AI · AI GOVERNANCE

Your staff are already using AI tools nobody approved. Find out which ones, and the guardrails to put on them.

A fixed-fee review that finds the AI tools, apps, and connectors plugged into your Microsoft 365, ranks each by risk and by how much it is used, and hands you a plan to govern the AI nobody approved.

Fixed priceRisk register you keepRead-onlyGoverned

The deliverable

Shadow AI Risk Register, on your desk

A representative deliverable. Yours is built on your own environment, with names and figures redacted here.

This is for you if

Built for the Owner, IT Director, or Security Lead.

  • Staff are pasting company data into public AI tools with no guardrails.
  • You have no list of the AI tools and connectors plugged into your Microsoft 365.
  • You cannot show an auditor or a client where company data goes once staff paste it into an AI tool.

What you receive

Shadow AI Risk Register

Every discovered AI app, agent, and connector, ranked by risk and usage with a recommended action.

Governance plan

Which tools to allow, watch, or block, and the rules that enforce it.

Executive readout

An executive summary of the AI footprint and the risk it carries.

Typical timeline

1 week

Included

  • Discovery of the AI tools, apps, and connectors in use
  • Risk and usage ranking
  • An allow, watch, or block call on each tool
  • Governance plan and executive readout

Assumptions

  • No tool is blocked or switched off during the review
  • No review of what individual employees typed into an AI tool

Not included

  • Policy rollout and tool blocking (scoped separately)
  • Legal or HR policy authoring

Scoped separately here: Fix & improve.

Required access

  • Read-only access to the reports showing which apps and AI tools staff have connected, or exports of them
  • A 30-minute kickoff with security or IT

Engagement complete when

The engagement is complete when the Shadow AI risk register, governance plan, and executive readout are delivered and walked through.

Get an allow, watch, or block call on each AI tool the review finds.

One fixed fee, agreed in writing before any access is granted. The timeline above is the whole engagement, and what you keep is documentation your team can act on. One senior engineer scopes and delivers it.

The fee depends on what is actually in your environment rather than your headcount. The scope-fit check tells you where you land →