Shadow AI discovery
Find the AI nobody registered.
First findings inside 24 hours.
Five discovery layers across agents, identities, email, endpoints and network - three of which connect with a single administrator consent and no software deployed. Read-only, no proxy, no standing write credentials.
Shadow AI is not one problem. An employee pasting a customer list into ChatGPT and an agent reconciling invoices under a service principal are both ungoverned AI, and no single sensor sees both. A browser extension cannot observe an agent that never opens a browser. An inventory of agents cannot see someone's personal ChatGPT account.
Five discovery layers
Each answers a question the others cannot. You do not need all five on day one - you need the ones that match where your AI actually is.
| Layer | What it finds | To connect |
|---|---|---|
| Agents & APIPlatform management APIs | Every agent in Copilot Studio and Microsoft 365 Agent Builder, across every environment, including drafts. Their foundation model, connectors, knowledge sources, tool operations, channels, autonomy tier and machine identity. | One admin consentRead-only. No endpoint agent, no proxy. |
| SaaS & identity Entra / Microsoft 365 | Personal OAuth grants connecting third-party AI applications to work accounts, service principals acting without a human, and enterprise application registrations nobody reviewed. | One admin consentThe channel most shadow AI actually arrives through. |
| Email & workflow Microsoft Graph | AI vendor traffic visible in mail metadata - sign-up confirmations, invoices, seat notices. Vendor and date only; message content is never read. | Scoped consentDeliberately conservative. Metadata, not mail. |
| Browser & endpoint Managed browser extension | AI sites reached from managed devices, what is being pasted into them, and enforcement at the point of use - block or redact before the prompt is sent. | RMM or Intune pushThe only layer that sees the person at the keyboard. |
| Network SASE / proxy logs | AI destinations reached from anywhere on the network, including tools nobody catalogued and devices no extension runs on. Adapters for Zscaler, Netskope, Cisco Umbrella and Cloudflare Gateway. | API credentialsUses logs you already generate. Nothing new deployed. |
Five sensors. One graph. Findings no single layer can produce.
Each layer answers a question the others cannot. The value is not in any one of them - it is that the estate becomes a single graph, where a path can be traced from a source of untrusted content to an agent that can act on it.
Three of the five connect on an administrator consent alone. Browser and network are available and are not required for the first assessment.
First findings inside 24 hours
Three of the five layers connect with an administrator consent and no software deployment, so the first real numbers arrive the same day.
A tenant administrator consents to a read-only application registration. Nothing is installed, no traffic is proxied, and no standing write credential is issued.
Every agent across every environment, with its model, connectors, knowledge sources, tool operations and machine identity. In parallel, OAuth grants and service principals connecting AI applications to work accounts.
Ownership gaps, autonomy tiers, duplicate and abandoned agents, tool reach, and the exposure paths described below. This is where the findings stop being a list and start being a work queue.
Findings ranked by severity, each traceable to the specific configuration evidence behind it, with the surfaces we could not measure named rather than left blank.
The managed extension deploys through your existing RMM or Intune. The network layer reads SASE or proxy logs you already generate. Neither is required for the first report.
What one estate looked like
A mid-market organisation, read-only connection, no software deployed.
The finding a browser cannot produce
An agent becomes structurally dangerous when three capabilities meet: access to private data, exposure to content nobody vetted, and a way to send data out. None is dangerous alone. Together they are an exfiltration path that prompt filtering does not close, because the attack vector is language itself.
How we report it
Evidence, not assertion
Every finding names the configuration behind it - the specific connector operation, the channel, the autonomy tier, the identity. A finding you cannot check is an alert, not a finding. Our own detector once flagged an agent called Bank Reconciliation Assistant as critical; the evidence named a write operation where a read was required, and it was corrected before it left the building.
Absence is stated, not filled in
Where a layer is not connected, the affected surface says not measured and gives the reason. It never shows an empty result as a clean one. A governance tool that overstates its coverage trains people to ignore it.
We decide and compile; your planes enforce
Govern360 compiles policy into native configuration for Purview, Intune, SASE and AI gateways you already operate. It does not proxy your traffic, hold standing write credentials, or change anything without a human review step.
Figures are from a connected tenant, used with permission and anonymised. Your estate will differ. Timings assume an administrator is available to consent; the browser and network layers depend on your own deployment and log-retention arrangements.
AI Exposure Management: the operating model for governed enterprise AI
Discover every AI agent. Identify ownership. Map identities, tools, data, actions, spend and exposure paths. Prove governance with evidence.
Written for CISOs, CIOs, CFOs and security, IT, risk and finance leaders. No form, no email required.