AI Tool Approval Checklist: Five Decisions Before You Connect
A practical guide to reviewing an AI tool's purpose, data access, permissions, human review and ownership, with a worked example and an editable review sheet.
Before you connect an AI tool to your inbox or CRM, decide what work it should do, what information it can use, which actions it can take, who checks the result and who is responsible for it. Record those decisions for the specific use you are approving.
That is the purpose of this AI tool approval checklist. It gives an owner and the people doing the work a starting point for deciding what to enable, what to check and what to leave off.
One distinction matters throughout: approving a tool for one task does not answer whether it belongs in another.
Start with the work someone needs to use
We built a prospecting system for a commercial insurance agency. A focused list now arrives every Monday, built around the agency's niche. The agency owner reviews it and decides where to spend her time.
Getting to that point took more than collecting names.
Commercial permits were one source. A permit might name the contractor when the person the agency needed to reach was the owner. We had to connect the public record to the right person, find a contact path and explain why the business might be worth approaching.
The agency owner brought her market knowledge. We brought the AI development, worked with specialist input and went through trial and error to get it right.
The output needed enough context to prepare her for a conversation, presented clearly and briefly enough to use. She still decides whom to approach. A permit does not tell us that someone wants to buy insurance.
That experience shapes how I think about introducing AI into a business. I want to know what the person using it needs to understand, and where that person's judgment belongs in the process.
The five decisions
Use the questions below for one tool and one use case. Include AI features in software you already pay for if you are turning on a new capability or connection.
| Decision | What to record |
|---|---|
| Work | The task, the person using the result and what a useful result looks like. |
| Information | The data categories, connected systems and evidence about how the provider handles them. |
| Actions | What the tool may read, draft, change or send, including what stays disabled. |
| Review | Who checks the work, what they check and when approval is needed. |
| Responsibility | Who owns the use case, who can change or pause it and when to review it again. |
These are practical starting decisions. Broader AI governance also includes training, supplier management, incident handling and other work appropriate to the business. NIST's AI Risk Management Framework is a voluntary framework for managing AI risks; this checklist is not a complete implementation of it.
1. What job are we approving?
“Help with sales” leaves too much open.
“Prepare a draft reply to an inbound inquiry using our approved service information” gives people something they can review. It identifies the work, the source material and the expected output.
Write down what would make that output useful. For a draft reply, that might mean answering the customer's question accurately, leaving pricing commitments to the salesperson and making missing information obvious.
Also decide how you will judge the trial. I would track how many drafts were used, how much correction they needed and the review time involved. A tool producing more drafts is only useful if the team can put them to work.
2. What information does the tool need?
List the categories of information involved: public service descriptions, customer correspondence, internal pricing or another clearly defined source. Keep actual confidential material out of the review sheet.
Then have the administrator check what the tool can reach. A connection intended for one task deserves a closer look if it also exposes unrelated folders or mailboxes.
Record what you have verified for the actual product, account and plan. That includes the applicable terms and settings for retention, deletion and model training, along with where the evidence is kept and when it was checked.
If the answer is unknown, give the question to someone who can resolve it before enabling that use. For an initial trial, I would use approved public material or made-up examples while those questions are open.
3. What may it do with that information?
Be specific about the verbs. Reading an email, drafting a response and sending it are different permissions. So are suggesting a CRM update and changing the record.
For an email drafting trial, I would begin with human review before anything is sent. The administrator should confirm that the available controls match that decision. A sentence in a prompt is not evidence that sending is disabled.
If the product cannot support the limits you need, change the setup or choose another way to run the trial.
Treat a later request for sending access or another connection as a new decision. Record why the additional capability is needed and who approved it.
4. Who reviews the result, and what do they check?
My rule: no reviewer, no run.
For this kind of trial, I want the reviewer identified before the work starts. Give that person a clear definition of acceptable output and room in their day to check it.
For the email example, the review could cover the recipient, the facts used, the answer to the question and any price or delivery commitment. Unsupported details should be removed or checked against an approved source.
NIST's Generative AI Profile, section 2.2 describes how generative AI can present incorrect information confidently. A polished draft still needs checking against what the business knows.
In our prospecting work, the agency owner needs context about the person and the business before deciding whether to approach them. The same question belongs in another workflow: what must the reviewer know to make the decision you are asking them to make?
5. Who keeps it working when something changes?
Name the person responsible for the use case, the administrator who can change access and the person staff should contact with a problem. In a small business, one person may hold several roles. Confirm that they know it.
Record how to pause the connection and what work needs to happen manually if it stops. Set a date to review the trial. Revisit the decision sooner if the data, permissions, provider terms or business use changes.
Maintaining an AI inventory and defining responsibilities are part of NIST's Govern guidance, including outcomes 1.6 and 2.1. In day-to-day terms, someone needs to be able to explain the setup and deal with the next question.
A worked example: an email drafting assistant
This is an illustrative setup, not a client deployment or a description of a particular product. The controls would need to be checked in the selected tool.
| Item | Proposed decision |
|---|---|
| Job | Draft replies to general service inquiries using approved public information. |
| Initial data | Made-up inquiries and public service descriptions. No live mailbox connection during this first check. |
| Actions | Prepare drafts. No sending, CRM changes or additional connections. Verify these limits in the actual setup. |
| Reviewer | Sales lead checks accuracy, relevance and commitments before using a draft. |
| Trial evidence | Log whether drafts were usable, what needed correction and how long review took. |
| Open question | Administrator checks the selected plan's terms, data handling and connection permissions before any live email use. |
| Responsibility | Business owner decides whether to expand the trial. Administrator controls access and confirms how to pause it. |
| Review | Choose a date before starting. Reassess before adding live customer information or sending access. |
This record leaves the live connection pending. It gives the team useful work to do while the administrator resolves the questions that affect that decision.
Put one tool through the review
Start with the tool you are about to connect, or one already handling important work. Use the AI tool review sheet below to record your answers. An existing connection can go through the same review.
If you first need a list of what your team uses, our AI inventory guide and free template cover that earlier step.
AI tool review sheet
Download the editable review sheet, or copy the fields below into your own working document. Keep supporting evidence in your approved workspace.
- Tool, provider, account and plan:
- Proposed use and intended users:
- Useful result and trial measures:
- Allowed data and connected systems:
- Allowed actions and limits:
- Reviewer, review criteria and approval point:
- Use case owner, administrator and backup contact:
- How to pause the use and continue the work:
- Evidence checked, by whom, on what date and where it is stored:
- Unknowns, next action, action owner and due date:
- Decision and conditions: pending / limited trial / approved for this use / declined:
- Decision maker, decision date and next review date:
An incomplete field is a question to resolve. Completing the sheet does not itself verify a tool's security or establish compliance.
For a broader starting point, take the free AI Exposure Check. We built it at Syndesi to help owners organize questions about tools, data, access, ownership and oversight. It uses your answers and suggests what to review next. It does not inspect your systems.
If you need help checking the evidence and working through the decisions, our AI Risk and Readiness Review covers that work. Tell us which tool or workflow you are reviewing.
Peter Belanger is co-founder of Syndesi, an AI venture studio that builds and operates AI-powered revenue systems.
