Shadow AI discovery

Find the AI nobody registered.
First findings inside 24 hours.

Five discovery layers across agents, identities, email, endpoints and network - three of which connect with a single administrator consent and no software deployed. Read-only, no proxy, no standing write credentials.

Shadow AI is not one problem. An employee pasting a customer list into ChatGPT and an agent reconciling invoices under a service principal are both ungoverned AI, and no single sensor sees both. A browser extension cannot observe an agent that never opens a browser. An inventory of agents cannot see someone's personal ChatGPT account.

Five discovery layers

Each answers a question the others cannot. You do not need all five on day one - you need the ones that match where your AI actually is.

The five discovery layers Govern360 reads, what each one finds, and what it takes to connect. Three of the five need only an administrator consent.
LayerWhat it findsTo connect
Agents & APIPlatform management APIs Every agent in Copilot Studio and Microsoft 365 Agent Builder, across every environment, including drafts. Their foundation model, connectors, knowledge sources, tool operations, channels, autonomy tier and machine identity. One admin consentRead-only. No endpoint agent, no proxy.
SaaS & identity Entra / Microsoft 365 Personal OAuth grants connecting third-party AI applications to work accounts, service principals acting without a human, and enterprise application registrations nobody reviewed. One admin consentThe channel most shadow AI actually arrives through.
Email & workflow Microsoft Graph AI vendor traffic visible in mail metadata - sign-up confirmations, invoices, seat notices. Vendor and date only; message content is never read. Scoped consentDeliberately conservative. Metadata, not mail.
Browser & endpoint Managed browser extension AI sites reached from managed devices, what is being pasted into them, and enforcement at the point of use - block or redact before the prompt is sent. RMM or Intune pushThe only layer that sees the person at the keyboard.
Network SASE / proxy logs AI destinations reached from anywhere on the network, including tools nobody catalogued and devices no extension runs on. Adapters for Zscaler, Netskope, Cisco Umbrella and Cloudflare Gateway. API credentialsUses logs you already generate. Nothing new deployed.
How the layers combine

Five sensors. One graph. Findings no single layer can produce.

Each layer answers a question the others cannot. The value is not in any one of them - it is that the estate becomes a single graph, where a path can be traced from a source of untrusted content to an agent that can act on it.

SIGNAL LAYERS ONE ESTATE GRAPH Agents & API SaaS & identity Email & workflow Browser & endpoint Network Agents, identities, connectors, data paths ownership - purpose - autonomy tool reach - machine identity model supply chain Exposure paths computed across the whole estate, not agent by agent Findings with evidence

Three of the five connect on an administrator consent alone. Browser and network are available and are not required for the first assessment.

First findings inside 24 hours

Three of the five layers connect with an administrator consent and no software deployment, so the first real numbers arrive the same day.

Hour 0 One admin consent

A tenant administrator consents to a read-only application registration. Nothing is installed, no traffic is proxied, and no standing write credential is issued.

Hours 1 - 4 Agent and identity discovery runs

Every agent across every environment, with its model, connectors, knowledge sources, tool operations and machine identity. In parallel, OAuth grants and service principals connecting AI applications to work accounts.

Hours 4 - 12 Exposure analysis

Ownership gaps, autonomy tiers, duplicate and abandoned agents, tool reach, and the exposure paths described below. This is where the findings stop being a list and start being a work queue.

Hours 12 - 24 A reviewed report

Findings ranked by severity, each traceable to the specific configuration evidence behind it, with the surfaces we could not measure named rather than left blank.

After Browser and network, when you want them

The managed extension deploys through your existing RMM or Intune. The network layer reads SASE or proxy logs you already generate. Neither is required for the first report.

What one estate looked like

A mid-market organisation, read-only connection, no software deployed.

625agents discovered, none previously inventoried
94at the autonomy tiers that act on systems
274with no directory machine identity
0with a declared purpose

The finding a browser cannot produce

An agent becomes structurally dangerous when three capabilities meet: access to private data, exposure to content nobody vetted, and a way to send data out. None is dangerous alone. Together they are an exfiltration path that prompt filtering does not close, because the attack vector is language itself.

One agent held all three. It reads incoming mail and is published on a programmatic channel, so anyone who can reach it can put content in front of it. It reaches the user's own mail and files through an MCP tool. It can send mail. Highest autonomy tier, and nobody recorded as accountable for it.
And the estate had a chokepoint. 398 of the 625 agents take in content nobody vetted. Only 3 can send anything outside the tenant. That is good news: most of the exposure closes by governing three agents rather than four hundred.
The path also completes between agents. 48 agents ingest untrusted content and write to Dataverse. One reads Dataverse and can send externally. Neither end fails a check that looks at agents individually - the exposure lives in the connection between them. Published analysis of this pattern evaluates one agent at a time and does not see it.

How we report it

Evidence, not assertion

Every finding names the configuration behind it - the specific connector operation, the channel, the autonomy tier, the identity. A finding you cannot check is an alert, not a finding. Our own detector once flagged an agent called Bank Reconciliation Assistant as critical; the evidence named a write operation where a read was required, and it was corrected before it left the building.

Absence is stated, not filled in

Where a layer is not connected, the affected surface says not measured and gives the reason. It never shows an empty result as a clean one. A governance tool that overstates its coverage trains people to ignore it.

We decide and compile; your planes enforce

Govern360 compiles policy into native configuration for Purview, Intune, SASE and AI gateways you already operate. It does not proxy your traffic, hold standing write credentials, or change anything without a human review step.

Figures are from a connected tenant, used with permission and anonymised. Your estate will differ. Timings assume an administrator is available to consent; the browser and network layers depend on your own deployment and log-retention arrangements.

Executive white paper · 2026

AI Exposure Management: the operating model for governed enterprise AI

Discover every AI agent. Identify ownership. Map identities, tools, data, actions, spend and exposure paths. Prove governance with evidence.

Written for CISOs, CIOs, CFOs and security, IT, risk and finance leaders. No form, no email required.

See your own number.

Book a 30-min demo