Microsoft 365
One read-only Entra app: Copilot credits and consumption, Purview DLP, identity, device posture, M365 trust.
Platform · Integrations
Every source Govern360 reads, grouped by what is actually true of it today, and the small number of actions it can take. The roadmap items are named rather than left out, because a list that hides what is missing is a list you cannot check.
One read-only Entra app: Copilot credits and consumption, Purview DLP, identity, device posture, M365 trust.
Users, groups and enterprise app inventory.
Every agent built on Power Platform — Copilot Studio and M365 Agent Builder, all environments.
Dataverse AI events and Copilot credit consumption.
The content surfaces behind Copilot prompts.
Azure OpenAI deployment usage and cost.
Pipelines and work-item activity.
Cost, security posture and asset inventory.
Bedrock model usage via AWS.
API usage and cost, from an admin key.
Organisation cost report, from an admin key.
Usage in credits by model, person and tenant; invoices counted in AI spend; Hatz agents, apps and workflows; admin events such as MCP servers switched on.
AI spend as Ramp reports it — by provider, model, API key, person and department — set beside what the platform counts.
The AI your people buy on expense reports, by tool, person and department; personal plans bought where a company plan exists; tools the AI inventory does not list.
Which machines running AI carry a Falcon sensor, which AI apps Falcon sees on hosts, an audited Contain action, and the block list as Falcon indicators.
Which machines running AI carry a SentinelOne agent, which AI apps it sees on hosts, an audited Disconnect from network action, and the block list as indicators.
Which machines running AI have a Tanium client checking in, which AI apps Tanium sees installed, and an audited Quarantine action.
Which machines running AI are segmented, learning or open, which talk to AI services, and an audited Isolate action.
Which machines running AI your NodeZero pentests reached, what they proved on them — CISA KEV, attack paths, weak credentials — and which were never tested.
Egress logs resolved to AI domains in real traffic.
Installed AI apps and bot users — where shadow AI announces itself.
Subscription cost, posture and inventory.
Which AI apps people reach through Entra Internet Access — who, how often, allowed or blocked.
Project cost, posture and inventory.
Vertex model usage via GCP.
Enterprise Antigravity bills through your Google Cloud project; connect Google Cloud to capture its cost.
Per-model cost, seats and public-code policy.
Per-member spend, usage and repository blocklists.
Agentforce agents, Einstein usage, and the data those agents reach.
AI Agent Studio agents, the tools they call and the workflows they run in.
Box AI agents and who uses Box AI, on which files.
Governance reviews and incidents as service requests, with their status read back.
Security ratings, grades and factor scores for the vendors in Vendor Risk.
Block IPs, domains and URLs — including AI services seen in your traffic — on PAN-OS, Panorama and Prisma Access, with proof the lists are pulled.
These are on the roadmap. They are listed so you can see the gaps before you buy rather than after. If one of them is the source that matters to you, say so and it moves up the order — but today the honest answer is no.
Identity, groups and app assignments.
Directory and app assignment data.
HR records — person, department, cost centre, manager.
ERP cost centres and finance hierarchy.
Finance cost-centre ownership.
Person to department to cost centre.
Map users and teams to finance cost centres.
Data warehouse retrieval and cost.
Lakehouse and model-serving activity.
Knowledge-base retrieval sources.
Workspace knowledge sources.
Atlassian Intelligence usage and project activity.
AI Companion summaries and meeting transcription.
Contract AI and agreement analysis.
Acrobat AI Assistant and Firefly usage.
Breeze AI agents and CRM data reach.
These are not connectors — nothing here authenticates to a vendor API. Inspected in browser means the managed extension reads prompt text before it is sent and can block or redact it. Network rules only means the tool is in your inventory and the SASE runbook can block or coach it, but nothing reads what was typed.
The limit, stated. A native desktop application is network-only whatever the browser column says — an extension cannot see inside one. Any vendor showing you one undifferentiated wall of logos is not telling you which half it can actually read.
Discovery and scoring are read-only, and Govern360 is never in the traffic path. Six actions exist, each opt-in per connector.
CrowdStrike Falcon. Isolates a host from the network through Falcon.
SentinelOne. The equivalent action through the SentinelOne agent.
Tanium, on a machine; and Power Platform, on an agent — written through the API, then read back and compared before the outcome is recorded.
Zero Networks. Segments a machine that talks to AI services.
Palo Alto PAN-OS, Panorama and Prisma Access, with proof the lists were pulled.
Jira Service Management. Reviews and incidents raised as requests, with status read back.
How each one is governed. Every action is started by a person, never by the platform; written to the audit chain with who did it and when; and runs on a credential you issue and can revoke at any time. Govern360 holds no blanket write access and never remediates on its own. Where a platform exposes a read path, the result is read back and reported as verified rather than assumed.
The full trust position · Runtime assurance · How discovery works · All answers
Thirty-four you can turn on: 21 are connected in a working estate today and 13 more are built and ready to connect. A further 16 are named on the roadmap and are not built yet. The roadmap items are listed by name rather than left out, so the gaps are visible instead of implied.
Not by default. Discovery and scoring are read-only. Five connectors carry an action you can switch on — Contain on CrowdStrike Falcon, Disconnect from network on SentinelOne, Quarantine on Tanium, Isolate on Zero Networks, and block lists pushed to Palo Alto — plus Quarantine on Power Platform agents. Each is started by a person, written to the audit chain with who and when, and runs on a credential you issue and can revoke.
Inspected in browser means the managed extension reads prompt text before it is sent and can block or redact it. Network rules only means the tool is in your inventory and the SASE runbook can block or coach it, but nothing reads what was typed. A native desktop application is network-only whatever the browser column says, because an extension cannot see inside one.
No, and coverage is published as a fraction from the first read. A source you have not connected reduces coverage and says so; it is never scored as if it were clean, and never as if it were failing.
Two different lists. The connectors are sources Govern360 authenticates to and reads. The AI surfaces are the tools it watches — nothing there authenticates to a vendor API.
Custom integrations are included wherever the platform exposes a read path. Where no read path exists, that is said rather than worked around.