Said It Here

How to decide who gets access to workplace AI tools

Organizations are struggling to figure out how to license AI tools fairly while controlling costs across different departments. Without a clear rollout strategy, companies face security risks from employees plugging sensitive information into public models and unmonitored shadow IT connections spreading across development teams.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Having department heads decide access and pay from their own budgets instead of IT's
  2. 2
    Requiring users to demonstrate a specific use case or proof of need
  3. 3
    Routing Azure subscription charges directly through department credit cards
  4. 4
    Writing up employees who violate policy
  5. 5
    Using HasMCP to build MCP servers from OpenAPI specs with different privileges
  6. 6
    Enforcing basic DevOps and SRE discipline to prevent direct changes

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin2 people · September 2026

I’m interested in hearing from you guys about how you’re handling AI adoption across your organization.source ↗

If you’re not licensing everyone, how are you deciding who gets access?source ↗

How are you preventing employees from entering sensitive, confidential, customer, financial, or proprietary information into AI tools?source ↗

thefreeelancer · r/sysadmin

Devs here started connecting Claude and Cursor to MCP servers on their own and now I have to put some control around it before it spreads further.source ↗

Infamous-Web7174 · r/sysadmin

Where this came up

People with this problem also raised