Agent Inventory Tool

Free browser tool

Shadow AI Discovery Tool and Review Guide

Use this shadow AI discovery tool guide to plan authorized source checks, validate owners and document unknown use without implying automated scanning.

A shadow AI discovery tool process starts with authorized evidence sources and a clear privacy boundary. This guide is a manual review method, not a scanner, employee-surveillance service, connector or account integration. A shadow AI assessment template should record source, date, scope, owner follow-up and unresolved gaps so a negative search is not mistaken for proof that no use exists.

What shadow AI looks like

Shadow AI is AI use that sits outside the organisation's current visibility or approval process. It can include an employee's separate account for a public assistant, a browser extension that summarizes pages, or an agent connected to an internal system. The label describes a visibility gap; it does not prove misconduct or establish that a particular use is unsafe. Start by recording the business purpose, people affected, data involved, permitted actions and the owner who can verify those facts.

Discovery methods (SSO, network, expense, browser)

Use several authorised sources because each shows a different slice of activity. SSO assignments can reveal provisioned services but miss personal accounts and applications that do not use your identity provider. Expense and procurement records can reveal paid services but may use an unfamiliar merchant name or omit free use. Approved browser-extension inventories show what is installed on managed browsers, not necessarily what was used or what data it handled. Network or endpoint evidence can show connections or software indicators, but encryption, mobile devices, off-network use and shared infrastructure can limit attribution. None of these sources alone proves a complete inventory.

Set a bounded discovery scope: business units, managed devices, approved data sources, review period and authorised analysts. Prefer aggregate service and configuration evidence over collecting message contents or individual browsing histories. Record the source, date, coverage and known blind spots for every finding. NIST's voluntary AI RMF 1.0 MAP function calls for establishing and documenting system context, intended purpose and deployment setting; it is a useful risk-management reference, not a discovery tool or certification. NIST says the framework is being revised. Read NIST AI RMF 1.0, especially MAP and its current status page.

Survey template

Use a short, non-punitive questionnaire to learn about workflows that technical sources may not reveal. Send it through an established internal process, explain who will use responses, and do not ask staff to paste prompts, customer records or credentials.

  1. Which AI-enabled service, feature, extension or agent do you use for this work? If you do not know its name, describe how you access it.
  2. What work task does it support, and which team owns the workflow?
  3. What kinds of information are submitted or made accessible? Choose the organisation's approved data categories; use “unknown” when unsure.
  4. Does it only provide suggestions, prepare drafts, or take an action in another system? Describe the action without including sensitive content.
  5. What human review or approval occurs before an output is used or an action is completed?
  6. Which business owner can confirm the service, purpose and access? What evidence source could help verify the record?

Illustrative hypothetical response: “Meeting-summary assistant; operations team; internal meeting notes; drafts summaries only; meeting owner reviews before sharing; service name and retention are unconfirmed.” Treat the unknowns as follow-up questions, not as evidence of a violation.

Triage

First verify that the service or agent exists and that the report describes the actual deployment. Then assign an owner and record purpose, data category, integrations, permissions, human checkpoints, evidence source and confidence. Prioritise follow-up when sensitive data, write access, consequential decisions or unclear ownership is involved, using your organisation's approved process. Keep the reason and reviewer visible. A missing expense entry or a builder's review label is not a legal risk classification, proof of policy breach or evidence that all use has been found.

For example, suppose a team reports a meeting assistant absent from SSO and expense records. Record the service as reported, mark account type and retention unknown, identify the meeting workflow owner, and ask an authorised service owner to verify the deployment and data handling. Do not infer that the report is false merely because two sources did not match.

Bringing tools into governance

Have the accountable owner decide whether to approve, constrain, replace or retire the workflow under existing policy. Capture the decision and evidence reference, define allowed data and actions, and set a review trigger for changes to service, permissions, model or purpose. Reconcile later discovery signals with the owner-validated record. This page offers a manual workflow only: this site does not scan identity, network, expense or browser systems, survey employees, or monitor service use.

For context and implementation guidance, the public ISO overview describes ISO/IEC 42001:2023 as an AI management-system standard, but the licensed normative text was not available in the reviewed source set; this page makes no Annex A clause mapping or conformity claim. The SEO brief also mentions EU AI Act Article 49, but this workflow does not classify systems or determine registration duties; check the official regulation and obtain qualified review before making a legal determination.

Continue with the AI agent inventory builder, the AI inventory template, or the AI agent inventory template.

Sources: NIST AI RMF 1.0; NIST AI RMF status; ISO/IEC 42001 public overview; EU AI Act official text.

Use approved sources and careful questions

A shadow AI survey template can ask teams which services support their work, what data they use and who approves the workflow. A shadow AI audit checklist can add evidence references, system owner, access path, permitted actions and disposition. Keep responses separate from telemetry, apply privacy and labor policies, and explain what the review will collect. To answer how to find shadow AI in your company, combine authorized interviews and procurement, identity or endpoint records with owner confirmation rather than relying on one search.

An AI agent discovery checklist should note source coverage and permissions. When evaluating an AI agent discovery tool or AI agent discovery software, test what it observes, which accounts and environments it can reach, and whether owners verify its results. This manual guide does not perform those checks.

Check platform records without claiming connectors

For discover AI agents in Microsoft 365 work, ask the tenant administrator which authorized inventory or audit surfaces exist and what their retention covers. A Copilot Studio agent inventory or Copilot Studio agents list should be reconciled with maker ownership and environment records where permitted. A Salesforce Agentforce agent inventory should be checked against the organization’s own configuration and owner records. An AWS Bedrock agents inventory should identify account, region, version and responsible team from approved AWS records. These are source questions, not integrations supplied by this site.

For a custom GPT inventory, ChatGPT Enterprise connectors inventory, Claude connectors audit or OpenAI assistants inventory, record workspace scope, administrator source and data-access boundary. A connector name does not prove it is enabled, used or approved. For an SSO audit for AI apps, compare authorized identity-provider assignments with owner records. An OAuth apps AI tools audit should record scopes and consent context using approved logs. A browser extension AI tools inventory should rely on allowed endpoint or browser-management evidence and disclosure, not covert collection.

Use the resulting shadow AI inventory to assign follow-up, not label an employee or application unsafe. Record unauthorized AI tools in the workplace as an unresolved policy question until owners confirm the facts. The manual builder can structure records you assemble; it does not discover services automatically. Updated 2026-10-08. Sources are linked on this page.

Primary sources and review

Published by Agent Inventory Tool. Updated . Sources are linked on this page. Outputs do not certify compliance.