Platform · Integrations

Thirty-four you can turn on. Sixteen we have not built yet.

Every source Govern360 reads, grouped by what is actually true of it today, and the small number of actions it can take. The roadmap items are named rather than left out, because a list that hides what is missing is a list you cannot check.

21Connectedlive in a working estate today
13Availablebuilt and ready to connect
16Coming soonnamed, and not built yet
Connected · 21

Live in a working estate today

Microsoft 365

One read-only Entra app: Copilot credits and consumption, Purview DLP, identity, device posture, M365 trust.

BillingActivityDiscoveryPolicyAdmin consent

Microsoft Entra ID

Users, groups and enterprise app inventory.

EnrichmentDiscoveryAdmin consent

Microsoft Power Platform agents

Every agent built on Power Platform — Copilot Studio and M365 Agent Builder, all environments.

DiscoveryAdmin sign-in

Microsoft Power Platform (consumption)

Dataverse AI events and Copilot credit consumption.

ActivityEntra app

SharePoint / OneDrive

The content surfaces behind Copilot prompts.

EnrichmentDiscoveryAdmin consent

Azure OpenAI

Azure OpenAI deployment usage and cost.

BillingActivityService principal

Azure DevOps

Pipelines and work-item activity.

EnrichmentOAuth

Amazon Web Services

Cost, security posture and asset inventory.

BillingAccess key

Amazon Bedrock

Bedrock model usage via AWS.

BillingAccess key

OpenAI (ChatGPT)

API usage and cost, from an admin key.

BillingAPI key

Anthropic (Claude)

Organisation cost report, from an admin key.

BillingAPI key

Hatz AI

Usage in credits by model, person and tenant; invoices counted in AI spend; Hatz agents, apps and workflows; admin events such as MCP servers switched on.

BillingAttributionDiscoveryAPI key

Ramp

AI spend as Ramp reports it — by provider, model, API key, person and department — set beside what the platform counts.

BillingAttributionAPI client

SAP Concur

The AI your people buy on expense reports, by tool, person and department; personal plans bought where a company plan exists; tools the AI inventory does not list.

BillingDiscoveryCompany app

CrowdStrike Falcon

Which machines running AI carry a Falcon sensor, which AI apps Falcon sees on hosts, an audited Contain action, and the block list as Falcon indicators.

PostureDiscoveryControlAPI client

SentinelOne

Which machines running AI carry a SentinelOne agent, which AI apps it sees on hosts, an audited Disconnect from network action, and the block list as indicators.

PostureDiscoveryControlAPI token

Tanium

Which machines running AI have a Tanium client checking in, which AI apps Tanium sees installed, and an audited Quarantine action.

PostureDiscoveryControlAPI token

Zero Networks

Which machines running AI are segmented, learning or open, which talk to AI services, and an audited Isolate action.

PostureDiscoveryControlAPI token

Horizon3.ai NodeZero

Which machines running AI your NodeZero pentests reached, what they proved on them — CISA KEV, attack paths, weak credentials — and which were never tested.

PostureFindingsAPI key

SASE / Network logs

Egress logs resolved to AI domains in real traffic.

DiscoveryAPI key

Slack

Installed AI apps and bot users — where shadow AI announces itself.

DiscoveryOne click
Available · 13

Built and ready to connect

Microsoft Azure

Subscription cost, posture and inventory.

BillingService principal

Microsoft Global Secure Access

Which AI apps people reach through Entra Internet Access — who, how often, allowed or blocked.

DiscoveryActivityMicrosoft app

Google Cloud

Project cost, posture and inventory.

BillingService account

Google Vertex AI

Vertex model usage via GCP.

BillingService account

Google Antigravity

Enterprise Antigravity bills through your Google Cloud project; connect Google Cloud to capture its cost.

BillingVia Google Cloud

GitHub Copilot

Per-model cost, seats and public-code policy.

BillingActivityPolicyPAT

Cursor

Per-member spend, usage and repository blocklists.

BillingAttributionAPI key

Salesforce

Agentforce agents, Einstein usage, and the data those agents reach.

DiscoveryEnrichmentOne click

ServiceNow

AI Agent Studio agents, the tools they call and the workflows they run in.

DiscoveryIntegration user

Box

Box AI agents and who uses Box AI, on which files.

DiscoveryActivityOne click

Jira Service Management

Governance reviews and incidents as service requests, with their status read back.

EnrichmentOne click

SecurityScorecard

Security ratings, grades and factor scores for the vendors in Vendor Risk.

EnrichmentAPI key

Palo Alto Networks

Block IPs, domains and URLs — including AI services seen in your traffic — on PAN-OS, Panorama and Prisma Access, with proof the lists are pulled.

ControlNo credentials
Coming soon · 16

Named, and not built yet

These are on the roadmap. They are listed so you can see the gaps before you buy rather than after. If one of them is the source that matters to you, say so and it moves up the order — but today the honest answer is no.

Okta

Identity, groups and app assignments.

EnrichmentOAuth

Google Workspace Admin

Directory and app assignment data.

EnrichmentOAuth

Workday

HR records — person, department, cost centre, manager.

EnrichmentOAuth

SAP

ERP cost centres and finance hierarchy.

EnrichmentOAuth

NetSuite

Finance cost-centre ownership.

EnrichmentOAuth

SCIM / HRIS mapping

Person to department to cost centre.

EnrichmentUpload / SCIM

Cost centre mapping (CSV)

Map users and teams to finance cost centres.

EnrichmentUpload

Snowflake

Data warehouse retrieval and cost.

EnrichmentBillingService account

Databricks

Lakehouse and model-serving activity.

EnrichmentBillingService account

Confluence

Knowledge-base retrieval sources.

EnrichmentOAuth

Notion

Workspace knowledge sources.

EnrichmentOAuth

Jira

Atlassian Intelligence usage and project activity.

EnrichmentOAuth

Zoom

AI Companion summaries and meeting transcription.

DiscoveryOAuth

DocuSign

Contract AI and agreement analysis.

EnrichmentOAuth

Adobe

Acrobat AI Assistant and Firefly usage.

DiscoveryOAuth

HubSpot

Breeze AI agents and CRM data reach.

DiscoveryEnrichmentOAuth
AI surfaces · 33

The AI tools the browser guard watches

These are not connectors — nothing here authenticates to a vendor API. Inspected in browser means the managed extension reads prompt text before it is sent and can block or redact it. Network rules only means the tool is in your inventory and the SASE runbook can block or coach it, but nothing reads what was typed.

Inspected in browser · 30

ChatGPTOpenAI PlatformClaudeAnthropic ConsoleGeminiGoogle AI StudioMicrosoft CopilotPerplexityGrammarlyGranolaNotion AIGammaOtter.aiFireflies.aiRead.aiPoeYou.comMistralDeepSeekHugging Face ChatGroqCharacter.AIJasperCopy.aiWritesonicQuillBotTomeBeautiful.aiSiderMerlin

Network rules only · 3

GitHub CopilotMidjourneyGrok

The limit, stated. A native desktop application is network-only whatever the browser column says — an extension cannot see inside one. Any vendor showing you one undifferentiated wall of logos is not telling you which half it can actually read.

Actions

What Govern360 can act on, named in full

Discovery and scoring are read-only, and Govern360 is never in the traffic path. Six actions exist, each opt-in per connector.

Contain

CrowdStrike Falcon. Isolates a host from the network through Falcon.

Control

Disconnect from network

SentinelOne. The equivalent action through the SentinelOne agent.

Control

Quarantine

Tanium, on a machine; and Power Platform, on an agent — written through the API, then read back and compared before the outcome is recorded.

Control

Isolate

Zero Networks. Segments a machine that talks to AI services.

Control

Block lists

Palo Alto PAN-OS, Panorama and Prisma Access, with proof the lists were pulled.

Control

Service requests

Jira Service Management. Reviews and incidents raised as requests, with status read back.

Enrichment

How each one is governed. Every action is started by a person, never by the platform; written to the audit chain with who did it and when; and runs on a credential you issue and can revoke at any time. Govern360 holds no blanket write access and never remediates on its own. Where a platform exposes a read path, the result is read back and reported as verified rather than assumed.

The full trust position · Runtime assurance · How discovery works · All answers

Questions

Integrations, answered

How many integrations does Govern360 actually have?

Thirty-four you can turn on: 21 are connected in a working estate today and 13 more are built and ready to connect. A further 16 are named on the roadmap and are not built yet. The roadmap items are listed by name rather than left out, so the gaps are visible instead of implied.

Does connecting a source give Govern360 write access?

Not by default. Discovery and scoring are read-only. Five connectors carry an action you can switch on — Contain on CrowdStrike Falcon, Disconnect from network on SentinelOne, Quarantine on Tanium, Isolate on Zero Networks, and block lists pushed to Palo Alto — plus Quarantine on Power Platform agents. Each is started by a person, written to the audit chain with who and when, and runs on a credential you issue and can revoke.

What is the difference between inspected in browser and network rules only?

Inspected in browser means the managed extension reads prompt text before it is sent and can block or redact it. Network rules only means the tool is in your inventory and the SASE runbook can block or coach it, but nothing reads what was typed. A native desktop application is network-only whatever the browser column says, because an extension cannot see inside one.

Do I need all of them connected to get a score?

No, and coverage is published as a fraction from the first read. A source you have not connected reduces coverage and says so; it is never scored as if it were clean, and never as if it were failing.

Are these connectors or AI tools?

Two different lists. The connectors are sources Govern360 authenticates to and reads. The AI surfaces are the tools it watches — nothing there authenticates to a vendor API.

Can you add a source that is not listed?

Custom integrations are included wherever the platform exposes a read path. Where no read path exists, that is said rather than worked around.