# AI tool review sheet

Syndesi.io | One tool, one use case | Version 1, September 2026

Use this with the person doing the work and the person managing access. Keep the completed record and evidence in your approved workspace. Record data categories, not confidential examples. Mark unknowns explicitly.

| Field | Your record |
| --- | --- |
| Tool / provider / account / plan | |
| Proposed use and intended users | |
| Expected useful result | |
| Trial measures, including review effort | |
| Allowed data categories | |
| Excluded data categories | |
| Connected systems and permitted scope | |
| Allowed actions: read / draft / change / send | |
| Actions or connections that stay disabled | |
| Reviewer and backup | |
| Review criteria and approval point | |
| Person responsible for the use case | |
| Administrator who manages access | |
| Reporting contact and how to reach them | |
| How to pause the use | |
| How the work continues while paused | |
| Evidence checked, checker, date and restricted evidence location | |
| Open questions | |
| Next action, action owner and due date | |
| Decision: pending / limited trial / approved for this use / declined | |
| Conditions and boundaries of that decision | |
| Decision maker and date | |
| Next review date and earlier review triggers | |

**Review the actual setup.** Written instructions alone do not establish which permissions are enabled. Confirm that the controls support the intended limits.

**Close the open questions.** A completed form is not evidence that a setting was checked. Record what supports the decision and revisit it when the use changes.

This is a practical working aid, not a security verification, certification or complete governance program.

Need to list the tools first? Use the [AI inventory guide](https://ai-audit.tools/guides/ai-inventory). For help reviewing the setup and making decisions, see [Syndesi's AI Risk and Readiness Review](https://www.syndesi.io/ai-governance-readiness).
