Coming soon · design previewThis page mocks up an unreleased capability with realistic data. It is not yet wired to live providers. Back to demo home

Coming soon · Shadow AI discovery

Every AI tool in your company, in one surface.

GreyScape.ai pulls signals from your expense cards, device fleet, network gateway, code repos, and SSO event log — and merges them into one ranked surface. You triage, sanction, or block from a single page.

Tools surfaced this month
12
Awaiting triage
11
High-risk findings
3
Est. personal-tier spend
$854/mo

Where the signal came from

Each connected source catches a slightly different kind of shadow AI. Stack as many as you can — coverage is additive.

Brex
Card transactions
3
discoveries
Ramp
Card transactions
2
discoveries
Jamf
macOS device inventory
1
discoveries
Intune
Windows / iOS / Android
1
discoveries
Network
DNS / HTTP egress
2
discoveries
GitHub
AI library imports
2
discoveries
Okta
SSO event hooks
1
discoveries

Recent discoveries

filter / sort
ToolCategoryDetected byFirst seenUsersEst. monthlyRiskStatus
ChatGPT Pluschat BrexMay 028$160mediumreview
Claude Prochat RampMay 035$100mediumreview
Cursor IDEcoding JamfApr 2812$240lowsanctioned
Midjourneyimage BrexMay 063$90lowreview
Perplexity Prochat NetworkMay 0814lowreview
ElevenLabsaudio RampMay 042$44mediumreview
Replit AIcoding BrexApr 194$80lowreview
langchain (import)agent GitHubMay 092highreview
OpenAI SDK in prodagent GitHubMay 101highreview
Claude.ai webchat NetworkMay 0721mediumreview
Ollama (local)agent IntuneMay 053highreview
Granolachat OktaMay 087$140lowreview

3 high-risk findings worth your attention this week

  • OpenAI SDK in production code — repo `customer-bot` calls OpenAI with a hardcoded sk-proj- key (committed by Maya Reyes, May 10). No corresponding approval request on file.
    Source: GitHub Enterprise scanner
  • Ollama installed on 3 engineering laptops — local LLM runtime that could be used to process sensitive data without any audit trail.
    Source: Microsoft Intune device inventory
  • langchain library imported in `support-ticket-summariser` — production service was instrumented with LangChain on May 9. Not approved; vendor risk unknown.
    Source: GitHub Enterprise scanner
How you'd use this
  1. Wire each source on /settings/integrations (one-time).
  2. Each morning, scan the high-risk callout — these are the things that need a decision today.
  3. Sanction (move to a corporate seat), Block (add to the deny-list), or Review (assign to a colleague) — every action is in the audit log.
Sample output
12 tools surfaced across 7 sources this month, of which 3 are flagged high-risk. Approx $854/month in personal-tier subscriptions on corporate cards — candidates to consolidate into a company plan.
What this unlocks
See AI tools before they're a habit, not after. Catch hardcoded API keys, local-LLM exfiltration risk, and unapproved library imports before a customer audit finds them.