USE CASES / BY RISK · SHADOW AI

Find the AI nobody registered.

Shadow AI is not one thing. It is a person consenting an AI app into your tenant, a Bedrock agent standing in an account nobody governs, a Now Assist topic a business admin switched on, and an MCP server a developer pasted into a client config. GovernorAI finds all four the same way — by reading records the systems you already run are already producing. Nothing is intercepted, and nothing changes how your agents run.

Read-only from supported sources No tap, no proxy, no packet inspection Named sources, stated posture Exportable AI-BOM
WHAT A CONNECTED SOURCE RECORDS WHAT NOTHING RECORDS An AI product nobody registered A principal with no owner An endpoint reached from CI A cadence that looks autonomous Traffic no connected source logs A model run wholly on a laptop Content inside a TLS tunnel Anything before the source was connected No tap, no proxy, no packet inspection anywhere in discovery. The blind spots of the systems you run are our blind spots too.

Discovery is a consumer of records the systems you already run are already producing. That is what makes it approvable in one signature — and it is also the limit: connecting no sources discovers nothing.

read-onlyconnectedavailableplanned

WHAT YOU ARE ACTUALLY LOOKING FOR

Four shapes, and only one of them is a person and a chatbot.

The version of shadow AI everyone pictures — an employee pasting a contract into a consumer assistant — is the least consequential of the four, because it does not act. The other three run on your infrastructure, hold your credentials, and can reach a system of record.

PEOPLE AND APPS

Consent and egress

An OAuth grant to a new AI app lands in Okta System Log, Microsoft Entra ID directory audit or the Google Workspace admin Reports API — usually before any proxy sees the traffic. Web egress to a known AI destination comes from the Zscaler, Netskope or Palo Alto logs you already export. A local model CLI on a laptop shows up as CrowdStrike Falcon process, DNS-request and outbound-connection telemetry.

identity · secure egress · endpoint
CLOUD AI PLATFORMS

Resources nobody registered

Agents enumerated across AWS Bedrock regions and resolved to their detail records and action groups. Azure Cognitive Services and AI Services accounts filtered to AI kinds, plus AI Foundry agents where the role permits enumeration. Google Vertex AI endpoints and reasoning engines per configured region. Databricks model-serving and foundation-model endpoints, de-duplicated so one physical endpoint is never counted twice.

control-plane list calls
ENTERPRISE SAAS

Agents a business admin switched on

Salesforce active Einstein Bot versions and AI-bearing Flow definitions over the REST query API. ServiceNow Virtual Agent topics, NLU models, Predictive Intelligence solutions and Flow Designer flows over the Table API. Microsoft Copilot Studio bots and Copilot-named application registrations over Graph, alongside M365 Copilot usage reports for ongoing per-user activity. Workday, SAP AI Core, Atlassian, Slack, Zendesk, HubSpot and n8n each connect against their own platform API.

read through the platform's own API
MCP AND FRAMEWORKS

Servers and runtimes a developer added

A catalog of MCP servers drawn from the official registry, from GitHub discovery and from a manifest repository you control — each scored on provenance, supply chain and declared capability before it is approved or blocked. LangChain, LangGraph, CrewAI and n8n framework runtimes group many agents under one process; they are registered by an operator or heartbeat themselves in, never found by scanning.

catalog · registered runtimes
Stated precisely Read-only discovery from supported sources, and nothing inferred about the ones you do not connect.

Every source is either something your forwarder posts to an ingest endpoint, something GovernorAI polls on a schedule, or a list call against a cloud control plane. There is no agent to install in a request path and no configuration change to the systems being inventoried. The only outbound write anywhere in this path is the OAuth token exchange that authenticates the read.

WHAT IT READS

Named sources, and a posture per source.

Each source is a shipped adapter with a real parsing contract. Each carries a posture derived from live wiring rather than a marketing list — so the surface cannot claim a source the backend cannot actually ingest. The per-vendor parsing contracts are set out on the platform page; this is the short list.

SIEM & log

  • Splunk
  • Microsoft Sentinel
  • Datadog
  • Generic SIEM webhook
  • Plain log lines

HTTP Event Collector including the batched newline-delimited stream, Azure Monitor / Log Analytics common-schema columns, and the Datadog logs intake with ddtags decomposed into user, host and env dimensions.

Secure egress & endpoint

  • Zscaler
  • Netskope
  • Palo Alto Networks
  • CrowdStrike

Internet Access web logs by way of Cloud NSS; CASB, SWG and web-transaction events; PAN-OS TRAFFIC and URL logs from Strata Logging Service. Threat and WildFire logs are deliberately out of scope — that is malware signal, not AI-usage signal.

Identity

  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • Microsoft 365 Copilot

System Log OAuth grants and application sign-ins, directory audit events, admin Reports token grants on a scheduled poll, and Graph Copilot usage reports for the ongoing activity a one-time consent event does not cover.

LLM gateways

  • LiteLLM
  • Portkey

The gateway's own per-request logs, ingested as an AI-usage feed: which models and providers each user and key actually called. Both are coexistence feeds — GovernorAI reads the gateway's telemetry rather than becoming the gateway.

Cloud AI platforms

  • AWS Bedrock
  • Microsoft Azure
  • Google Vertex AI
  • Databricks

Enumerated with list and get calls against the control plane, per configured region, and resolved to detail records where the role permits it.

Enterprise SaaS

  • Salesforce
  • ServiceNow
  • Microsoft 365
  • Workday
  • SAP AI Core
  • Atlassian
  • Slack
  • Zendesk
  • HubSpot
  • n8n

Each a connector against the platform's own API, with required credentials and supported auth types stated per platform. Only Salesforce and ServiceNow support a single connection carrying both discovery and governed execution; the rest are discovery-only.

MCP & frameworks

  • Official MCP registry
  • GitHub discovery
  • Your manifest repo
  • LangChain
  • LangGraph
  • CrewAI
  • n8n

Catalog entries move through discovered, validated, assessed and then approved, blocked or quarantined. Framework runtimes are registered through onboarding or by the runtime itself.

connected An enabled feed exists

And it reports its own health: healthy, stale or not configured. A feed that is enabled but has never reported is stale, because silence is not health.

available Shipped, not yet wired

The adapter is registered and the catalog will offer it. Nothing about that source is being read until you connect it.

planned Nothing ships

Printed rather than omitted, so the coverage grid shows a genuine gap instead of a blank cell.

Per-vendor envelopes, auth types and parsing contracts: Discovery & Shadow AI.

HOW A ROW EARNS ITS LABEL

A finding carries the reason that produced it.

Three destination buckets and one strictly separate behavioural bucket. Each finding stores a machine-readable reason code, a human-readable detail, every source channel that observed the subject, first and last seen times, and sample event identifiers you can pivot into.

Shadow AI classifications, their reason codes and what each means
ClassificationReason codeWhat it means
knownregistered_in_model_registryThe AI product the subject reached is registered in your model registry. A match against your own inventory, not a vendor allow-list.
likely_shadowai_product_fingerprint_no_governanceThe destination matched a known AI provider, host-boundary-aware, and no governance coverage was found for it. This is the shadow-AI row.
unknownunknown_endpointAI-tagged signal whose destination matched no known AI product. It needs human triage; it is not asserted to be shadow AI.
unknownunmanaged_principalThe directory loaded and this person was not in it. It means "not present in the governed inventory" — deliberately not a claim that the human is unknown to the company.
suspected_autonomous_loopcadenceA subject's event rhythm is regular enough to be machine-driven. Computed from observed timestamps only, never from prompt or model content, and carried on its own row.

Fail-closed by design: when the registry that answers "is this already governed?" cannot be read, the event is not classified at all. A shadow finding is never produced on an unanswered question.

Honesty note — the rhythm bucket is circumstantial

A regular cadence is consistent with an autonomous loop, and equally consistent with a nightly backup, a cron export or a health check. It is reported as suspected, on timing evidence alone, at a deliberately low confidence, and it is refused as the basis for registering an agent, attaching a policy or opening an approval. Below the minimum sample count nothing is emitted at all. Inside a connected SaaS tenant, deciding which automations count as AI is partly a keyword judgement over names and descriptions, tuned broad so an operator can dismiss what does not belong rather than never see it — the n8n connector deliberately lists every workflow. The risk level attached to a discovered SaaS agent is inferred from what that platform's objects typically reach, not measured from that tenant's grants; Slack is the one connector that reads the app's real OAuth scopes.

THE HONEST PART

Two lists. The one on the right is the reason this page is not a coverage claim.

Every category of shadow AI GovernorAI can see arrives because a system you already run wrote it down. That is the whole design, and it is also the whole limit — so both halves are printed together rather than one being left for the deployment call.

Visible · a connected source recorded it

What a system you already run hands over

  • An OAuth consent to a new AI app, from Okta, Entra ID or Google Workspace.
  • A web egress record to a fingerprinted AI destination, from Zscaler, Netskope or Palo Alto.
  • A process, DNS request or outbound connection on a managed endpoint, from CrowdStrike Falcon.
  • A gateway request log naming the provider, model, key and user, from LiteLLM or Portkey.
  • A cloud control-plane resource — a Bedrock agent, an Azure AI account, a Vertex endpoint, a Databricks serving endpoint.
  • A SaaS object — an Einstein Bot version, a Virtual Agent topic, a Copilot Studio bot.
Invisible · nothing recorded it

What no connected source writes down

  • A model call over a path none of your connected sources logs. There is no tap and no proxy here to catch what the log did not.
  • An unmanaged device, or one where the endpoint agent is not deployed. The endpoint feed's coverage is our coverage.
  • A SaaS or cloud tenant you have not connected. Nothing is inferred about it — it is a gap in the coverage grid, not an empty cell.
  • An MCP server running inside your estate. The catalog is a registry of publicly published servers; it never connects to one, and its behavioural dimension is not assessed.
  • A framework runtime nobody registered. No repository and no host is scanned to find one.
  • Prompt and completion content. Discovery reads envelopes, destinations, principals and timestamps — the cadence signal is computed from timestamps alone.

Connect one source and you see what that source sees. Connect nothing and GovernorAI discovers nothing.

Honesty note — this is not a network product

There is no tap, no proxy and no packet inspection anywhere in discovery. Every source is a log, an audit record or a control-plane list call that a system you already run hands over, which means the blind spots of those systems are our blind spots too: an agent calling a model over a path no connected source records is invisible to GovernorAI, and connecting no sources discovers nothing at all. Where you run a network or traffic-level security product — a secure web gateway, a CASB, an EDR — this sits alongside it and consumes its output rather than competing with it for raw traffic discovery. A finding is a worklist item, never an action: the discovery path itself never blocks, disables or reconfigures anything, and holding a discovered subject is a separate action on a separate permission that the state machine refuses outright on a finding resting only on rhythm.

THE OUTPUT

An AI-BOM, and a map of your own gaps.

The inventory exports as JSON or PDF and is fingerprinted with a content hash over the export, so a post-hoc edit is detectable. Three sections ship empty on purpose, with a written explanation in the file instead of a plausible guess.

ai-bom export · shape
// GET /api/v1/aibom/export?format=json
{
  "agents":       [ /* id, name, namespace, environment, models, policies */ ],
  "models":       [ /* registry entry, approved_by provenance */ ],
  "guardrails":   [ /* policies covering at least one agent */ ],
  "frameworks":   [ "langchain", "langgraph", "crewai", "n8n" ],
  "owners":       [],
  "tools_mcp":    [],
  "data_sources": [],
  "notes": [
    "Ownership is honest-empty: GovernorAI records agent registrant"
    " and model approver PROVENANCE, not a designated owner.",
    "Tools/MCP inventory is honest-empty: no per-tenant"
    " agent-to-tool binding is recorded today."
  ],
  "content_hash": "sha256:…"
}
Honesty note — the empty sections are empty on purpose

There is no per-tenant agent-to-tool, agent-to-MCP or agent-to-data-source binding recorded today, so those inventories are honest-empty rather than populated with a guess. Ownership is empty because GovernorAI knows who registered an agent and who approved a model — that is provenance, and a registrant is not an owner. Policy coverage is read from a projection that can lag live assignments, so the export carries an as-of timestamp; an agent missing from that projection is reported as coverage-unknown, which is a different thing from ungoverned.

Why this is where adoption starts Nothing on this page requires a policy, an SDK in an agent, or an enforcement decision.

You can connect one source, mint a per-source credential that is revocable on its own, run a test ingest that exercises the real adapter and persists nothing, export the AI-BOM, and stop there. Promoting a discovered model into the registry lands it as pending review — governed, but not yet approved. Registering a discovered agent, attaching a policy to it, or holding it are separate governance actions you take deliberately, on separate permissions.

Continue