Finding What Is Already in Use
Discovery done as a hunt produces hiding. Done as a question it produces an inventory and a requirements list.
Discovery · Procedure
Before any policy, find out what is happening. How you conduct that determines whether you get an accurate picture or a quiet one.
The recommendations in “Finding What Is Already in Use” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating time reporting tools can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.
For an independent benchmark, compare the local approach with CISA cyber-risk guidance; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
The framing that works
Announce it. Say what you are doing and why: we want to know what is useful so we can provide it properly.
Make clear nobody is in trouble for what discovery finds.
And mean it, because the first person disciplined over a discovery finding ends your ability to run another one.
The four sources
Network and DNS evidence: which services are being reached.
Browser and endpoint evidence: extensions, installed clients, logged-in sessions.
Expense claims and card data: who is paying for a subscription personally or on a departmental card.
Asking people, which finds what the other three cannot.
Each has its own note. Used together they produce a reasonably complete picture in a fortnight.
Sequence them deliberately
Start with the announcement and the asking, not with the network logs.
An organisation that discovers it has been quietly watched before being asked will answer the survey dishonestly.
The technical sources then confirm and extend what people told you, which is a better use of them than catching people out.
What a good output looks like
A list of tools, with: what task it does, which department, roughly how many people, which account type, and whether anybody assessed it.
Not a list of individuals.
That distinction should be visible in the artefact itself, because the document will circulate further than you intend.
What you will find
More tools than expected, concentrated in a few departments.
At least one tool that is genuinely load-bearing for somebody's work.
AI features switched on inside tools you already approved, which nobody evaluated.
And one or two cases that are genuinely concerning, which is what the exercise is for.
Doing it repeatedly
Once is a snapshot of a fast-moving field.
Quarterly for the first year, then twice yearly.
And a standing route for people to declare something new, which the policy section covers and which reduces how much discovery has to find.
The restraint that matters
Do not act on individual findings during discovery.
Act on patterns: this task needs a tool, this service has unacceptable terms, this department has a gap.
Individual action during a discovery exercise is the thing that makes the next one useless.
What to check
Was your discovery announced, or conducted quietly?
Does the output list tools or people?
Did anybody face consequences for something it found?
And is there a route to declare a tool between exercises?
The point
Announce discovery, promise that findings carry no consequences, and honour it.
The first person disciplined over a finding ends your ability to run another.
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.