Usage controls
Approved tools, permitted data, staff training, exceptions, and escalation.
Movahedi Control Atlas checklist
A first-pass checklist for privacy, security, legal, product, and risk teams moving from shadow AI discovery to accountable operation.
For general operational guidance only. It is not legal advice, an AI audit, or a security certification.
Seven operating moves
List models, agents, copilots, vendors, experiments, and embedded AI features. Name a business owner and technical owner for each.
Record purpose, affected people, data sensitivity, decision impact, scale, human involvement, and plausible harm.
Map prompts, training or retrieval data, model providers, subprocessors, integrations, access paths, retention, and transfers.
Define approved tools, prohibited inputs, review gates, training expectations, exception handling, and escalation.
Specify who reviews outputs, when a person can challenge or stop an outcome, and how overrides are recorded.
Test quality, safety, privacy, bias, and security before release; monitor meaningful changes and performance after release.
Define detection, containment, investigation, notification, rollback, corrective action, and learning for harmful output or drift.
Keep the boundary clear
Approved tools, permitted data, staff training, exceptions, and escalation.
Identity, authorization, secrets, prompt handling, integrations, logging, testing, and runtime protection.
This checklist is maintained by Mohammad Movahedi as part of the Movahedi Control Atlas. Confirm current legal, regulatory, contractual, and security requirements for your facts and jurisdiction.