USE CASES / BY RISK · SHADOW AI

Find the AI nobody registered.

Shadow AI is not one thing. It is a person consenting an AI app into your tenant, a Bedrock agent standing in an account nobody governs, a Now Assist topic a business admin switched on, and an MCP server a developer pasted into a client config. GovernorAI finds all four the same way — by reading records the systems you already run are already producing. Nothing is intercepted, and nothing changes how your agents run.

Read-only from supported sources No tap, no proxy, no packet inspection Named sources, stated posture Exportable AI-BOM
WHAT A CONNECTED SOURCE RECORDS WHAT NOTHING RECORDS An AI product nobody registered A principal with no owner An endpoint reached from CI A cadence that looks autonomous Traffic no connected source logs A model run wholly on a laptop Content inside a TLS tunnel Anything before the source was connected No tap, no proxy, no packet inspection anywhere in discovery. The blind spots of the systems you run are our blind spots too.

Discovery is a consumer of records the systems you already run are already producing. That is what makes it approvable in one signature — and it is also the limit: connecting no sources discovers nothing.

read-onlyconnectedavailableplanned

WHAT YOU ARE ACTUALLY LOOKING FOR

Four shapes, and only one of them is a person and a chatbot.

The version of shadow AI everyone pictures — an employee pasting a contract into a consumer assistant — is the least consequential of the four, because it does not act. The other three run on your infrastructure, hold your credentials, and can reach a system of record.

PEOPLE AND APPS

Consent and egress

An OAuth grant to a new AI app lands in Okta System Log, Microsoft Entra ID directory audit or the Google Workspace admin Reports API — usually before any proxy sees the traffic. Web egress to a known AI destination comes from the Zscaler, Netskope or Palo Alto logs you already export. A local model CLI on a laptop shows up as CrowdStrike Falcon process, DNS-request and outbound-connection telemetry.

identity · secure egress · endpoint
CLOUD AI PLATFORMS

Resources nobody registered

Agents enumerated across AWS Bedrock regions and resolved to their detail records and action groups. Azure Cognitive Services and AI Services accounts filtered to AI kinds, plus AI Foundry agents where the role permits enumeration. Google Vertex AI endpoints and reasoning engines per configured region. Databricks model-serving and foundation-model endpoints, de-duplicated so one physical endpoint is never counted twice.

control-plane list calls
ENTERPRISE SAAS

Agents a business admin switched on

Salesforce active Einstein Bot versions and AI-bearing Flow definitions over the REST query API. ServiceNow Virtual Agent topics, NLU models, Predictive Intelligence solutions and Flow Designer flows over the Table API. Microsoft Copilot Studio bots and Copilot-named application registrations over Graph, alongside M365 Copilot usage reports for ongoing per-user activity. Workday, SAP AI Core, Atlassian, Slack, Zendesk, HubSpot and n8n each connect against their own platform API.

read through the platform's own API
MCP AND FRAMEWORKS

Servers and runtimes a developer added

A catalog of MCP servers drawn from the official registry, from GitHub discovery and from a manifest repository you control — each scored on provenance, supply chain and declared capability before it is approved or blocked. LangChain, LangGraph, CrewAI and n8n framework runtimes group many agents under one process; they are registered by an operator or heartbeat themselves in, never found by scanning.

catalog · registered runtimes
Stated precisely Read-only discovery from supported sources, and nothing inferred about the ones you do not connect.

Every source is either something your forwarder posts to an ingest endpoint, something GovernorAI polls on a schedule, or a list call against a cloud control plane. There is no agent to install in a request path and no configuration change to the systems being inventoried. The only outbound write anywhere in this path is the OAuth token exchange that authenticates the read.

WHAT IT READS

Named sources, and a posture per source.

Each source is a shipped adapter with a real parsing contract. Each carries a posture derived from live wiring rather than a marketing list — so the surface cannot claim a source the backend cannot actually ingest. The per-vendor parsing contracts are set out on the platform page; this is the short list.

SIEM & log

  • Splunk
  • Microsoft Sentinel
  • Datadog
  • Generic SIEM webhook
  • Plain log lines

HTTP Event Collector including the batched newline-delimited stream, Azure Monitor / Log Analytics common-schema columns, and the Datadog logs intake with ddtags decomposed into user, host and env dimensions.

Secure egress & endpoint

  • Zscaler
  • Netskope
  • Palo Alto Networks
  • CrowdStrike

Internet Access web logs by way of Cloud NSS; CASB, SWG and web-transaction events; PAN-OS TRAFFIC and URL logs from Strata Logging Service. Threat and WildFire logs are deliberately out of scope — that is malware signal, not AI-usage signal.

Identity

  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • Microsoft 365 Copilot

System Log OAuth grants and application sign-ins, directory audit events, admin Reports token grants on a scheduled poll, and Graph Copilot usage reports for the ongoing activity a one-time consent event does not cover.

LLM gateways

  • LiteLLM
  • Portkey

The gateway's own per-request logs, ingested as an AI-usage feed: which models and providers each user and key actually called. Both are coexistence feeds — GovernorAI reads the gateway's telemetry rather than becoming the gateway.

Cloud AI platforms

  • AWS Bedrock
  • Microsoft Azure
  • Google Vertex AI
  • Databricks

Enumerated with list and get calls against the control plane, per configured region, and resolved to detail records where the role permits it.

Enterprise SaaS

  • Salesforce
  • ServiceNow
  • Microsoft 365
  • Workday
  • SAP AI Core
  • Atlassian
  • Slack
  • Zendesk
  • HubSpot
  • n8n

Each a connector against the platform's own API, with required credentials and supported auth types stated per platform. Only Salesforce and ServiceNow support a single connection carrying both discovery and governed execution; the rest are discovery-only.

MCP & frameworks

  • Official MCP registry
  • GitHub discovery
  • Your manifest repo
  • LangChain
  • LangGraph
  • CrewAI
  • n8n

Catalog entries move through discovered, validated, assessed and then approved, blocked or quarantined. Framework runtimes are registered through onboarding or by the runtime itself.

connected An enabled feed exists

And it reports its own health: healthy, stale or not configured. A feed that is enabled but has never reported is stale, because silence is not health.

available Shipped, not yet wired

The adapter is registered and the catalog will offer it. Nothing about that source is being read until you connect it.

planned Nothing ships

Printed rather than omitted, so the coverage grid shows a genuine gap instead of a blank cell.

Per-vendor envelopes, auth types and parsing contracts: Discovery & Shadow AI.

HOW A ROW EARNS ITS LABEL

A finding carries the reason that produced it.

Three destination buckets and one strictly separate behavioural bucket. Each finding stores a machine-readable reason code, a human-readable detail, every source channel that observed the subject, first and last seen times, and sample event identifiers you can pivot into.

Shadow AI classifications, their reason codes and what each means
ClassificationReason codeWhat it means
knownregistered_in_model_registryThe AI product the subject reached is registered in your model registry. A match against your own inventory, not a vendor allow-list.
likely_shadowai_product_fingerprint_no_governanceThe destination matched a known AI provider, host-boundary-aware, and no governance coverage was found for it. This is the shadow-AI row.
unknownunknown_endpointAI-tagged signal whose destination matched no known AI product. It needs human triage; it is not asserted to be shadow AI.
unknownunmanaged_principalThe directory loaded and this person was not in it. It means "not present in the governed inventory" — deliberately not a claim that the human is unknown to the company.
suspected_autonomous_loopcadenceA subject's event rhythm is regular enough to be machine-driven. Computed from observed timestamps only, never from prompt or model content, and carried on its own row.

Fail-closed by design: when the registry that answers "is this already governed?" cannot be read, the event is not classified at all. A shadow finding is never produced on an unanswered question.

THE HONEST PART

Two lists. The one on the right is the reason this page is not a coverage claim.

Every category of shadow AI GovernorAI can see arrives because a system you already run wrote it down. That is the whole design, and it is also the whole limit — so both halves are printed together rather than one being left for the deployment call.

Visible · a connected source recorded it

What a system you already run hands over

  • An OAuth consent to a new AI app, from Okta, Entra ID or Google Workspace.
  • A web egress record to a fingerprinted AI destination, from Zscaler, Netskope or Palo Alto.
  • A process, DNS request or outbound connection on a managed endpoint, from CrowdStrike Falcon.
  • A gateway request log naming the provider, model, key and user, from LiteLLM or Portkey.
  • A cloud control-plane resource — a Bedrock agent, an Azure AI account, a Vertex endpoint, a Databricks serving endpoint.
  • A SaaS object — an Einstein Bot version, a Virtual Agent topic, a Copilot Studio bot.
Invisible · nothing recorded it

What no connected source writes down

  • A model call over a path none of your connected sources logs. There is no tap and no proxy here to catch what the log did not.
  • An unmanaged device, or one where the endpoint agent is not deployed. The endpoint feed's coverage is our coverage.
  • A SaaS or cloud tenant you have not connected. Nothing is inferred about it — it is a gap in the coverage grid, not an empty cell.
  • An MCP server running inside your estate. The catalog is a registry of publicly published servers; it never connects to one, and its behavioural dimension is not assessed.
  • A framework runtime nobody registered. No repository and no host is scanned to find one.
  • Prompt and completion content. Discovery reads envelopes, destinations, principals and timestamps — the cadence signal is computed from timestamps alone.

Connect one source and you see what that source sees. Connect nothing and GovernorAI discovers nothing.

THE OUTPUT

An AI-BOM, and a map of your own gaps.

The inventory exports as JSON or PDF and is fingerprinted with a content hash over the export, so a post-hoc edit is detectable. Three sections ship empty on purpose, with a written explanation in the file instead of a plausible guess.

ai-bom export · shape
// GET /api/v1/aibom/export?format=json
{
  "agents":       [ /* id, name, namespace, environment, models, policies */ ],
  "models":       [ /* registry entry, approved_by provenance */ ],
  "guardrails":   [ /* policies covering at least one agent */ ],
  "frameworks":   [ "langchain", "langgraph", "crewai", "n8n" ],
  "owners":       [],
  "tools_mcp":    [],
  "data_sources": [],
  "notes": [
    "Ownership is honest-empty: GovernorAI records agent registrant"
    " and model approver PROVENANCE, not a designated owner.",
    "Tools/MCP inventory is honest-empty: no per-tenant"
    " agent-to-tool binding is recorded today."
  ],
  "content_hash": "sha256:…"
}
Why this is where adoption starts Nothing on this page requires a policy, an SDK in an agent, or an enforcement decision.

You can connect one source, mint a per-source credential that is revocable on its own, run a test ingest that exercises the real adapter and persists nothing, export the AI-BOM, and stop there. Promoting a discovered model into the registry lands it as pending review — governed, but not yet approved. Registering a discovered agent, attaching a policy to it, or holding it are separate governance actions you take deliberately, on separate permissions.

SO THE NEXT ONE IS NOT SHADOW AI

Discovery finds what nobody registered. Assurance is how the next one avoids becoming that.

Finding unregistered AI is a recovery step, and it will always be needed. The gate is what stops the backlog growing: an agent that has not cleared a preregistered bar does not reach production in the first place.

Whether a domain can be measured is a property of how the environment is wired, so it is computed per deployment and the gap is named rather than scored.

See what each domain needs →

Continue