See every AI tool and agent your team really uses.
Lutril's shadow AI discovery combines a Chrome extension, mailbox scanning, sign-in logs, and code scanning to surface every AI tool and agent your team runs, sanctioned or not, so nothing handles your data in the dark.
- Chrome extension
- Catches AI tools at the point of use, even when they skip SSO.
- Email scanning
- Reads sender and subject lines in Google and Microsoft mailboxes to spot sign-up emails from AI vendors.
- OAuth & SSO
- Pulls grants and sign-in logs straight from your identity provider.
- Risk scoring
- Ranks every tool by users, data exposure, and training policy.
| Tool | Signal | Risk | ||
|---|---|---|---|---|
| ChatGPT | 84 | Chrome extension | high | — |
| Claude | 37 | OAuth grant | medium | Eng |
| Gemini | 52 | SSO sign-in | medium | — |
| Copilot | 19 | OAuth grant | low | Eng |
| Perplexity | 28 | Chrome extension | high | — |
| DeepSeek | 6 | Email scan | high | — |
Where the signal comes from.
Four independent sources. Each catches tools the others miss, so the picture stays complete even when people route around IT.
Chrome extension
Deployed through your MDM. Flags the AI domains employees open in the browser, including tools that never sign in through SSO.
Email scanning
Scans message metadata in Google Workspace and Microsoft 365, sender and subject only, for the sign-up and welcome emails AI vendors send. Message bodies are never fetched.
OAuth & SSO
Reads OAuth grants and SSO sign-in logs to show which AI apps hold standing access through a corporate Google or Microsoft account.
Code scanning
Finds the agents living in your GitHub and GitLab repos, wired to API keys nobody tracks.
Questions buyers ask
How do you discover shadow AI?
By combining signals, because each one misses something. An OAuth grant only exists when someone signs in with Google or Microsoft; a tool adopted with an email and a password leaves no grant, and an agent built in code calls an API with a key your identity provider never sees. Lutril reads OAuth grants, sign-up emails, browser visits to known AI domains and your GitHub and GitLab repositories, and merges them into one inventory per vendor.
What should a shadow AI discovery tool show?
Four things: which AI tools and agents are in use, who uses each one, what each can reach, and a way to act on it. In Lutril every vendor gets one card listing its users, the sources that saw it and the OAuth scopes it holds, with high-risk scopes flagged. From there you mark it managed or unmanaged, block it or revoke its OAuth access, and discovered agents can be promoted into the agent registry with an owner.
Can Lutril detect AI models running locally on a laptop?
No. Lutril has no endpoint agent that inventories installed software or running processes, so a model run locally through a desktop runtime, with no browser visit, no sign-up email, no OAuth grant and no code in a scanned repository, is not visible to it. What Lutril does see are the traces around it: a visit to a catalogued AI site such as Hugging Face through the extension, a vendor sign-up email, or agent code that lands in GitHub or GitLab. Local inference itself is the job of endpoint tools: your MDM software inventory or your EDR, which see installed applications and running processes.
Does the browser extension record browsing history or read prompts?
No. It checks each visited hostname on the device against a catalogue of known SaaS and AI domains and reports the hostname only when it matches, never the full URL, path, query string or page content. If prompt DLP is enabled, prompts on ChatGPT, Claude and Gemini are scanned on the device and only a count of detected data types leaves it. The extension is force-installed through Google Workspace or Intune, and each device can be revoked on its own.
What does email scanning read?
Message metadata only: sender, subject and date. Lutril looks for sign-up and welcome emails from SaaS and AI vendors, which is how it finds tools adopted with an email and a password. Bodies are never fetched or stored, the scan is opt-in per workspace, and the first run looks back 90 days.
How does code scanning find AI agents in repositories?
Lutril connects to GitHub or GitLab with a read-only token and scans a snapshot of each repository for agent code, such as LangChain, CrewAI, AutoGen, LlamaIndex or the OpenAI Agents SDK, and for agent definitions declared in YAML or JSON. Code is never executed and never sent to an LLM. Each finding carries a risk score from its declared capabilities and a suggested owner drawn from commit authors, and can be promoted into the agent registry or dismissed.