How it works
What we read, what we do with it, what you get out.
GreyScape sits beside your AI providers, not in front of them. We read from a fan-out of sources — provider admin APIs, expense feeds, the browser, your billing inbox, your code — turn that into a deduplicated AI inventory attributed to real people, classify each system under the EU AI Act, surface obligations, materialise evidence, and forward the audit trail to your SIEM. The product is read-only on day one. Setup is ten minutes.
Inputs
Six places we read data from
Every input is opt-in and read-only on day one. Together they form a fan-out signal: no single source catches every AI tool, but the union of six does.
Provider admin APIs
Today: OpenAI + Anthropic · Coming soon: Azure OpenAI, AWS Bedrock, Google Vertex
You paste one organisation-level admin key per provider. Every 15 minutes we pull the canonical usage + cost endpoints (OpenAI /v1/organization/costs, Anthropic /v1/organizations/usage_report and the equivalents on Azure / Bedrock / Vertex when those connectors ship). No prompts, no completions, no embeddings — just the metadata you need to govern.
Try it in the demoBrowser extension
Today
Lightweight extension watches a curated allow-list of AI tool domains and emits one heartbeat per day per tool per device. Catches consumer-tier ChatGPT, Claude.ai on a personal Google account, Midjourney through Discord, Suno on a phone-tethered laptop — the long tail provider APIs cannot see. Detection-only; never reads page content.
Try it in the demoCard + receipt feeds
Today: email receipts · Coming soon: Brex, Ramp, NetSuite, QuickBooks
Forward your billing inbox to your tenant's GreyScape address — we parse vendor receipts (PDFs, HTML, plain text) for amount, plan, cadence, vendor. Even on a personal card. When the card feeds ship, the merchant scan covers ~200 curated AI vendor names.
Try it in the demoSmart upload + CSV intake
Today
Drop any file — bank statement, vendor CSV, a slack export — and an LLM extracts the AI/shadow-AI signal: which tools, who's using them, how much. CSVs with a known shape skip the LLM and parse deterministically. Per-row diagnostics on every import.
Try it in the demoIdentity + device feeds
Coming soon — WorkOS SSO + SCIM, Jamf, Intune
One WorkOS connector covers Okta, Entra ID, Google Workspace, Rippling, OneLogin and Ping for SSO event hooks + SCIM directory sync. Jamf + Intune surface AI apps installed on managed laptops (Claude desktop, Cursor IDE, Raycast AI extensions). The org chart stays live as people join, change roles, or leave.
Try it in the demoNetwork + code feeds
Coming soon — Cloudflare AI Gateway, Zscaler, Cisco Umbrella, GitHub Enterprise
DNS + HTTP egress to AI domains catches browser-only users who never trigger a card transaction. A GitHub Enterprise scanner walks your repos for AI library imports (openai, anthropic, transformers, langchain, llama-index) and inline API-key patterns — often the first signal that an engineering team has gone live with AI without telling anyone.
Try it in the demoYou pick the surfaces that match your environment. Most customers start with provider admin APIs + email receipts + the browser extension — three zero-touch sources that surface roughly 70% of shadow AI in the first week. Full integrations list →
The engine
What we do with the data
Six operations run continuously over the input streams. Each one is a building block the dashboards, registers and audit pack stand on top of.
Deduplicate across sources
The same ChatGPT can show up as a provider-API workspace, an email receipt, three browser-extension heartbeats and a card charge. A canonical_tool_id keeps the catalogue collapsed to one row per actual tool — every source contributes to the same record, never spawns a duplicate.
Attribute to real people + teams
Provider usage is tagged by service-account or workspace membership, which we join to your SSO directory by email. Card and receipt signals match on declared_by / billing email. The Users + Teams pages roll spend, requests and shadow-AI activity up to real people — not anonymous keys.
Classify under the EU AI Act
An admin opens any tool and answers six questions: role (provider / deployer / importer / distributor), risk class (prohibited / high / limited / minimal / unclassified), Annex III use-case selection if high-risk, owner, legal basis, oversight design. On save, the applicable obligations from the catalogue (Art 4, 5, 9–17, 26, 27, 49, 50, 71, 73) materialise automatically for that system.
Detect Article 50 transparency triggers
Heuristic on tool name + category flags systems that interact with humans (chat assistants → Art 50(1) disclosure), generate synthetic audio / image / video content (Art 50(2)), or are capable of producing deepfakes (Art 50(4)). Surfaces on the per-system page so admins can document the disclosure even when their risk class is just 'limited'.
Govern new workloads in 60 seconds
When someone wants to build with AI, an admin sends a one-use scoping link. The requester chats with an LLM-driven advisor for about a minute — what they're trying to do, on what data, how often, what quality bar. Recommends the cheapest sensible model, estimates monthly cost, lands a structured request on the approval queue. Approve and a scoped service-account key is auto-provisioned.
Forward the audit trail to your SIEM
Every admin action, every classification change, every shadow-AI discovery streams to your security stack via a generic JSON webhook — Splunk HEC, Microsoft Sentinel, Elastic, Datadog, LogScale or any HTTPS collector with bearer-token auth. Per-stream toggles, per-destination cursor advance, idempotent retry on failure.
Outputs
What you get out of it
Six things you can do with the engine's output. Every link below is a real route in the portal — click any to open the seeded demo on that surface.
See spend across providers, users, teams
Month-to-date spend, end-of-month forecast, 30-day trend, per-provider/user/team/project rollup. Sort by month-to-date, % change vs last month, or anomaly score.
For: Finance, FinOps, CFO
Open the demo dashboardTriage shadow AI to one inventory
Every discovered AI tool, deduplicated across the six input surfaces. Per tool: team, user count, source, risk score, status (review / sanctioned / blocked). Triage with one click.
For: IT, security, FinOps
See the shadow-AI hubApprove workloads with an audit trail
One-minute scoping advisor, structured approval queue, auto-provisioned service-account keys per workload. Every decision recorded with the full requester conversation.
For: IT admins, approvers, requesters
Try the approval flowTrack EU AI Act readiness to 2 Aug 2026
Live countdown to enforcement. Coverage stats: classified vs unclassified, high-risk vs prohibited, Annex III count. Gap cards: systems missing oversight docs, classifications in draft, missing owners.
For: CISO, DPO, compliance officer
Open the EU AI Act dashboardDownload a regulator-ready audit pack
One-click HTML export per system: classification rationale, Article 50 triggers, full obligation checklist with status + notes, evidence inventory, FRIA, last 50 audit-log entries, SHA-256 integrity hash. Prints to PDF cleanly.
For: Internal audit, external audit, regulators, customer vendor-risk
See an audit packStream the audit trail to your SIEM
Audit log + compliance classifications + shadow-AI events forwarded to your SIEM every 15 minutes via JSON webhook. Per-stream toggles, retry on failure, in-app delivery log shows every batch.
For: Security ops, SOC, SIEM admins
See SIEM forwardingTrack AI literacy + report incidents
Per-user training records with bulk LMS imports for Article 4 compliance. Serious-incident reporting workflow for Article 73 — capture, investigate, report to authority, resolve. Tamper-evident audit log with cryptographic chaining.
For: DPO, compliance officer, HR
See literacy + incidentsPlus: budget alerts on Slack + email, anomaly detection for runaway spend, structured + natural-language reports, CSV exports for chargeback, and a tamper-evident audit log of every admin action.
Workflows
From zero to regulator-ready
Four timeline scenarios showing the platform in motion. Each step links to the demo so you can see exactly what it looks like.
Day 1 · 10 minutes
Connect a provider, see your first inventory
- Sign up via Google or Microsoft SSO. Pick a tenant slug.
- Paste an OpenAI or Anthropic admin API key into Inputs → Sources.
- First sync runs in under a minute. Dashboard fills in.
- Within ten minutes you have a real-tenant view of MTD spend, top providers, and the first shadow-AI candidates.
Week 1
Classify your highest-risk systems
- Forward your billing inbox to your tenant's GreyScape address. Shadow-AI candidates start populating from receipts.
- Open /compliance/register — every active subscription appears as 'Unclassified'.
- Click any tool → the 6-section questionnaire takes ~3 minutes. On save, obligations materialise automatically for that system.
- By end of week 1 your top 5–10 systems are classified, obligations are tracked, and the dashboard's gap cards show what's still outstanding.
Month 1
Continuous SIEM forwarding + monthly chargeback
- Configure a SIEM destination in /compliance/SIEM forwarding (Splunk HEC, Sentinel, Elastic, Datadog, LogScale or generic webhook).
- Fire the Test button to confirm credentials + URL. Real audit + compliance events forward every 15 minutes from then on.
- End of month: export the per-user/team/project CSV for chargeback into NetSuite or QuickBooks. Repeat monthly.
- Anomaly detection emails the budget owner whenever a workload trends ≥ 30% above last month's run-rate.
Before 2 August 2026
Complete FRIA, attach evidence, download the audit pack
- Upload DPIA + conformity-assessment + instructions-for-use PDFs to each high-risk system's evidence vault.
- For high-risk deployers in essential public/private services, complete the FRIA template (Art 27) — purpose, scope, affected categories, risks, mitigations, residual risk.
- Mark obligations 'complete' as evidence lands.
- Hit Download audit pack on each system — a single signed HTML file ready for the regulator, internal audit, or a customer vendor-risk review.
See it on a fully-seeded tenant
The demo isn't a slideshow. It's a real GreyScape tenant with 42 days of realistic data — providers connected, shadow-AI inventory populated, six systems classified across every risk class, obligation checklist mid-progress, two evidence files attached, one FRIA completed, a SIEM destination configured. Refreshed daily. No sign-up. Click anything, change anything.
Frequently asked
How the architecture answers the questions you'll get first
What does GreyScape see — and what does it never see?
Provider usage metadata only: which key, which model, token count, cost, timestamp. We never see prompts, completions, embeddings, training data, or anything in the request body. Provider admin APIs don't expose those to us by design — and we wouldn't ingest them if they did.
How long does setup actually take?
About ten minutes for the read-only path: paste an OpenAI or Anthropic admin API key, run the first sync, the dashboard fills in. No production code changes, no proxy, no SDK swap. Auto-provisioning and the approval workflow add another five minutes once you decide to switch them on.
Where does our data live?
EU-region Postgres on Railway (Frankfurt) by default. US region available on request. Tenant data is isolated by tenant_id at every query, enforced with Postgres row-level security policies. We never share data between tenants. Full residency + sub-processor detail at /trust and /legal/subprocessors.
What's the sync cadence?
Provider sync runs hourly per (tenant, provider). Budget alerts + anomaly detection run hourly. SIEM forwarding runs every 15 minutes. The demo tenant refreshes daily so the trend lines always end on today's date. Configurable per cron job.
Will the approval workflow slow our developers down?
No. The advisor + approve cycle takes about one minute. Existing approved workloads keep their existing keys (BYOK supported). Budgets are guardrails, not hard caps — a 100% breach raises an alert; it does not kill the production application. Hard gateway enforcement is opt-in on the roadmap.
What about the EU AI Act?
The /compliance/* surface (dashboard, register, per-system detail, audit pack) was built for this. We don't certify your compliance — that's the role of notified bodies — but we produce the underlying evidence (classified inventory, obligation tracking, evidence vault, FRIA, signed audit pack) every framework requires. Mapped to Articles 4, 5, 9–17, 26, 27, 49, 50, 71, 73. Read the full /eu-ai-act page for the regulatory detail.
How do shadow AI tools get attributed to real people?
Card-feed and receipt-feed signals match on cardholder / billing email. Browser-extension signals match on the corporate Google or Microsoft account the device is signed into. SSO event hooks (when WorkOS SCIM ships) match on the SSO email at signup time. For tools that never produce any of those signals, you can launch an attestation campaign that asks employees to declare what they use.
What if our SIEM isn't on the supported list?
Generic webhook (JSON over HTTPS POST with bearer auth) covers ~90% of the SIEM market — Splunk HEC, Microsoft Sentinel Log Analytics, Elastic, Datadog, LogScale, Sumo, and any custom HTTPS collector with token auth. If your SIEM needs something exotic (HMAC-signed bodies, mTLS, a proprietary auth scheme), tell us — it's a small add.
Continue reading
Related pages
- Integrations → — every connector, with a candid roadmap.
- What we collect → — per data point, mandatory vs optional.
- Shadow AI discovery → — pillar page on the discovery surfaces.
- AI budget control → — attribution, budgets, approvals.
- EU AI Act readiness → — the regulatory detail + portal walkthrough.
- Trust overview → — residency, sub-processors, security stack.
- AI workload calculator → — pre-build sizing tool.