AI Tool Approval Process: How Staff Request a New AI Tool

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for AI Tool Approval Process: How Staff Request a New AI Tool.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for AI Tool Approval Process: How Staff Request a New AI Tool.

Staff fill in a one-page request: the problem, the tool and plan, the data it will touch, who'll use it, the cost and what they tried already. The AI lead checks it against a short list (need, data, security, contract, cost, exit) and replies within five working days: approved, approved with conditions, or declined with a reason.

The point is speed with a paper trail, not gatekeeping. If asking takes longer than signing up for a free account, staff will skip the asking. A workable target for a small team: low-risk requests answered within a day, everything else within a week, and every "no" accompanied by an alternative.

Follow me on Instagram@sagnikteaches

When a request is needed, and when it isn't

Publish this list alongside the form, so nobody has to guess. A request is needed for:

Connect on LinkedInSagnik Bhattacharya
  • Any new AI tool, app, browser extension or add-on, free or paid.
  • Upgrading to a paid plan, or adding seats to one.
  • Connecting an AI tool to company email, files, calendars, the CRM or accounts.
  • Adding an AI meeting recorder or note-taker to calls with customers.
  • Using an already approved tool with a new kind of data, such as customer details for the first time.
  • Switching on a new AI feature inside software you already use, if it will touch customer or staff data.

No request is needed for everyday uses of approved tools that stay inside your usage policy: drafting an internal email, tidying your own meeting notes, rephrasing a job advert. If you haven't yet decided who approves what, set that up first with AI governance for a small business; this tutorial assumes there's a named AI lead.

Subscribe on YouTube@codingliquids

The request form

Keep it to one page. Every extra question costs you requests, and the unasked requests turn into personal accounts. A shared form (Microsoft Forms, Google Forms or a page in your intranet) works better than email, because the answers land in one list the AI lead can track.

AI TOOL REQUEST

Your name:                          Date:
1. What problem will this solve? (one or two sentences)
2. Tool name, website and plan you want:
3. Who will use it, and roughly how often?
4. What information will go into it? Tick all that apply:
   [ ] Nothing about customers or staff
   [ ] Customer names or contact details
   [ ] Job, quote or pricing details
   [ ] Staff information
   [ ] Financial or bank information
   [ ] Photos or recordings of people or their property
5. Will it connect to any company account (email, files, calendar,
   CRM, accounts)? Which?
6. Cost: monthly / annual / free. Is there a contract or minimum term?
7. Have you checked whether a tool we already have can do this?
   What happened?
8. How will we know in 60 days whether it was worth it?

Question 7 does a lot of work. Many requests turn out to be for something Microsoft 365, Google Workspace or your CRM already includes. Question 8 means the review date is set from day one.

Here is a first attempt at the form from a sales coordinator at a bespoke furniture maker, with the answers that needed a follow-up (illustrative):

1. Problem:     I spend ages writing up calls with customers about
                their commissions.
2. Tool/plan:   [AI meeting recorder], Pro plan
3. Who/how often: me, about 8 customer calls a week
4. Data:        [x] Customer names or contact details
                [x] Job, quote or pricing details
5. Connects to: my work calendar, so it can join calls automatically
6. Cost:        about $17 a month, monthly
7. Tried already: no
8. Success:     it saves time

Three answers need another pass before the review can start. "Ages" in question 1 should be a number: the coordinator timed the next three write-ups at 25 minutes each, about three and a half hours a week. Question 7 was "no", and a five-minute look showed that the firm's existing video-call software includes transcripts, though no summaries. And "it saves time" in question 8 became "call write-ups under 10 minutes each, with nothing missing that the customer later disputes". The calendar connection in question 5 also matters: a recorder that joins every meeting automatically will join internal ones too, so the approval has to say which calls it may join.

The reviewer's checklist

Work through these groups in order. If a tool fails the need check, there's no reason to read its privacy terms. Each item says what to check, why it matters, and how to verify it.

A. Need

  • The problem is real and recurring. One-off curiosity doesn't need a paid tool. Verify: ask how often the task happens and how long it takes now.
  • No existing tool does it. Paying twice for the same capability is an easy way to waste money. Verify: check the AI features in your office suite, CRM and accounting software for the same job.
  • There's a success measure. Without one, the 60-day review becomes a matter of opinion. Verify: answer 8 on the form is specific (a number of hours, quotes or replies).

B. Data

  • You know what goes in. The data decides the risk more than the tool does. Verify: the ticks on question 4, confirmed in a two-minute chat with the requester.
  • The vendor doesn't train on your content, or lets you switch it off. Otherwise your customers' details could end up shaping someone else's model. Verify: read the privacy policy and terms for the plan being requested, not the free plan; what to check in an AI tool's privacy policy and terms lists the exact clauses.
  • A data processing agreement exists if personal data is involved. Data-protection rules generally expect a written agreement whenever a supplier handles personal data for you. Verify: look for a "DPA" link in the vendor's legal or trust pages, or ask their support.
  • Retention and deletion are clear. You need to know how long they keep your data and how to delete it. Verify: search the terms for "retention" and "deletion".

C. Security and access

  • Two-factor sign-in is available, and ideally sign-in with your Microsoft or Google work account. Verify: the vendor's security page or the account settings during a trial.
  • There's an admin view if more than one person will use it, so you can remove leavers. Verify: team or business plan feature list.
  • Connections ask only for what they need. A note-taker that wants full access to every email and file is asking for more than it should. Verify: read the permissions screen before clicking accept, during a trial with a test account if possible.
  • Some evidence of security practice for tools touching customer data, such as a SOC 2 Type II report or ISO 27001 certificate. Verify: the vendor's trust page.

D. Contract and terms

  • No surprise lock-in. Annual contracts and auto-renewals are fine once a tool has proved itself, not before. Verify: start on monthly billing where offered.
  • You own what you put in and get out. Verify: search the terms for "ownership" or "your content".
  • Customer-facing uses are allowed by the terms, if that's the plan. Verify: the acceptable-use policy.

E. Cost

  • The real monthly cost is known, including per-seat charges and any usage-based fees. Verify: the pricing page, then a quick calculation for your number of users.
  • It fits the budget line and the approver's spending limit. Above the limit, it goes to the owner.

F. Exit

  • You can export your data in a usable format if you leave. Verify: find the export option during the trial and try it.
  • Someone owns the tool after approval: renewals, users, the 60-day review. Verify: a named owner in the register.

For a tool that will touch customer data, the vendor questions go further; questions to ask an AI vendor before you sign covers the conversation to have before any contract.

The fast lane: low-risk requests answered in a day

Most requests are low risk, and making them wait five days teaches people not to ask. A request qualifies for the fast lane if all of these are true:

  1. It's free, or under your fast-lane limit (say $25 a month) on monthly billing.
  2. Question 4 is ticked "nothing about customers or staff".
  3. It doesn't connect to any company account.
  4. One person will use it.

Fast-lane requests still go on the register, with a 60-day review date. If the requester later wants to add customer data or connect it to email, that's a new request.

Two requests from the same afternoon show where the line falls. An estimator asks for a free AI image tool to mock up planting schemes from stock photos, for their own use, with no customer photos. All four conditions are true: approved that day. A receptionist asks for a free AI writing extension for the browser, "to tidy up emails", and ticks "no company accounts". But a browser extension of that kind typically can read what's typed on the pages where it runs, and the receptionist types in webmail and the booking system all day. So in practice it touches customer data and every account open in that browser. It leaves the fast lane and gets a full review, and the likely answer is the writing help in the office suite, if your plan includes it. The requester wasn't being careless; the form's question simply doesn't make that connection obvious, so it's worth adding "browser extensions count as connected to everything you use in the browser" as a note under question 5.

AI features that arrive by software update

Plenty of new AI turns up by software update rather than by request. Copilot Chat is included in Microsoft 365 business plans, Gemini is now built into Google Workspace business plans, and CRMs and accounting packages keep adding AI assistants. Nobody asks for these, so no form gets filled in.

Two habits cover it. First, make one person responsible for reading vendors' product-update emails and admin notices, and for flagging any new AI feature that can read customer data. Second, where the admin console lets you, leave new AI features off for users until the AI lead has looked at them; turning something on a week late costs little. Treat a new feature that touches new data as a request, filled in by whoever wants it switched on.

In practice it looks like this. A small insurance broker's CRM sends an admin notice: an AI assistant that summarises every email thread with a client, and suggests replies, will be switched on for all users at the next release unless an admin changes the setting. The office manager, who reads those notices, turns it off for everyone except herself, tries it for a week on her own client threads, and checks three things: where the summaries are stored, whether the vendor's terms for the feature differ from the main CRM terms, and whether a suggested reply ever states a policy detail the thread didn't contain. The first two answers were fine. The third wasn't: one suggested reply confirmed a cover limit the thread never mentioned. The feature went on for the team with a condition written into the register, "summaries yes, suggested replies only after a human checks every figure", and a note to recheck at the next major update.

Reply wording for the three outcomes

A clear reply with a reason keeps people using the process. Copy and adapt:

APPROVED
Hi [name], your request for [tool] is approved. I've added it to the
register with you as owner. Please use your work email to sign up and
turn on two-factor sign-in. We'll review it on [date, 60 days on]
against what you said: [success measure].

APPROVED WITH CONDITIONS
Hi [name], [tool] is approved for [use], with these conditions:
- [e.g. no customer names or addresses in uploads]
- [e.g. model-training setting switched off before first use]
- [e.g. monthly billing only until the review]
We'll review it on [date]. If you need it for anything beyond this,
send a new request.

DECLINED
Hi [name], thanks for the request for [tool]. I'm declining it because
[specific reason, e.g. the vendor trains on uploaded content and has no
way to switch it off]. The problem you described is real, so here's
what I suggest instead: [alternative tool, feature or next step].
Happy to talk it through.

Never decline without an alternative or a next step. "No" on its own sends people to their personal accounts.

Filled in, a decline for a real-looking request might read like this. A contracts administrator at a commercial cleaning firm asked for a free "chat with your PDF" website to summarise client contracts before renewals:

"Hi, thanks for the request. I'm declining the PDF site because its free plan keeps uploaded files and uses them to improve its service, with no way to switch that off, and our client contracts include pricing and named site contacts. The problem is real: you're reading about 15 contracts a quarter. Our ChatGPT Business accounts can do the same job, since uploaded files there aren't used for training by default. I've added you to the team plan; start with one contract, and check the summary's renewal dates and notice periods against the original before relying on it."

The reason is specific, the alternative is ready to use, and the last sentence sets the condition without making it sound like a punishment.

Worked example: a landscaping crew leader's request

An illustration. Say a 16-person landscaping business has an office manager acting as AI lead. A crew leader requests an AI quoting app that estimates areas from site photos and drafts a quote. The app has a monthly plan at $39. Answers on the form: quotes take about 40 minutes each and they write around 12 a week; photos of customers' gardens and addresses will go in; no connection to company accounts; success measure is "quote time under 20 minutes without more pricing errors".

The review takes about 90 minutes:

  • Need: passes. Nothing in their current software measures from photos.
  • Data: the terms say uploaded images may be used to improve the vendor's models, with an opt-out in account settings on paid plans. No DPA linked; the office manager emails support and receives one within two days.
  • Security: two-factor sign-in available; no admin view, which is acceptable for a single user.
  • Contract: monthly billing available; the annual plan is cheaper but is declined for now.
  • Exit: quotes export to CSV; tested during the free trial.

Outcome: approved with conditions. Training opt-out on before first use, no customer names in photo file names, monthly billing only, and every AI-drafted quote checked against the price list before sending. Review in 60 days against the 20-minute target. Before committing further, the crew leader runs a structured two-week trial on five real quotes.

Rolling the process out

  1. Explain the why in one message: faster answers and safer customer data, not more rules.
  2. Offer an amnesty. Ask everyone to list the AI tools they already use within two weeks, with no blame attached. You'll likely find a handful of personal accounts; move the useful ones onto proper plans. Shadow AI in a small business covers how to handle that conversation.
  3. Pin the form where people will find it: the team chat, the intranet, the office wall.
  4. Review the process after three months. How many requests came in? What was the average response time? What share were declined? If responses take more than five working days, or more than about a third are declined, the process is too tight and people will route around it.

An amnesty rarely turns up anything alarming, but it nearly always turns up something. In an eleven-person estate agency, the two-week list might hold nine tools. Three were already approved. Two personal ChatGPT accounts were moved onto the business plan. Two were stopped: a free transcription app a negotiator used on valuation visits, which recorded sellers' phone numbers and the times their houses stood empty, and a browser extension with access to the agency's webmail. The remaining two, an image resizer and a spelling tool used on nothing but property descriptions, went on the register as fast-lane approvals. Nobody was disciplined, which is why the next amnesty, a year on, will get honest answers too.

The three-month review is quick if the form's answers land in one list. At the landscaping business in the worked example, the numbers might read: 14 requests, 6 through the fast lane, an average reply time of three and a half working days, and 2 declined, both with alternatives. One outlier took 19 days because the reviewer waited for a vendor's data processing agreement. That led to the only rule change: while a DPA is pending, a tool can be approved for use with no personal data, so the requester isn't left waiting on a vendor's support queue.

Further reads

Sources: vendor pricing and plan pages for Microsoft 365 and Google Workspace (checked September 2026). The worked example is illustrative.

Want an approval process your team will actually use?

On a 1:1 call we'll set the thresholds for your business, adapt the request form and checklist to your tools, and work through a request that's already waiting.

Book a 1:1 call with me