Practical guides / AI governance

AI inventory: record the owner, authority, cost and ending

Build an AI inventory that supports governance decisions: human ownership, approved actions, usage evidence, cost allocation and verified retirement.

Operational ITAM · Practical guidance · September 21, 2026

  1. Discover
  2. Assign an owner
  3. Bound authority
  4. Measure
  5. Review the ending
A decision sequence to adapt to your own operating environment.

An inventory should change a decision

A list of AI product names is useful for discovery, but it cannot tell a reviewer whether an agent may send a customer message, which data a retrieval tool can expose, or who must reconcile a usage charge. Start with a service or use case that someone can own. Link the application, subscription, model, agent and relevant data sources without pretending they are the same asset.

Start with six decision fields

Record a stable service identifier; a named human owner and backup; the approved purpose; permitted data and actions; the source of usage and billing evidence; and the renewal or retirement route. Mark unknown fields as unknown. A missing owner is an unresolved decision, not a reason to insert a department name and call the register complete.

Worked example: an internal drafting assistant

Suppose a team buys an assistant to draft internal support replies. Its approved purpose is drafting, not sending. The service owner accepts responsibility for access, the data owner identifies permitted knowledge sources, and a human approves any external reply. Link the subscription to the billing owner and record where acceptance evidence lives. If the product later gains an autonomous send action, that is a change requiring review—not merely an updated version number.

Reconcile discovery against authority

Compare procurement records, expense reports, identity assignments and approved technical discovery sources. A discovered subscription does not prove approved use. Conversely, a procurement record does not prove that access has ended. Record the source and date of each observation, resolve conflicting records with a named authority, and retain the reason for the decision.

Ask how it ends before renewal

Identify who can disable identities, export required records, verify deletion where applicable, and close commercial commitments. Test the route while the service is still operating. A canceled subscription alone is not evidence that integrations, retained data and agent permissions have ended.

Source context

Methods can be adapted internationally. The paid collection’s jurisdiction-specific operating guidance centers on the United States and Canada; apply local requirements and actual contracts. Examples are illustrative, not guaranteed savings or certification.

Browse free starter resources · All practical guides