Sets up a complete intake-to-approval pipeline for AI tool access requests. Creates a Jira issue type with structured fields, configures automation rules for risk-based tier assignment and reviewer routing, adds Slack notifications for transparency, and includes a security review runbook with decision templates.
Standardized workflow for employees to request AI tool access with auto-routing to security review.
Integrations: Jira, Slack
Help the user define risk-based tiers:
| Tier | Risk Level | Examples | Approval Required |
|---|---|---|---|
| Tier 1: Pre-Approved | Low | GitHub Copilot, Cursor (with SSO) | Auto-approved, manager notification |
| Tier 2: Standard Review |
| Medium |
| ChatGPT Team, Claude, custom MCP servers |
| Manager + Security review (SLA: 3 days) |
| Tier 3: Extended Review | High | Tools handling PII/PHI, self-hosted LLMs, fine-tuned models | Manager + Security + Legal + CISO (SLA: 10 days) |
Set up a Jira issue type "AI Tool Access Request" with these fields:
| Field | Type | Required |
|---|---|---|
| Tool Name | Short text | Yes |
| Tool URL/Vendor | URL | Yes |
| Business Justification | Long text | Yes |
| Data Types Involved | Multi-select (None, Internal, Confidential, PII, PHI) | Yes |
| Team/Department | Select | Yes |
| Number of Seats | Number | Yes |
| Estimated Monthly Cost | Number | No |
| Urgency | Select (Standard, Expedited) | No |
Set up automation rules:
Configure Slack integration:
Provide a runbook for the security review team:
The workflow produces: