✳By Hero Published Sept 12, 2026 · Updated Oct 7, 2026
The useful detailsList every AI tool your team uses, including free accounts, browser add-ons and apps connected to work email or files. Note what each is for, what information goes in and who owns it. Then keep a short approved list, cut the overlap, and give people one simple way to ask for something new.
Make the list from people, not only from receipts
Invoices show what you pay for. They miss free accounts, personal subscriptions, browser extensions and AI features switched on inside software you already use. So ask two groups: whoever pays the bills, and the people doing the work. An anonymous question works best: "Which AI tools have you used for work in the last month, including free ones?"
Apps connected to work accounts can read far more than a single chat. Ask your administrator to check:
Microsoft 365: the Microsoft Entra admin center, under Enterprise applications, lists apps people have signed in to or granted access with their work account.
Google Workspace: the Admin console, under Security, then Access and data control, then API controls, shows third-party apps with access to your domain's data.
Individual Google accounts: each person can check Security, then "Your connections to third-party apps and services", in their Google Account.
Chat and file tools (Slack, Teams, Dropbox and similar): the admin settings list installed apps and integrations.
Browsers: each person's extensions page. AI writing helpers and "summarize this page" add-ons often read everything on screen.
AI tools themselves: the settings, usually under apps or connectors, show what a ChatGPT, Copilot or Gemini account can reach.
Menu names change from time to time. If you can't find these, search the vendor's help centre for "third-party app access".
An inventory you can copy
Tool and plan
Who holds the login
Used by, for what
Information that goes in
Cost and renewal
Status
Owner
Example: Copilot Chat, work accounts
IT admin
Everyone, drafting and summaries
Internal documents; no red-list data
Included in Microsoft 365
Approved
Office manager
Example: free AI website
Personal account
Two people, rewording client emails
Client names and details
Free
Stop
Office manager
Example: meeting note-taker add-on
One manager, personal sign-up
Team meetings
Everything said in meetings
Monthly card charge
Review
Office manager
The examples are illustrative. Use one row per tool and per plan: a personal and a business account of the same brand are different rows.
Core: the approved tool most people use. Usually one.
Specialist: a tool a few people need for a specific job, with a named owner.
Experiment: allowed for a set period with an end date. An experiment with no end date becomes clutter.
Duplicate: does what a core tool already does. Plan to move people off it.
Remove: risky, unexplained or unowned. Especially anything personal that handles client or employee information.
One door for new requests
Give people one short way to ask for a new tool: what task, who will use it, what information goes in, and how they do it today. Low-risk requests should get a quick answer. Anything touching client, employee or health information gets a slower, careful yes or no. If requests vanish into silence, people go back to personal accounts.
If you remove a tool, say what replaces the work
Cancelling a subscription while the team still depends on it just moves the work to someone's personal account. For every tool you remove, name the approved way to do that job, and show people how before the old one goes.