Deployment Inventory
One row per deployment. Not per tool.
This is the distinction that determines whether your inventory is accurate or misleading.
A tool used three ways is three rows. A tool used one way in four locations may still be one row, but the locations column has to reflect all four.
Why Tools Are the Wrong Unit
A software inventory tells you what you have licensed.
A deployment inventory tells you what you are responsible for.
They are not the same list, and the second is always longer.
| Tool inventory says | Deployment inventory says |
|---|---|
| We have 20 AI tools | We have 34 deployments |
| One row per license | One row per tool-and-use |
| Scoped by procurement | Scoped by what the tools actually do |
Before You Start
Where to find deployments you may not know about:
- The AI approval or governance log
- Procurement records for the last 24 months
- Expense reports — departmental software purchases
- Single sign-on application list
- Network or endpoint tooling — what is actually running
- Ask each business unit lead directly
- Vendor renewal notices
And the one most likely to surface surprises: ask whether any existing tool has recently added AI features. Vendors add them to products you already own, without a new purchase and often without a new approval.
The Inventory
Copy this table and extend as needed. Columns are ordered by what you will need first.
| # | Tool | Use case (one per row) | Business owner | Status | Locations affected | People affected | Decisions about people? | Sensitive data? | Assessments required | Assessment status | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | ||||||||||||
| 2 | ||||||||||||
| 3 | ||||||||||||
| 4 | ||||||||||||
| 5 |
Column Notes
Use case — one per row. If the description contains "and also," split it.
Status — evaluating, pilot, live, or inherited. Inherited means it was running before the process existed. Those need a different conversation than new deployments.
Locations affected — where the people are, not where you are. This column is the one most often wrong.
People affected — roughly. A number is fine. Employees, customers, applicants, patients — note which.
Decisions about people — yes, influences, or no. If yes or influences, this deployment needs closer attention.
Sensitive data — yes or no, and which categories if yes.
Assessments required — from the determination. May be several per row.
Assessment status — not started, in progress, complete, or unresolved pending a scope question.
Working Through It
You will not complete this in one pass. Nobody does.
A workable sequence:
- List every tool you know about
- For each, ask the business lead how many ways it is used
- Split into one row per use
- Fill the locations column — this is where the work is
- Flag the rows involving decisions about people or sensitive data
- Work through the flagged rows first
Step four is the one that takes longest and matters most. Most organizations can name their tools. Very few can name where their affected people are without going to ask.
Prioritizing the Backlog
Work through the flagged rows in this order:
| Priority | Characteristics |
|---|---|
| First | Consequential decisions, sensitive data, limited human review, multiple locations |
| Second | Decisions about people, single location, human review present |
| Third | Personal data, no decisions about individuals |
| Fourth | No personal data, internal outputs only |
Record the prioritization reasoning:
A documented order of work is a program decision. An undocumented one is indistinguishable from having missed something.
Keeping It Current
Add a row when:
- A new tool is approved
- An existing tool is used a new way
- Another team adopts a tool already listed
- A vendor adds AI features to an existing product
Revisit a row when:
- The use case changes
- A new location comes into scope
- The vendor changes something material
- The scheduled review date arrives
The fourth trigger in the first list is the one that gets missed. A product you already own becoming an AI product does not arrive as a purchase request.
Summary Position
Useful for reporting upward.
| Count | |
|---|---|
| Tools in use | |
| Deployments identified | |
| Deployments involving decisions about people | |
| Deployments involving sensitive data | |
| Assessments identified as required | |
| Assessments complete | |
| Assessments outstanding | |
| Deployments not yet assessed for scope |
That last row is the honest one. It is the number that tells you how much of the picture you can actually see.
Inventory owner: ________________
Last updated: ________________
Next full review: ________________
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.