Worksheet 6 · Deployment InventoryThe Handbook
06Worksheet 6 of 6

Deployment Inventory

One row per deployment. Not per tool.

This is the distinction that determines whether your inventory is accurate or misleading.

A tool used three ways is three rows. A tool used one way in four locations may still be one row, but the locations column has to reflect all four.


Why Tools Are the Wrong Unit

A software inventory tells you what you have licensed.

A deployment inventory tells you what you are responsible for.

They are not the same list, and the second is always longer.

Tool inventory saysDeployment inventory says
We have 20 AI toolsWe have 34 deployments
One row per licenseOne row per tool-and-use
Scoped by procurementScoped by what the tools actually do

Before You Start

Where to find deployments you may not know about:

  • The AI approval or governance log
  • Procurement records for the last 24 months
  • Expense reports — departmental software purchases
  • Single sign-on application list
  • Network or endpoint tooling — what is actually running
  • Ask each business unit lead directly
  • Vendor renewal notices

And the one most likely to surface surprises: ask whether any existing tool has recently added AI features. Vendors add them to products you already own, without a new purchase and often without a new approval.


The Inventory

Copy this table and extend as needed. Columns are ordered by what you will need first.

#ToolUse case (one per row)Business ownerStatusLocations affectedPeople affectedDecisions about people?Sensitive data?Assessments requiredAssessment statusLast reviewedNext review
1
2
3
4
5

Column Notes

Use case — one per row. If the description contains "and also," split it.

Status — evaluating, pilot, live, or inherited. Inherited means it was running before the process existed. Those need a different conversation than new deployments.

Locations affected — where the people are, not where you are. This column is the one most often wrong.

People affected — roughly. A number is fine. Employees, customers, applicants, patients — note which.

Decisions about people — yes, influences, or no. If yes or influences, this deployment needs closer attention.

Sensitive data — yes or no, and which categories if yes.

Assessments required — from the determination. May be several per row.

Assessment status — not started, in progress, complete, or unresolved pending a scope question.


Working Through It

You will not complete this in one pass. Nobody does.

A workable sequence:

  1. List every tool you know about
  2. For each, ask the business lead how many ways it is used
  3. Split into one row per use
  4. Fill the locations column — this is where the work is
  5. Flag the rows involving decisions about people or sensitive data
  6. Work through the flagged rows first

Step four is the one that takes longest and matters most. Most organizations can name their tools. Very few can name where their affected people are without going to ask.


Prioritizing the Backlog

Work through the flagged rows in this order:

PriorityCharacteristics
FirstConsequential decisions, sensitive data, limited human review, multiple locations
SecondDecisions about people, single location, human review present
ThirdPersonal data, no decisions about individuals
FourthNo personal data, internal outputs only

Record the prioritization reasoning:



A documented order of work is a program decision. An undocumented one is indistinguishable from having missed something.


Keeping It Current

Add a row when:

  • A new tool is approved
  • An existing tool is used a new way
  • Another team adopts a tool already listed
  • A vendor adds AI features to an existing product

Revisit a row when:

  • The use case changes
  • A new location comes into scope
  • The vendor changes something material
  • The scheduled review date arrives

The fourth trigger in the first list is the one that gets missed. A product you already own becoming an AI product does not arrive as a purchase request.


Summary Position

Useful for reporting upward.

Count
Tools in use
Deployments identified
Deployments involving decisions about people
Deployments involving sensitive data
Assessments identified as required
Assessments complete
Assessments outstanding
Deployments not yet assessed for scope

That last row is the honest one. It is the number that tells you how much of the picture you can actually see.


Inventory owner: ________________

Last updated: ________________

Next full review: ________________


Use and reuse

Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.

LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com

Written by compliance and audit practitioners who spent decades on the other side of the table.

Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.

Contents
Talk to usWe're here to help
AI Deployment Inventory Worksheet | LegisGate