30 minutes total. Run in order.

1 · The expense question (10 min)

Pull 90 days of card/expense data. Search the vendor list: OpenAI, Anthropic, Claude, ChatGPT, Midjourney, Perplexity, Gemini, Copilot, Jasper, Otter, Fireflies, ElevenLabs. Personal-card reimbursements count double — that's someone who wanted the tool badly enough to float the cost themselves.

2 · The network question (10 min)

DNS / secure-web-gateway logs, top AI domains by unique users: chat.openai.com · claude.ai · gemini.google.com · perplexity.ai · copilot.microsoft.com. You want WHO and HOW MUCH — not blocking yet.

3 · The human question (10 min)

Ask team leads, verbatim: "What AI tools does your team use to get work done? Nobody's in trouble — I need the list to protect it." The amnesty framing is the entire trick. Punish honesty once, and you go blind forever. Asked right, question three finds the tools one and two missed.

Then triage

Sort everything into the Inventory database as Approved (low-risk, real value) · Approved with rules (fine unless client data, credentials, or regulated data goes in) · Replace (high-risk, a sanctioned tool already does the job). Write it down — that triage IS your first AI policy.