Playbooks

The work, written out — not the pitch for the work.

Every guide here is executable with no Vincosha account, and each one says plainly what the manual path costs before it mentions us at all. A how-to whose fourth step is "buy our product" is a landing page wearing a tutorial's clothes, and you would stop reading — rightly.

how to use this set

Do them roughly in the order below. The most expensive mistake in this work is sequencing: teams routinely write the AI usage policy first, because it is the deliverable an executive asked for, and end up with a document that prohibits things nobody can detect and permits things nobody has inventoried.

Inventory first. Then the reviews that inventory makes possible. Then the policy, which can now say something enforceable. Then the measurement that tells you whether any of it worked.

Why these are shaped as procedures rather than advice

Most published material on AI governance stops at the level of principle — *maintain an inventory*, *review third-party components*, *apply least privilege*. All true, and none of it survives contact with the specific question of what to type on Monday morning. The gap between a principle and a procedure is where programmes stall.

So each guide names the owner, gives an honest effort range rather than a fabricated one, and ends every step with the artefact you are holding when it is done. If a step produces nothing you could show someone, it is not a step — it is a paragraph pretending to be one.

Each guide also carries a copy-pasteable artifact: an approval checklist, a policy skeleton, a field set, a worksheet. That is deliberate. It is the half of the page worth arriving for, and keeping it inside the guide that teaches it means one page serves both the person searching how to do the thing and the person searching for the template.

Sequence

  • Find out what you actually run

    Shadow AI discovery and an MCP server audit. Everything downstream is guesswork until this exists, and it is the step most often skipped because it produces bad news.

  • Make the reviews repeatable

    A skill review procedure and an injection blast-radius assessment. These turn 'somebody looked at it' into a decision anyone can reproduce and disagree with.

  • Write the policy the inventory can support

    An AI usage policy drafted after discovery says enforceable things. Drafted before, it says aspirational ones, and everybody learns to route around it.

  • Make it provable and measurable

    An AI-BOM for the auditor, incident procedure for the bad week, and spend attribution for the quarterly conversation about cost.

8 / 8 guides

Frequently asked

Do I need to buy anything to follow these?
No, and that is a design constraint rather than a marketing line. Every guide is written to be executable with the tools you already have, and each one carries a section stating what the manual path costs in time and where it breaks down at scale. If that section reads as an argument for doing it by hand in a ten-person company, that is because it is one.
Which guide should we start with?
Whichever inventory you are missing. In practice that is shadow AI discovery if you do not know which surfaces are in use, or the MCP server audit if you do. Both produce a list, and a list is the only thing that makes the later guides possible — a policy written without one is a wish.
How current is this?
Every guide carries the date its sources were last checked, and this set was compiled on 2026-07-25. The vendor-specific mechanics in this space move quickly, so where a control is changing we describe the mechanism rather than assert a current state, and we link the vendor documentation so you can verify rather than trust us.
Can we adapt the templates for our own company?
That is what they are for — 8 of the guides here end in a block written to be pasted into your own document and edited. They are deliberately generic on names and specific on structure, because the structure is the part that takes a week to get right and the names take ten minutes.

Reference these guides lean on

When the manual version stops scaling

Everything above works by hand, and keeps working until the fleet grows. Vincosha Assay runs the reviews these guides describe before an artifact reaches a laptop; Vincosha Registry makes the approved version provably the installed one; Vincosha Ledger answers the questions the incident and spend guides can only answer manually.