Anonymous staff survey
The highest-yield method. Short, anonymous, framed as fact-finding rather than enforcement. See the design notes below — how you ask determines whether people tell the truth.
Guide · Discover phase
Before you write a single rule about AI, find out what your client's staff are already doing. A structured discovery engagement gives you a real deliverable, a defensible starting point, and a natural path into follow-on work.
Why discovery comes first
It is tempting to open a client engagement with a policy template — fill in the company name, adjust a few clauses, send it out. This almost never works: a policy written in ignorance of what people actually use gets ignored.
If the accounting team has been pasting client data into a free AI tool to draft emails, a policy that never mentions it will not stop them. If nobody realizes the CRM vendor turned on an AI summarization feature by default, banning "AI tools" in the abstract does nothing about it. Rules written for a company that does not exist do not get followed by the company that does.
Discovery flips the order. Find out what is already happening, sort it into what is fine, what needs conditions, and what needs to stop — then write anything down. The resulting policy reads like it was written by someone who has met the client, because it was.
This is also the honest reason discovery is worth charging for. It produces information the client did not have, organized so they can act on it. That is a deliverable, not a preamble to the real work.
Shadow AI discovery
"Shadow AI" is shadow IT with a current name: tools employees adopted on their own because they solved a problem faster than asking IT. None of these methods require covert monitoring — tell staff you're running an assessment and why. Combine several; each catches things the others miss.
The highest-yield method. Short, anonymous, framed as fact-finding rather than enforcement. See the design notes below — how you ask determines whether people tell the truth.
Pull recent expense reports and card statements for AI-adjacent vendor names, and check the company's software subscription list. Personal-card subscriptions expensed back to the business are a strong signal of unmanaged tool sprawl.
Most identity providers (Google Workspace, Microsoft 365 admin center) show which third-party apps employees have granted access to their account. Review this list for AI writing assistants, meeting bots, and extensions with access to email, files, or calendar.
Ask managers directly what their team does day to day, and where they've looked for a faster way to do it. Frontline managers often know about tool use their own leadership does not.
This is the one that surprises people. Platforms the client already pays for — CRM, help desk, video conferencing, productivity suites — often ship AI features (summarization, drafting, transcription) turned on by default in a recent update. Nobody "adopted" a new tool; the existing tool changed under them. Check admin settings and release notes for every major platform in use, not just the obvious AI brands.
Survey design
A badly designed survey produces a clean-looking report that is wrong. Four design choices matter more than the question list itself:
Illustrative starting point — adapt the wording and length to the client, not a standard to reuse unchanged:
Interviews
What is driving interest in doing this now? What would make this a wasted engagement? Any tools they've explicitly heard about and want addressed or blocked?
What is already managed centrally (SSO, device management, approved software list)? What visibility exists into third-party app access? Any past incidents involving a tool leaking data?
What does their team spend time on? Where have they encouraged — or quietly tolerated — a faster way of working? What would they want a policy to make easier, not just safer?
Keep interviews to 20–30 minutes each, aimed at specific, concrete answers about current behavior — not opinions about AI in general.
The inventory
A tool register is only useful if it captures enough detail to decide on later. For each tool found via survey, interview, or technical review, log:
That last field matters most. "Drafts follow-up emails to prospects" is something you can make a bounded decision about. "AI tool for productivity" is not.
The deliverable
Raw survey notes and interview transcripts aren't a deliverable — they're working material. What the client pays for is a package with four parts:
Plain-language account of what discovery turned up: which tools, how many people, what kind of data, and any surprises (especially the "already switched on" category).
Every tool gets an initial verdict. Default to Conditionally approved rather than a standing Approved — even for Low-risk tools. Low does not mean auto-Approve, and Approved does not mean unrestricted; a first-pass register bounds risk while you learn more, not settles it permanently.
Not fifty open questions — the handful of calls only the client can make, such as whether a tool handling customer data continues, or a department exception is warranted.
What happens next, in order: interim guidance, a formal policy, tool-specific reviews, and an ongoing review cadence.
A findings summary with no recommended decisions is homework you're handing back to the client.The verdicts and shortlist are what make it a deliverable.
The follow-on
Done well, the assessment produces its own next step. The 30-day rollout proposal is the pitch for a second, larger engagement: the acceptable-use policy, tool-by-tool reviews, employee guidance, and a living tool register.
After rollout, the ongoing relationship is a light quarterly review: revisit the register, check for new tools, confirm nothing Conditionally approved has quietly become unrestricted, and promote anything stable to standing Approved. That cadence turns a one-off fee into a recurring line item, without becoming a heavy compliance program the client resents paying for.
Common mistakes
FAQ
It depends on client size and how many systems you're reviewing. Scope it as a fixed, bounded engagement with a clear survey window and defined interview list, rather than leaving it open-ended.
No — this is usually available directly in the client's existing identity provider admin console (for example, connected apps or third-party access settings in Google Workspace or Microsoft 365). Check the vendor's current documentation for the exact path, since layouts change.
Reviewing company-paid expenses and admin-console records the client already controls is generally straightforward, but monitoring practices carry legal and HR obligations that vary by jurisdiction. Recommend transparency with staff about what's being reviewed and why, and have clients confirm specifics with their own legal or HR advisor first.
That's a legitimate finding, not a failed assessment — it means the client has more headroom to design proactive guidance before habits form, rather than reacting to entrenched shadow use. Say so plainly in the findings summary instead of padding the report.
Where this fits
Everything above is the Discover phase of the Discover → Decide → Operate method behind the AI Guardrails Kit. Running it well from scratch takes real preparation: a survey you trust, an interview list, a register template, and a way to turn findings into verdicts instead of just notes.
The MSP / Consultant Pack ($299) ships a client-ready discovery agenda, a client pitch one-pager, scope language for bounding the engagement, and a practitioner license to reuse the materials across every client. It also includes the Decide and Operate materials this discovery work feeds into: the acceptable-use policy, tool playbooks, and the quarterly review structure described above.
The full kit is available now on the AI Guardrails Kit page — Business Pack $79, MSP / Consultant Pack $299, one-time. Read more on the For MSPs page, or try the free AI tool checklist to see the style first. Questions: hello@railstead.com.
Operational templates only — not legal, compliance, privacy, security, HR, or professional advice. Seller: CurioHausCo LLC.