# See every AI tool and agent your team really uses.

> A Chrome extension, email scanning, sign-in logs, and code scanning surface every unsanctioned AI tool and agent in your company, before it becomes an incident.

Source: https://www.lutril.com/ai-governance/shadow-ai

---

A Chrome extension, mailbox scanning, sign-in logs, and code scanning surface every AI tool and agent your team runs, sanctioned or not, so nothing handles your data in the dark.

- Browser extension
- IdP sign-in signals
- Agent discovery

- **Chrome extension** Catches AI tools at the point of use, even when they skip SSO.
- **Email scanning** Reads Google and Microsoft mail for sign-up and receipt emails from AI vendors.
- **OAuth & SSO** Pulls grants and sign-in logs straight from your identity provider.
- **Risk scoring** Ranks every tool by users, data exposure, and training policy.

## Where the signal comes from.

Three independent sources. Each catches tools the others miss, so the picture stays complete even when people route around IT.

- **Chrome extension** Deployed through your MDM. Flags the AI domains employees open in the browser, including tools that never sign in through SSO.
- **Email scanning** Scans Google Workspace and Microsoft 365 mail for the sign-up confirmations, receipts, and trial notices AI vendors send.
- **OAuth & SSO** Reads OAuth grants and SSO sign-in logs to show which AI apps hold standing access through a corporate Google or Microsoft account.
- **Code scanning** Finds the agents living in your GitHub and GitLab repos, wired to API keys nobody tracks.
