How to decide who gets access to workplace AI tools
Organizations are struggling to figure out how to license AI tools fairly while controlling costs across different departments. Without a clear rollout strategy, companies face security risks from employees plugging sensitive information into public models and unmonitored shadow IT connections spreading across development teams.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Having department heads decide access and pay from their own budgets instead of IT's
- 2Requiring users to demonstrate a specific use case or proof of need
- 3Routing Azure subscription charges directly through department credit cards
- 4Writing up employees who violate policy
- 5Using HasMCP to build MCP servers from OpenAPI specs with different privileges
- 6Enforcing basic DevOps and SRE discipline to prevent direct changes
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“I’m interested in hearing from you guys about how you’re handling AI adoption across your organization.”source ↗
“If you’re not licensing everyone, how are you deciding who gets access?”source ↗
“How are you preventing employees from entering sensitive, confidential, customer, financial, or proprietary information into AI tools?”source ↗
“Devs here started connecting Claude and Cursor to MCP servers on their own and now I have to put some control around it before it spreads further.”source ↗
Where this came up
People with this problem also raised
- 3How to secure and support internal AI apps built by non-technical employees
- 4How to use AI in grant writing without getting flagged
- 13Why am I being forced to use AI at work?
- 5How do you enable record updates in Agentforce and check credit costs?
- 8What to do when your boss uses AI to write everything
- 3Employees demanding IT changes based on AI chatbot instructions