Shadow IT and Shadow AI Discovery
An inventory of the apps and AI tools your team already uses, including the ones nobody approved.
- Cadence
- Monthly
- Pricing
- Scoped to your environment after the assessment.
- Family
- Identity and access
The problem
Teams sign up for SaaS apps and AI tools with a work email and a credit card. Company data ends up in tools security never reviewed, and nobody has the list.
What you get
- An inventory of SaaS apps and AI tools in use, with owners
- Which tools hold company data, and what kind
- Risk notes for each unapproved tool
- A recommendation for each: approve, replace, or retire
How it works
Step 1: Connect read-only sources
Sign-in and app connection records from your identity provider, plus any other sources you choose.
Step 2: Agents build the inventory
Apps and AI tools matched to the people and teams using them.
Step 3: An expert reviews the risk
Each unapproved tool judged on the data it can reach.
Step 4: You approve any change
You decide what stays, and we draft the follow-up for your approval. Every approval is logged.
Access we need
- Read-only access to sign-in and app assignment data in your identity provider
- Read-only access to third-party app connections (OAuth grants) in Google Workspace or Microsoft 365
What we never do
- We never read the contents of email or files.
- We never block or remove a tool; that decision is yours.
The full access model is on the security and trust page.
Related services
- Identity Assurance
Access reviews that finish, every quarter.
- AI Governance
Rules and an inventory for the AI your team already uses.
Questions about Shadow IT and Shadow AI Discovery?
Tell us what you run and what you need, and we will reply with next steps.