchases — Create a purchase policy that checks the full commitment, reserves the budget and gives staff a clear route for routine and urgent spending.
- Does Cyber Insurance Cover AI Incidents? What Insurers Ask — Which AI incidents a cyber policy usually covers, where the grey areas are, and how to answer the new AI questions on insurers' proposal forms.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: vendor pricing and plan pages for Microsoft 365 and Google Workspace (checked September 2026). The worked example is illustrative.