The Workflow Edit | Department AI Governance

AI Is No Longer One Tool. It Is a Department-by-Department Stack.

The next AI advantage is not chasing every new model. It is knowing which department uses which AI tool, what it can access, what it costs, and who owns the result.

Dear Suzannah

Dear Suzannah, our team is using AI everywhere now. Marketing has one workflow, sales has another, operations is experimenting, and someone is connecting tools to files and calendars. We bought the software, but I am not sure anyone actually owns the rules. Where do we start?

Start by mapping AI by department, not by tool.

Guess what I found. The problem is not that people are using AI. The problem is that everyone is using AI differently, with different data, different permissions, different costs, and different levels of human review. Very fun. Very modern. Also a beautiful little way to create chaos with a subscription receipt.

A business does not need to panic. It needs a department-level AI stack map.

Here’s the deal

AI is no longer one chatbot sitting politely in a browser tab. It is becoming a work layer across documents, spreadsheets, presentations, files, code, meetings, search, design, websites, and connected apps.

OpenAI has been expanding enterprise administration, usage analytics, spend controls, workspace-scoped admin keys, group management, cost reporting, and analytics. That is not just a product update. That is a signal that AI is becoming something companies have to manage like infrastructure.

At the same time, major AI companies are making huge compute arrangements, regulators are forcing platform access changes, and AI assistants are moving deeper into operating systems, phones, workspaces, and team tools.

Translation: AI is not just a tool choice anymore. It is an operating decision.

What this actually helps you do

A department AI stack map helps you see what is actually happening inside the business.

It answers the questions that matter before the AI sprawl becomes expensive, risky, or impossible to explain:

  • Which departments are using AI?
  • Which tools are approved?
  • Which tools are being used without review?
  • What data is going into each tool?
  • Which apps are connected?
  • Who owns the tool?
  • Who owns the budget?
  • Who reviews the output?
  • What happens if the model is unavailable?
  • What happens if the tool makes a mistake?

The answer cannot be “we trust everyone to be careful.” That is not governance. That is a group project with billing access.

The real use case

This is for small businesses, agencies, consultants, nonprofits, professional service firms, and growing teams that have moved from “let’s try AI” to “why is AI touching half the business?”

Example: marketing uses AI to draft campaigns. Sales uses AI to research prospects. Operations uses AI to summarize meetings. Client services uses AI to write reports. Finance experiments with analysis. HR uses AI to clean up policies.

Each use sounds reasonable alone.

Together, they create a system that needs owners, limits, and a review process.

Three benefits

  • Cleaner decisions: You can approve AI by department and workflow instead of saying yes or no to an entire platform.
  • Lower risk: Sensitive data, connected apps, and automated actions can be controlled before something leaks, posts, sends, or updates.
  • Better ROI: You can measure AI by useful work, not by who is excited about the newest model this week.

No prompt needed: use this workflow instead

This is not a prompt problem. This is a control problem. Before you write a better prompt, build a better map.

  1. List your departments. Start with leadership, sales, marketing, operations, client services, finance, HR, IT, and administration.
  2. List every AI tool in use. Include obvious tools like ChatGPT, Claude, Gemini, Copilot, Canva, Adobe, and coding agents. Also include AI features inside tools your team already uses.
  3. Assign each tool to the departments using it. Do not duplicate the same tool record for every department. Use one tool record with department-specific rules.
  4. Write the approved use case. “Marketing drafts public social posts” is useful. “Marketing uses AI” is not.
  5. Define the data level allowed. Use public, internal, confidential, and restricted.
  6. Document connected systems. Email, calendar, Drive, SharePoint, Slack, CRM, website, billing tools, code repos, and file systems all matter.
  7. Define permitted actions. Drafting is not the same as sending. Reviewing is not the same as publishing. Summarizing is not the same as updating the CRM.
  8. Assign owners. Each department needs a tool owner, data owner, budget owner, and approval owner.
  9. Set cost controls. Track subscriptions, usage-based costs, routing fees, human review time, and rework.
  10. Create fallback rules. Every critical workflow needs a backup tool, backup model, or manual process.
  11. Add an audit trail. Log approvals, exceptions, incidents, policy changes, owner changes, and major AI-assisted outputs.
  12. Review monthly. AI tools change quickly. A quarterly review is the bare minimum. Monthly is better while the stack is still forming.

The Department AI Stack Map

Field What to document Why it matters
Department Marketing, sales, operations, finance, HR, client services, IT, leadership AI risk and value are different by department.
Workflow The actual work AI supports Tools should be approved for specific uses, not vague experimentation.
User-facing tool ChatGPT, Claude, Gemini, Copilot, Canva, Adobe, OpenRouter, or another approved tool This is what the employee sees and uses.
Underlying model The model powering the work, where known Model changes can affect quality, cost, speed, and risk.
Connected systems Email, calendar, Drive, SharePoint, CRM, website, Slack, files, finance systems Connected apps determine what AI can access or affect.
Allowed data Public, internal, confidential, or restricted Data rules prevent accidental exposure.
Permitted actions Draft, summarize, analyze, create, update, send, publish, delete, purchase AI should not have more authority than the business intended.
Human approval Who must review before output is used Finished-looking AI work can still be wrong.
Monthly cost Subscription, token use, routing fees, human review time, and rework AI cost is not only the software bill.
Success metric Accepted-output rate, hours saved, revenue supported, errors reduced, speed gained AI should be measured by useful work, not activity.
Fallback process Backup tool, backup model, manual process, switching owner AI access, pricing, and performance can change quickly.
Shutdown owner The person who can pause access, revoke permissions, or stop an agent Persistent agents need a clear off switch.

Make the result less generic

  • Name the department. Do not approve tools in the abstract.
  • Name the workflow. “Create client proposal draft” is better than “help with client work.”
  • Name the data level. Public content and client-confidential strategy are not the same thing.
  • Name the connected apps. Files, email, calendar, CRM, and billing access change the risk level immediately.
  • Name the human reviewer. If the output leaves the company, someone needs to own the final review.
  • Name the fallback. If the preferred model is unavailable, expensive, restricted, or wrong, the work still needs a plan.
  • Name the stop button. Any AI agent that can keep working needs a person who can shut it down.

What this looks like by department

Marketing

Marketing may use AI for public content drafts, campaign outlines, keyword research, design concepts, captions, video scripts, and ad variations.

The controls should cover brand voice, image rights, source claims, customer testimonials, regulated claims, and final human approval before publishing.

Sales

Sales may use AI for prospect research, email drafts, call prep, follow-up summaries, and CRM notes.

The controls should prevent AI from inventing promises, discounts, case studies, or contract terms. Messages to prospects should be reviewed unless the workflow is formally approved.

Operations

Operations may use AI to create SOPs, summarize meetings, build trackers, prioritize tasks, and automate routine follow-ups.

The controls should define which files AI can access, whether it can update records, and who approves process changes.

Finance

Finance can benefit from AI-assisted categorization, budget summaries, invoice review, and forecast explanations.

The controls must be stricter. Bank credentials, tax IDs, payroll records, payment-card data, and sensitive financial records should not go into general-purpose AI tools without formal approval.

Human Resources

HR may use AI for policy drafts, training materials, job-description cleanup, and internal communications.

The controls should address employee data, hiring bias, disciplinary content, accommodations, confidential records, and legal review.

Client Services

Client-facing teams may use AI for briefs, reports, meeting summaries, recommendations, and project plans.

The controls should distinguish between public client information, confidential strategy, regulated data, and final recommendations. The client should never receive unchecked AI work as if it were finished expert judgment.

Common mistakes

  • Approving the tool but not the workflow: A tool can be safe for one department and risky for another.
  • Ignoring connected apps: AI with file, email, calendar, CRM, or website access is a different risk category than an isolated chat.
  • Letting every department buy its own version: Duplicate tools create duplicate costs, inconsistent rules, and messy reporting.
  • Tracking subscription cost only: Human review time, rework, routing fees, and failed outputs belong in the cost picture too.
  • Skipping fallback planning: Models can change, retire, slow down, get restricted, or become too expensive.
  • No shutdown owner: If an agent can continue working, someone needs authority to stop it.

Quick human check

  • Do you know which departments are using AI?
  • Do you know which tools each department uses?
  • Do you know which tools are approved, restricted, or unapproved?
  • Do you know what data each tool may receive?
  • Do you know which apps each AI tool can access?
  • Do you know who owns the tool, budget, data, and review process?
  • Do you know which workflows require human approval?
  • Do you know the monthly cost by department?
  • Do you know the fallback if a tool fails or access changes?
  • Do you know who can shut down an agent or revoke access?

How to measure success

  • Tool visibility: Every active AI tool is listed and assigned to departments.
  • Owner coverage: Every department AI workflow has a tool owner, data owner, budget owner, and reviewer.
  • Data-rule coverage: Every tool has clear public, internal, confidential, and restricted data rules.
  • Cost control: AI spend is tracked by department, tool, workflow, and accepted output.
  • Output quality: The team tracks accepted outputs, rework, corrections, and human review time.
  • Fallback readiness: Critical workflows have a tested backup model, backup tool, or manual process.
  • Incident readiness: The business has a place to log AI errors, data exposure, unauthorized use, and policy exceptions.
  • Decision speed: The business can approve, restrict, retire, or replace AI tools without starting from scratch every time.

FAQ

Do small businesses really need AI governance?

Yes, but not enterprise theater. A small business needs a practical map of tools, owners, data rules, costs, and approvals. That is enough to prevent most avoidable messes.

Should we approve one AI tool for everyone?

Not automatically. One tool may be appropriate across the business, but the rules should still vary by department and workflow.

What is the difference between an AI tool and an AI stack?

The tool is what the employee uses. The stack includes the tool, model, connected apps, data access, permissions, cost structure, fallback, and review process.

What data should never go into general AI tools?

Passwords, API keys, authentication codes, bank credentials, payment-card data, Social Security numbers, medical records, legally privileged material, and highly sensitive client or employee records should be treated as restricted unless a formal approval process says otherwise.

What is the first thing to build?

Build the Department AI Stack Map. Start with one department, one tool, one workflow, one owner, and one data rule. Then expand.

Glossary

  • AI stack: The full system behind AI use, including tool, model, data access, integrations, permissions, costs, and controls.
  • Department AI governance: Managing AI rules, approvals, owners, costs, and risks by department.
  • Connected app: A system AI can access, such as email, calendar, Drive, SharePoint, Slack, CRM, files, or a website.
  • Fallback model: A backup model used when the primary model is unavailable, too expensive, restricted, or underperforming.
  • Human approval gate: A required review step before AI output is sent, published, filed, updated, or acted on.
  • Audit trail: A record of who used what tool, for which purpose, with what data, and what happened afterward.
  • Restricted data: Highly sensitive information that should not be entered into general AI tools without formal approval.
  • Shutdown owner: The person authorized to pause an AI workflow, revoke access, stop an agent, or disable a risky tool.

Sources and further reading

The practical rule is simple: do not manage AI as one company-wide blob. Manage it by department, workflow, data access, cost, approval, and fallback. That is where the real control lives.

One Response

Leave a Reply

Your email address will not be published. Required fields are marked *

Verified by MonsterInsights