Solutions / Lumen — Shadow AI

Centeye Lumen™ — shadow-AI discovery and governance, across every client tenant.

Shadow AI is the AI tooling employees connect to company data without IT approval. They connect AI note-takers to mailboxes, paste ledgers into chatbots, and wire AI tools into company data over APIs — none of it visible in a browser history. Lumen inventories it, scores the risk, and gives you a governed way to sanction, flag, or revoke — per tenant, with the client’s sign-off on record.

Google WorkspaceMicrosoft 365DNS-level visibility
This surface’s chapter of the attack
New AI tool connectedOAuth grant · mailbox scope
Vendor trust: unknown3-week-old domain · no posture
Data flowing via APIDNS-level signal · no browser
Risk scoredaccess × vendor trust
Governedflagged for review · revocable
What your clients get

Inventory it. Score it. Govern it — without a blanket ban.

Shadow AI discovery — including what the browser never sees

The riskiest AI use does not appear in a browser plugin report or an expense line. Discovery covers the channels where unsanctioned AI actually lives:

  • AI tool inventory — which AI services are in use across the client’s workspace, including tools connected by OAuth grant rather than installed software.
  • Direct API detection — AI calls that bypass the browser entirely (scripts, plugins, integrations) surfaced at the network and DNS layer.
  • Workspace & sign-in monitoring — authentications to AI services with company identities across Google Workspace and Microsoft 365.

OAuth + DNS + identity — three discovery planes

Risk scoring, not raw usage counts

A meme generator and a mailbox-connected note-taker are not the same exposure. Every discovered tool is scored on what it can reach and who is behind it:

  • Vendor trust signals — an established vendor with a published security posture, or a three-week-old wrapper holding a mailbox scope.
  • Access scoring — the data the grant actually reaches: mail, files, calendar, directory.
  • DNS-level exfiltration monitoring — data leaving through DNS, the channel most stacks never watch.

access × vendor trust · scored per grant

Governance with an audit trail

Blanket AI bans fail — people route around them. Lumen gives the provider a governed middle path: sanction the approved list, flag risky grants for review at the QBR, revoke the dangerous ones — with the same approval modes and tamper-evident audit trail as every other Centeye action, and the client’s sign-off on record.

sanction · flag · revoke — audited

How it works

Discovery first. The inventory makes the case.

Connect the workspace

The same API connections that power the rest of Centeye — no new agent, no end-user friction.

Run discovery

The AI-tool inventory builds itself: what’s connected, what it can reach, how it’s being used.

Set the AI policy

Sanction the approved list, review the flags at the QBR, revoke the rest — documented, with the client’s sign-off.

Kavach · on this surface

Flags the new AI grant with mailbox reach the day it appears, scores it, and stages the revoke for approval.

Argus · for the client

Equips the client conversation that matters this year: “here is the AI your team uses, what it can reach, and what we sanctioned” — the basis of an AI acceptable-use policy you can actually enforce.

Common questions

What MSPs ask us first

What is shadow AI?

AI tools adopted by employees without IT approval — chatbots, note-takers, browser plugins, and API integrations — that touch company data outside any sanctioned control. It is the fastest-growing unmanaged data channel in most client environments.

Is this about blocking ChatGPT?

No — it is about knowing which tools touch company data and governing the risky ones. Most clients end up sanctioning a short list and revoking the rest, with the decision documented.

Why does DNS matter here?

API-based AI use never appears in a browser plugin or a CASB portal. The DNS layer sees the traffic anyway — which is why discovery includes it.

Does this slow anyone’s work down?

Discovery and scoring are invisible to end users. Governance actions are deliberate, reviewed, and reversible.

Can this support an AI acceptable-use policy?

Yes — the inventory and risk scores are exactly the evidence an acceptable-use policy needs: what is in use, what it can reach, what is sanctioned, and what was revoked.

Run discovery on one tenant.

Bring the inventory to your next QBR — most client owners are surprised within the first week.