Map workplace AI use through transparent conversations about tasks, accounts and data categories, without collecting private prompts or treating silence as proof.

Direct answer: Ask staff to describe the tools, accounts, tasks and broad data categories involved in their work, using a clearly explained conversation or short form. Do not request private prompt histories, passwords or screen recordings, and do not treat a missing response as evidence of no AI use. Use the findings to clarify approved workflows and address risks; a suspected security incident requires its own authorised investigation, not a covert extension of the inventory.

A list of applications is not enough. The same assistant might be used to rephrase public text or process confidential customer material. The task and information flow determine what you need to examine next.

The quality of the inventory also depends on whether people believe its stated purpose. The parent guide recommends an honest starting point for team AI adoption. Here the narrower job is to obtain useful information without turning that conversation into an undisclosed performance assessment.

Applies to: a small team's transparent fact-finding exercise, with UK employment and data-protection context. Requirements differ by country, sector and contract; obtain qualified local advice for monitoring, disputes or formal investigations.

Use the voluntary workflow inventory

The voluntary workflow inventory is an editorial method for collecting task-level descriptions and recording the limits of what people report. It is not a monitoring product, a compliance certification or a promise that self-reporting identifies every use.

First decide what the information will change. A useful purpose is identifying which workflows need approved accounts, clearer instructions or support. “Find out who is most productive with AI” is a different exercise and should not be smuggled into the same form.

Name the person who will receive responses and who can see the raw detail. Explain the intended retention and the planned team-level output before collecting anything. Do not promise anonymity if names, sign-in information or distinctive roles can identify respondents.

Voluntary participation is not itself a blanket data-protection lawful basis. The ICO's employment-record guidance warns that the employer-worker power imbalance can make consent difficult to rely on. It also calls for defined purposes and appropriate handling of worker information. The guidance is currently marked as under review following legislative changes, so get specific advice where the decision depends on it. ICO guidance on collecting employment records.

Explain the purpose before asking for answers

Use a short explanation that matches what you will actually do. For example: “We want to understand which work tasks need AI guidance or approved support. Please describe tools and data categories, not customer details or private conversations. The operations lead will review responses and share a task-level summary.”

Add your actual position on existing-policy breaches and incidents. Do not promise immunity you lack authority to grant. If a response reveals a possible exposure of restricted information, it may need escalation under the relevant process. Explain that boundary honestly without making the whole exercise sound like a disciplinary trap.

The NCSC describes shadow AI as AI use outside an organisation's approved systems and processes. Its guidance emphasises understanding why staff turn to such tools and encouraging open communication, rather than assuming the risk can be eliminated. NCSC guidance on the hidden risks of shadow AI.

My recommendation is to begin with transparent task discussions rather than buying screen-monitoring software for this purpose. Self-reporting is incomplete, but it can explain unmet needs that activity logs do not. In an actual incident, authorised security evidence may be necessary; that does not make covert collection an appropriate default for ordinary fact-finding.

Ask for the minimum useful task record

Use one record per distinct use, not one per person. The questions should be simple enough to answer without reconstructing a month of work:

QuestionUseful level of detail
Which tool or embedded feature?Product and feature name, if known
Which account arrangement?Personal, organisation-provided or uncertain
What task does it support?A concrete activity, not a whole department
What information goes in?Public text, internal material, customer information or another broad category
What happens to the output?Private draft, internal review, client delivery or automated action
What is difficult without it?The unmet need or recurring friction

Include an “unsure” answer. A colleague may not know whether a feature uses AI or which account terms apply. That uncertainty is useful work for the account owner, not evidence that the colleague was careless.

Do not ask for example prompts if a task description will do. A prompt can contain the very personal or confidential information you are trying not to spread. Where a demonstration would genuinely clarify the workflow, ask the colleague to use fictional material in an approved setting.

Offer a short conversation as an alternative to the form. Acas describes consultation as both talking and listening, and recognises direct discussions and representative routes. Choose the appropriate route for your workplace rather than assuming one online form gives everyone a meaningful voice. Acas guidance on consulting employees.

Count tools and uses separately

Suppose an illustrative eight-person studio reports 19 tool-task combinations. Several people use the same application differently, and some report the same workflow. All counts and timings here are hypothetical.

After checking the descriptions, you identify seven distinct tools and 14 distinct workflows. Five records describe already listed tool-task uses: 19 - 5 = 14. You retain which accounts and data categories differ rather than merging those details away.

The inventory is not “19 AI tools”, and 14 workflows do not mean every workflow has been discovered. If six of the eight staff respond, the response proportion is 6 ÷ 8 = 75%. It does not establish that the remaining two use no AI.

Assume each of the six respondents spends eight minutes completing the exercise, the coordinator spends three minutes on each submitted record, and four clarifying conversations take ten minutes each:

(6 × 8) + (19 × 3) + (4 × 10) = 48 + 57 + 40 = 145 minutes.

Add a 25-minute coordinator review to prepare the decisions, giving 170 minutes of total person-time. A ten-minute meeting with all eight staff would add 80 person-minutes, not ten. Include that cost if you choose the meeting.

This is an inventory workload, not a productivity gain. Its value depends on the decisions it enables, such as moving a recurring task to an approved account or stopping an unsafe connection.

Turn incomplete findings into bounded decisions

Separate confirmed facts, self-reported descriptions and unresolved details. “Staff member reports using a personal account” is not the same as verified supplier retention terms. Ask the responsible owner to check those terms without requesting access to the person's private history.

Classify the next action at workflow level: clarify account approval, review a proposed data flow, provide an existing alternative, or handle a potential incident through the correct route. Give each action an owner. Do not rank colleagues by how many tools they mention.

The ICO's monitoring guidance says employers should be clear about their purpose and choose the least intrusive way to achieve it. It also treats transparency and proportionality as central considerations. A hidden screen-capture exercise is not made acceptable by calling it an inventory. ICO guidance on monitoring workers.

Share the useful outcome with staff: what was learned, which questions remain open and what support or rules will change. If you cannot act on a request, explain why and provide the interim method. Asking people for details and then offering no response makes the next inventory harder to justify.

Complete a first pass within one working week

  1. On the first day, define the purpose, recipients, collection method and information boundaries. Resolve privacy and consultation questions before collecting responses.
  2. Give staff a reasonable window to describe their workflows, with a conversation option. Use fictional examples to show the requested level of detail.
  3. Review the records, ask narrow follow-up questions and separate tools from tasks. Mark missing responses and uncertain facts without making assumptions.
  4. By the end of the week, assign the most consequential next actions and share a task-level summary. Set a date to review changes, not to collect everyone's history continuously.

Stop and use the appropriate incident process if the exercise reveals a possible security or data exposure. Do not broaden access to private accounts or devices just because you want a more complete spreadsheet.

Frequently asked questions

Should the survey be anonymous?

Use anonymity only if you can genuinely provide it and it suits the decision. In a small team, a unique job or tool can identify someone even without a name field. A truly anonymous survey may surface concerns but make it difficult to clarify the account or workflow. A confidential named conversation can be more useful when access is tightly limited and the purpose is credible. Explain the arrangement accurately before collecting responses. Do not label a signed-in form anonymous without checking what identifiers the service and its administrators can retain.

What if a colleague says they do not use AI but their software includes it?

Record their answer and clarify the feature, rather than treating the discrepancy as dishonesty. People may use an embedded function without knowing how it works, and not every automated feature is AI. Ask about the actual task and feature name, then have the software owner check current documentation. Keep observed capability separate from assumptions about use. If the feature is optional, its availability does not prove it was enabled. The inventory should improve shared understanding, not reward confident terminology over an accurate description of what someone does.

Can I compare the responses with company billing records?

You may be able to use existing business records within an appropriate, authorised purpose, but explain the comparison and do not overinterpret it. A paid subscription proves an expense, not which data was uploaded or whether the tool remains in use. Conversely, free services will not appear on a bill. Limit access to the people who need it and avoid importing unrelated personal information into the inventory. If the proposed cross-check changes the purpose or becomes employee monitoring, seek the relevant advice and approval before proceeding rather than treating it as routine housekeeping.

What if staff are worried that admitting AI use threatens their jobs?

Address the concern directly and honestly. Explain what decisions the exercise will and will not inform, and do not promise job security or immunity beyond your authority. Give people a route to raise concerns through a representative or an appropriate confidential conversation. Ask about friction and support needs rather than demanding estimates of how replaceable their work is. If workforce changes are actually under consideration, do not disguise that purpose as a harmless tool inventory. The applicable employment and consultation process needs to be handled openly with appropriate qualified advice.

Should we collect prompt histories to verify what people say?

Not as part of this ordinary task inventory. Histories can contain unrelated private material, customer information and confidential work, while still failing to explain the context of use. Ask a narrow clarification or request a fictional demonstration when you need to understand a workflow. If there is a specific incident that requires evidence, use the authorised investigation process with appropriate scope and safeguards. Do not ask staff to export entire personal accounts for convenience. More collected text does not automatically mean a more reliable or proportionate understanding of workplace behaviour.

How long should we retain the responses?

Keep identifiable responses only for a justified purpose and review point, while preserving the operational decisions the team still needs. There is no single retention period for every workplace inventory. Consider relevant legal or contractual requirements before deleting records, and limit access while they remain. You may be able to retain a task-level register after removing unnecessary respondent detail, but do not assume that removing names makes a small-team record anonymous. Follow the organisation's retention arrangements and get advice where they do not cover the exercise, rather than keeping every response indefinitely.

Sources and verification

  • NCSC: the hidden risks of shadow AI, published 7 September 2026 and checked 11 September 2026 for its definition and communication advice. Its cited survey figures are not used here.
  • ICO: monitoring workers, checked 11 September 2026 for purpose, transparency and proportionate collection.
  • ICO: collecting and keeping employment records, checked 11 September 2026 for consent and retention context; the guidance carries an under-review notice.
  • Acas: consulting employees, checked 11 September 2026 for consultation methods and scope.
  • The parent was read in the supplied website source; its public route could not be retrieved. No staff survey was conducted for this article.
Twokq Tech

This article is practical guidance. Apply it in proportion to your tools, evidence, risks, and responsibilities.