"Who approved this AI tool,
and on what basis?"
That question arrives from an auditor, a customer security questionnaire, or your board — usually with a deadline. The Tracker is where employees request AI tools, where each one gets assessed and decided, and where the dated, attributed record of that decision lives.
From $299/month · Onboarding a first group of teams
The problem
Your AI tool list lives in someone's head.
Somebody approved Otter.ai for the sales team eleven months ago, over Slack. Nobody wrote down what data it was allowed to touch, nobody has looked at it since the vendor changed its retention terms, and the person who approved it has left. That is the normal state of things — and it is fine right up until someone asks you to evidence it.
The request arrives anyway
People will adopt tools whether or not there is a process. Without one, the decision happens in a DM and leaves no trace.
Approvals go stale silently
A tool approved last year against last year's terms is not approved today. Nothing tells you which ones have drifted.
Evidence is reconstructed under pressure
Assembling a defensible history the week an auditor asks is the most expensive possible time to do it — and the least convincing.
How it works
Request, assess, decide, record.
Four steps, and the fourth is the one you are actually buying.
An employee requests a tool
They name it, what they want it for, and what data it would touch. One short form, sent from a link you share.
It gets assessed
The request is classified against the EU AI Act risk tiers and mapped to NIST AI RMF, ISO 42001, SOC 2, GDPR and CCPA, with a risk score and a recommendation. A PDF is generated and filed.
You decide
Approve, approve with conditions, or deny — from a dashboard, with the assessment in front of you. The requester is emailed the outcome automatically.
It becomes the record
The decision, the acting user and the timestamp land in an append-only audit trail, and the tool joins your inventory with a review date.
Scope, stated plainly
What this is — and what it isn't.
This is the section a compliance buyer reads first, so it goes near the top rather than in the small print.
What lands in your inbox
The monthly summary is the point.
On the first of each month, every admin gets a posture report for the month just ended: requests received, how they were decided, what joined the inventory — and, leading the email, every approval that has passed its review date. An approval nobody has revisited is the one an auditor pulls on, so it sits at the top rather than under the counts.
Pricing
Priced per organisation.
Month-to-month. No per-request charge — the point is that people file requests rather than route around the process.
- Unlimited tool requests
- Assessment + PDF per request
- Append-only audit trail
- Tool inventory with review dates
- Monthly posture report
- Everything in Team
- Framework-mapping evidence export
- CSV export of the full audit trail
- Priority coverage for frameworks you name
- Named contact, not a support queue
- Everything in Compliance
- Single sign-on
- Multiple legal entities
- Onboarding for your GRC team
Month-to-month, cancel any time · Covered by the same 30-day money-back guarantee as our other plans
Already have an AI policy? The Tracker enforces one — see the policy generator.
Early access
We're onboarding a first group of teams.
The Tracker is new. We are starting with a small number of organisations so we can cover the frameworks you are actually audited against and fix what does not survive a real approval queue. Tell us what you are up against and we will come back to you personally, usually within two business days.
Questions
What teams ask first
Have the answer before you're asked for it.
Two business days to a reply, and a real conversation about what you're audited against.
Request early access