Get shadow AI into the light (L3)

People are already pasting customer data into personal accounts on personal cards, and an ungoverned L1 is more dangerous than no AI at all because exposure is live and visibility is zero. Banning tools drives usage underground, so the fix is amnesty first, then making the sanctioned path on Okta, Entra ID or Google Workspace SSO faster than the shadow one. Fits any company above roughly 50 employees, and is urgent in healthcare, financial services, insurance, legal, defense and education.

WORKFLOW1Run an amnesty survey wit… the CRO's name on the announcGoogle Forms2Find the paid shadow spen… in the expense dataRamp3Sanction two tools, not e…ghtManual4Put them behind SSO and m…ke that path genuinely fasterOkta5Write a one-page rule set…anyone can recite from memoryNotion6Re-run amnesty quarterly …nd update the listOkta7Instrument the resultManual
7 steps, in order, with the tool that owns each one.
Adoption ladderSix levels from Starter to Rebuilt. This item sits at level 3.L1 StarterOne tool, no workflow changeL2 AssistedAI drafts, humans approveL3 IntegratedWired into CRM and SlackL4 OrchestratedMulti-step, owned, measuredL5 AutonomousAgent runs, human auditsL6 RebuiltThe process itself changes
This playbook belongs at L3 Integrated. Running it above your level is how pilots stall.
Measures of successPercentage of AI usage through SSO-managed accounts; Shadow spend reclaimedPROVE IT WORKEDPercentage of AI usage through SSO-managed accountsShadow spend reclaimed

The steps

  1. 01

    Run an amnesty survey with the CRO's name on the announcement

    Tool: Google Forms

    Three questions only: which AI tools do you use for work, what do you use them for, are you paying personally. The announcement matters more than the form. State plainly: nobody gets in trouble, the goal is to buy the good ones properly, and the survey is anonymous. If it comes from IT with the word "compliance" in it, response rate collapses and you learn nothing. Nobody taught us how to do this, so there is no blame to hand out. • Owner: RevOps, sponsored by the CRO or CIO • Tool options: an anonymous Google Form or Microsoft Form, announced in Slack or Teams by the sponsor personally • Pitfall: letting IT send the survey with compliance language attached, which collapses response rate • Definition of done: response rate clears 60% and you have a tool list with real use cases attached

  2. 02

    Find the paid shadow spend in the expense data

    Tool: Ramp

    Search 12 months of expense and card data for every AI vendor name, including all the ones surfaced in step 1 plus the obvious majors. Total it, and break it down per vendor and per department. The number is almost always larger than anyone guessed, and it is what funds the sanctioned rollout without a new budget request. • Owner: Finance • Tool options: Ramp, Brex, Expensify, Concur or Navan • Pitfall: underestimating shadow spend by only searching for a few obvious vendor names • Definition of done: a dollar figure exists with a per-vendor and per-department breakdown

  3. 03

    Sanction two tools, not eight

    One general assistant, plus one specialist tool covering the single most common shadow use case from the survey. Business or enterprise tier only, consumer tiers train on your data by default and have no admin controls. Three things must be documented before launch: training-on-your-data is off, retention is configured to your policy, and the DPA is signed. Publish those three facts internally, because "is it safe to paste this" is the question that drives people back to personal accounts. Two supported tools beats eight tolerated ones. • Owner: CIO or CRO plus legal • Tool options: procurement • Pitfall: sanctioning consumer tiers, which train on your data by default and have no admin controls • Definition of done: two contracts are signed and the three data facts are published where employees can find them

  4. 04

    Put them behind SSO and make that path genuinely faster

    Tool: Okta

    Enable and enforce SSO so usage becomes visible and offboarding actually works. Then do the part most companies skip: make the sanctioned path faster than the shadow one. Pre-load company context into shared Projects, publish saved prompts for the top five use cases, no personal card, no second login, one click from Slack or Teams. People route around governance whenever governance is slower. Every time. If your approved tool takes three clicks more than the personal one, you have built a policy, not a solution. • Owner: IT • Tool options: Okta, Microsoft Entra ID, Google Workspace SSO or JumpCloud • Pitfall: shipping a sanctioned path slower than the shadow one, which people route around • Definition of done: SSO is enforced, and weekly active users through SSO exceed the usage level the survey reported

  5. 05

    Write a one-page rule set anyone can recite from memory

    Tool: Notion

    Three lists with one concrete example under each. Always fine: drafting internal content, summarizing public material, brainstorming. Never: named customer PII, unreleased pricing, source code, anything under NDA, health or payment data. Ask first: anything customer-facing, anything with a compliance claim, anything going to a regulator. One page, nobody reads fourteen. Then spot-check: ask ten people in the revenue org to name the three never-items. If they cannot, the page is too long or nobody has seen it. • Owner: Legal plus enablement • Tool options: one page in Notion, Confluence or the intranet • Pitfall: writing a policy longer than one page that nobody actually reads • Definition of done: 90% of a ten-person spot check can name the three never-items unprompted

  6. 06

    Re-run amnesty quarterly and update the list

    Tool: Okta

    New tools appear monthly and the shadow list regenerates. Re-survey quarterly, compare against SSO usage data, and add or retire tools based on what people actually adopted rather than what you hoped they would. Expect to change the sanctioned list at least once a year. • Owner: RevOps • Tool options: the same survey plus SSO app reports from Okta or Entra • Pitfall: treating the sanctioned list as permanent instead of re-surveying quarterly • Definition of done: two quarterly cycles are complete and the sanctioned list has changed at least once as a result

  7. 07

    Instrument the result

    Instrument: percentage of AI usage happening through SSO-managed accounts, plus shadow spend reclaimed. The first number is the risk metric, the second pays for the program. • Where it breaks: you lead with the ban. Usage goes dark, you lose the visibility you were buying, and the next incident is one you cannot see coming. Second failure: the sanctioned tool is slower or more locked down than the shadow one, so adoption stalls and people keep two workflows. Third: the survey comes from IT with compliance language attached, response rate hits 20%, and you plan a rollout on bad data. • Visual guidance: the same org chart twice. Before: scattered dots outside a boundary, labeled with personal accounts and personal cards. After: dots inside the boundary, two tool logos, one SSO gate. No numbers needed.

Tools in this playbook

Next playbooks

Unfamiliar terms are defined in the AI and Revenue Dictionary. Related frameworks live in the framework library.

Share this playbook

Posting to Instagram or TikTok? Copy the link, it carries the title, summary and share image.

Arrives weekly by email. Free. Unsubscribe anytime. By subscribing you agree to our Privacy policy and Terms. We never sell or share the list.