Eight preconditions that determine whether an organization has authorized AI use — or merely authorized authentication.
For each of the twenty-four items below, mark whether the precondition is complete, partial (underway, undocumented, or contested), or missing. Be honest. An accurate "missing" is more useful than an optimistic "complete."
Until Security writes this down, the organization has authorized how people log in — not what they can do once inside.
Each category of data — public, internal, confidential, restricted, regulated — receives its own explicit verdict. Bulk approval is not approval.
SSO is the floor, not the ceiling. Most organizations stop here and mistake authentication for governance.
AI-specific vendor diligence extends beyond standard SaaS TPRA. Training data terms and subprocessor chains are where the novel exposure lives.
Each integration is its own project. Slack, Drive, Email, CRM — each requires independent security review, independent admin sign-off, and independent coordination.
Public company obligations, sector rules, and jurisdictional exposure — mapped before deployment, not during audit.
What happens after Day One. New use cases, new roles, new incidents — the governance that keeps Phase 0 alive.
AI-generated output is not a decision until a human verifies it. Who checks the output, on what cadence, with what authority — is as foundational as who approves the input.