✓ ✓ ✗ ✗
Learn / Sanctioned AI

An approved AI list people actually follow

Most sanctioned-tools policies fail the same way: a list nobody can find, criteria nobody understands, and a request path slower than just using the tool. This page builds the version that works, and shows how an audit turns it into a number.

Measure your sanctioned share free
First principles

What "sanctioned" should actually mean

Sanctioned is a contract state, not a mood. A tool earns the label when four conditions hold at once.

1

The right tier is licensed

The organization pays for the business or enterprise tier, not employees expensing consumer plans.

Why: data protections live in paid tiers. Sanctioning the free tier sanctions its terms too.

2

Training terms are settled in writing

The contract or terms state no training on your content, with the verdict's check date recorded.

Why: 85.5% of tools say nothing about training. Silence cannot be sanctioned; a dated commitment can.

3

Access runs through SSO

Accounts are provisioned and deprovisioned centrally, never personal signups with work email.

Why: offboarding. A sanctioned tool that survives departures is shadow AI with a receipt.

4

An owner is named

Someone owns the renewal, the terms re-check and the "should this stay sanctioned" question.

Why: verdicts drift. Ownerless entries rot on the list until an auditor finds them first.

Everything not meeting all four is unsanctioned. Not evil, not banned, just unmeasured, which is exactly what the audit's sanctioned split quantifies.

Building the list

Start from usage, not from a catalog

Lists built from vendor brochures get ignored. Lists built from what staff already chose get adopted, because they legalize the popular.

Step 1: audit first

Run a full audit and sort the tool table by user count. The top of that column is your candidate list, pre-validated by adoption. The walkthrough gets you there in an afternoon.

Step 2: gate the top ten

Push each popular tool through the four gates. Tools that pass go on the list; tools that fail get an enterprise-tier negotiation or a stated no with a reason.

Step 3: publish with the why

One page: the list, each tool's approved uses, and the request path. The reasons matter; "no-training terms, checked on this date" educates while it governs.

Keep it short on purpose

  • Five to ten tools cover most organizations' real needs across text, code, image and transcription.
  • Every added tool adds a renewal, a terms watch and an owner. List size is a maintenance budget.

Make the request path faster than sneaking

  • One form or one Slack message, answered within two business days, with the gates as the public rubric.
  • When asking is fast, the audit's "new tools since last run" list shrinks on its own.
The measurement loop

How the audit turns policy into a number

Paste your sanctioned list into the audit and every report splits reality against it. That split is the only honest adoption metric.

What the split showsReadingMove
High sanctioned share, few unsanctioned toolsThe list matches reality. Governance is working.Hold cadence; spot-check verdict dates.
Popular tools missing from the listThe list lags adoption; staff voted with usage.Gate the top unsanctioned tools this month.
Sanctioned tools with near-zero usageYou bought what nobody wanted.Ask the teams why before renewal, not after.
Unsanctioned twins of sanctioned toolsThe sanctioned option is worse or unknown.Fix the tool or the awareness, then re-measure.

The sanctioned list you provide is used for the split in your report only. Uploads are read once and discarded; reports live 90 days, deletable earlier.

Failure modes

Why sanctioned lists die, and the antidotes

Four deaths we see repeatedly, each preventable by design.

Death by committee

Six months to approve one chatbot means staff decided five months ago. Antidote: the two-day request SLA, with a provisional "controlled trial" state for hard cases.

Death by blanket ban

"No AI" reads as "no asking". Usage continues, minus the visibility. Antidote: a real list with real tools on it, so compliance has a destination.

Death by staleness

The list still names a tool that changed its terms last spring. Antidote: owners per entry plus quarterly re-audits; changed verdicts between runs are review triggers.

Death by invisibility

A perfect list nobody can find governs nothing. Antidote: the list lives where work happens, linked from the tools' own request-denied pages if you block.

See the sanctioned split rendered

The sample report shows the split and the per-tool sanctioned column exactly as your board would see them, on sample data.

Open the sample report
Category playbook

Sanctioning by category, not by brand

Approve capabilities, then name the tool that fills each. It keeps the list stable while brands churn.

Text and chat

  • One general assistant on an enterprise tier covers most demand.
  • Watch for: staff preferring a niche writing tool; gate it or explain the assistant's same feature.

Code

  • One assistant, org-wide license, repository-aware settings reviewed by engineering leadership.
  • Watch for: service-account API use that bypasses the seat license entirely.

Transcription and meetings

  • The strictest gate: it hears everything. No-training terms plus a consent workflow are the floor.
  • Watch for: bots invited by external parties to your calls, which no list controls.

Image and video

  • License questions dominate: commercial-use rights per tier matter as much as training terms.
  • Watch for: client-deliverable work in consumer tiers, the classic agency finding.

Data analysis

  • Spreadsheet uploads are data exports. Sanction one copilot with contractual protections, block casual alternatives.

Everything abusive

  • Deepfake, nudify and uncensored generators are never gate candidates. Block on sight; the audit flags them for you. The tier logic is on the risks page.
FAQ

Sanctioned list questions

How many tools should a sanctioned list hold?

Five to ten covers most organizations. Each entry costs an owner, a renewal and a terms watch, so size the list to your maintenance capacity.

Should we sanction free tiers?

Rarely. Training protections and admin controls live in paid tiers; sanctioning a free tier endorses terms you cannot rely on.

What about tools that refuse enterprise terms?

Then the organization decides with open eyes: accept the stated terms in writing, or block with the reason published. Both beat silent tolerance.

How do we measure whether the list works?

The audit's sanctioned split, quarterly. Rising sanctioned share with falling unsanctioned tool count is the success curve.

Who should own the sanctioned list?

One named owner overall, typically in security or IT, plus per-entry owners for renewals and terms re-checks. Committees advise; owners decide.

What happens to tools we reject?

Publish the reason, offer the sanctioned alternative, and block only what stays risky. The ordering argument lives on detect before you block.

Build the list from what your logs already know

The audit hands you the candidate list, the risk context and the measurement loop. The four gates do the rest.

Run the free audit