Why an AI seat audit matters
Small businesses often add AI tools one workflow at a time: one assistant for marketing, another for support, a browser extension, a note taker, a chatbot, and a few team seats. Without a seat audit, unused accounts keep renewing, departed staff keep access, shared logins hide accountability, and customer data may sit in tools nobody reviews.
Copy/paste AI tool seat audit card
| Field | What to capture | Review rule |
|---|---|---|
| Tool/workspace | Vendor, workspace, plan, billing owner, renewal date, payment owner, and support contact. | Verify from the admin or billing portal, not from memory. |
| Seat list | User name or role, email, department, seat type, last active date, and whether the person still needs access. | Flag unknown, inactive, duplicate, contractor, and former-employee access. |
| Usage evidence | Recent workflows used, prompts/templates relied on, customer-facing outputs, automations, or files created. | Keep seats only when use is current, valuable, and reviewable. |
| Data exposure | Customer notes, calls, transcripts, reviews, invoices, files, source docs, CRM data, uploads, or integrations visible to the seat. | Remove or restrict seats if private data access is broader than the user's role. |
| Shared access | Shared passwords, browser extensions, API keys, OAuth connections, team folders, automations, and webhooks. | Shared access needs owner review because it hides accountability and offboarding risk. |
| Decision | Keep, remove, downgrade, consolidate, train user, rotate credentials, or schedule renewal review. | Record owner, due date, proof source, and next billing check date. |
Seat cleanup snippets
Owner review note: We are auditing [tool] seats before [renewal/billing/staff-change]. Please confirm whether [person/role] still needs access, what workflow they use it for, and whether any customer data or automations are connected to their seat.
Team update: [Tool] access will be limited to [approved roles] after [date]. Do not use shared logins or paste customer/private data into unapproved seats. If you need access, request it through [owner/process] with the workflow and review rule.
Billing follow-up: Seats removed/downgraded: [list]. Proof saved: [admin screenshot/email/invoice]. Next billing check: [date]. Owner: [name]. If the charge does not change, escalate with proof.
AI review prompt
Act as a cautious small-business AI tool access reviewer. Use only the verified facts below. Do not invent tool usage, savings, renewal dates, user activity, customer-data exposure, security status, approval history, cancellation status, refund rights, or replacement workflows. Return: 1) missing seat-audit fields, 2) seats to keep, remove, downgrade, or review, 3) data/access risks, 4) billing follow-up checks, 5) team-update wording, and 6) STOP AUTOMATION items.
Verified facts:
- Tool/vendor/workspace:
- Plan/cost/renewal date:
- Billing owner/account owner:
- Seat list and last active dates:
- Workflows each seat uses:
- Customer/private data visible:
- Shared logins/API/OAuth/webhooks:
- Former staff/contractor access:
- Decision owner and due date:
- Proof source:
- Next billing check date:Fast QA before changing access
- Confirm the admin portal matches the billing invoice and renewal date.
- Check whether inactive users still own prompts, automations, files, integrations, or API keys.
- Separate "unused" from "critical but quiet" workflows before removing access.
- Save proof of seat removals, downgrades, credential rotations, and final billing checks.
Related free assets: AI Workflow Access Review Checklist, AI Tool Renewal Checklist, and AI Tool Cancellation and Access Shutoff Checklist.
Disclosure: Horizon Flow is Andrew Burton's digital product catalog. This worksheet is useful without purchase; product links are labeled and UTM-tagged.