Architecture & decision engagement

Find the shadow AI tools and agents your staff already use, from your own tenant.

Review the AI tools, agents and connected apps visible in the available Microsoft 365 records. The report lists usage, access, recommended actions and gaps in visibility. This read-only review ends with a findings meeting and a costed plan for the changes.

PricePrice fixed after a short scope call.

DeliveryThe proposal names the start date, the change windows and the completion date before anything is agreed.

What you receive · illustrative sample

An inventory your team can act on.

Illustrative read-only discovery record. Recommendations do not revoke or block access during the audit.

Discovered toolEvidence and reachRecommended decision
Sample reporting assistantOAuth grant; selected business dataReview with named owner
Sample document helperAvailable application inventoryConfirm purpose and licensing
Unattributed connectorConsent exists; owner unresolvedInvestigate before changing access

Meet the person responsible for delivery.

Alwatheq Zboun leads the agreed work. A sample shows the format; the statement of work defines your deliverable and acceptance checks.

Engagement context

When this engagement applies.

Shadow AI is in use across the business: tools staff signed up for with work accounts, agents running from laptops, and nobody holds the list.

Scope considerations

  • One Microsoft 365 tenant
  • Read-only throughout
  • Tenant evidence, plus any discovery export you can provide

The defined work

Engagement scope.

  1. 01

    AI apps, agents and connected tools visible in the available evidence are inventoried: app consents and their scopes, enterprise apps, the Teams app list, software Intune has seen, and the audit log.

  2. 02

    If the tenant already licenses Cloud App Discovery, the client exports a snapshot and it is folded in. If not, the report says what that would have added.

  3. 03

    Each tool is recorded with its users, the data it can reach, a risk rating, and an owner, or a flag where no owner can be found.

  4. 04

    Every entry gets a recommended allow, watch or block decision, with the reason, for the client to confirm.

  5. 05

    The readout walks the list and the correction plan. Each fix is costed, so the follow-on can be scoped from it.

Acceptance

Completion has an agreed standard.

Done when every tool found is on the list with an owner or a flag and a recommended decision, the readout is delivered, and access is removed.

  • Every in-scope discovered tool is in the inventory with its evidence source, users, reach and risk rating

  • Each entry carries an owner or an explicit flag, and a recommended disposition with the reason

  • The readout and the costed correction plan are delivered and access is removed

Commercial basis

Price, scope and timing are considered together.

Engagement price

Price fixed after a short scope call.

The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:

What determines the scope

  • Size of the app-consent and enterprise-application surface
  • Evidence sources available: audit log retention, Intune enrolment, Teams app inventory, any Cloud App Discovery export
  • Number of users and teams in scope
  • Whether a board-level summary is required alongside the technical readout

Delivery calendar

The proposal names the start date, the change windows and the completion date before anything is agreed.

How engagements work

Scope & responsibilities

The full engagement boundary.

Review the exclusions, required client participation, change controls and operational handover for this engagement.

Exclusions
  • No production changes: revoking consents, blocking tools and configuring an approval path are quoted separately from the correction plan
  • Browser- and network-level discovery beyond tenant evidence, which needs client-side tooling or the Cloud App Discovery export
  • Employee monitoring or surveillance
  • Legal review of tool terms
  • Ongoing governance operation, which is handed to internal IT or the MSP
Client responsibilities
  • Grant read-only access to the tenant for the audit window
  • Export a Cloud App Discovery snapshot if the tenant licenses it
  • Confirm or change the recommended disposition on each discovered tool
Change and rollback method
  • The audit is read-only. Nothing is revoked, blocked or reconfigured during it.
  • No software is installed on user devices and no user is interrupted.
  • Access is granted for the audit and removed at the readout, with written confirmation.
Operational record and handover
  • The shadow AI inventory, with the evidence source recorded against every entry
  • The disposition register: recommended allow, watch or block, with owner or flag and reason
  • The consent and reach map: which tools hold which scopes into mail, files, chat and calendars
  • The costed correction plan handed over at the readout

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Discuss this engagement

Put the scope in context.

Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.

Get the Shadow AI Audit Priced in Writing