AI approval sheet and staff-use note
For Cybersecurity, Automation & AI, Owner
MSP Stockroom / Free working sheet / October 7, 2026
Read https://mspstockroom.com/guides/ai-safe-use.html for the complete method.
AI approval sheet and staff-use note
- Use-case ID and purpose: [one activity / expected outcome].
- Authority: [business owner / data owner / qualified reviewer where needed / approval date].
- Approved tool: [product / plan / organization account / tenant or workspace].
- Input boundary: [permitted classes and fields / prohibited inputs / redaction method].
- Data-flow evidence: [training / retention / access / sharing / connected features / URLs and review dates].
- Unknown or unavailable controls: [gap / consequence / owner / decision].
- Output boundary: [destination / required human check / excluded actions].
- Monitoring: [events or references retained / storage access / retention / alert owner].
- Validation: [fictional test cases / observed results / pause and reporting route checked].
- Review trigger: [expiry / product change / connector change / new data category].
- Staff instruction: use [approved account] only for [activity] with [permitted inputs]. Never enter credentials or client secrets. Keep [excluded data] out. Check [facts and approval requirements] before using output.
- Staff escalation: ask [owner / route] before a new use. If excluded data enters the tool, stop [affected activity] and report through [incident route] using a safe reference, not another copy of the data.
- Remaining human work: [approval / output review / incident handling / capacity effect].
Before using this sheet
Choose the owner, scope and period. Use safe references rather than private customer exports. Keep missing evidence marked unknown.
Use and license status
License: adapt internally for your MSP and the clients you support; do not resell or redistribute the source files. See https://mspstockroom.com/terms.html.