Discover
AI agents interview employees to map AI use cases — no forms, no manual entry
CISO Discovery Campaign
Send AI agents to interview all departments. Agents ask about AI tool usage, data handling, and risk exposure.
Employee Self-Registration
Share a link with staff. An AI agent interviews them conversationally and extracts use case data automatically.
Auto-Detect via Okta
12 new AI tools detected in your SaaS estate this week. Review and trigger intake agents for ungoverned tools.
12 new
142
Outreach Sent
89
Responded
47
Use Cases Identified
12
Shadow AI Detected
Agent Conversations
Sarah Chen
Legal
AI
Hi Sarah — I'm helping your security team understand how AI is being used across the organisation. Are you currently using any AI tools in your daily work?
S
Yes, we use ChatGPT for drafting contracts and summarising legal briefs.
AI
Thanks! Does the contract text include any client-confidential information such as names, deal terms, or financial data?
S
Yes, client names and deal terms are included.
AI
Got it. Who reviews the AI output before it's used — or does it go directly into documents?
S
I always review it, but junior associates sometimes use it directly.
✓ Use case extracted: Contract Review AI · GPT-4o · Confidential data · Owner: Sarah Chen
James Okafor
IT
AI
Hi James — quick question from the security team. Is your engineering team using any AI coding assistants or automation tools?
J
Yes, GitHub Copilot for the whole team, and some people use Claude for code reviews.
AI
Does Copilot have access to any proprietary internal codebases or API keys in the repo context?
J
It has access to our internal repos yes, including some that have config files.
✓ Use case extracted: Code Assistant · GitHub Copilot · Internal codebase · Owner: James Okafor
Priya Sharma
HR
AI
Hi Priya, the security team is conducting an AI use case review. Does HR currently use any AI tools for recruitment or employee management?
P
Yes — we use an AI tool to screen CVs and rank candidates. Also using ChatGPT for writing job descriptions.
AI
The CV screening tool — does it process any protected characteristics data like age, nationality, or gender from the CVs?
P
The CVs often include photos and dates of birth. We haven't configured it to ignore those.
✓ Use case extracted: CV Screening · AI Classifier · Sensitive personal data · Owner: Priya Sharma · HIGH RISK: Bias
Michael Torres
Finance
AI
Hi Michael — I noticed ChatPDF was accessed from your machine using your corporate credentials. Are you using this for work purposes?
M
Oh yes, I use it to read client contracts and financial reports. It's much faster than reading the full PDFs.
AI
Are those documents confidential? And was this tool approved by IT?
M
They're definitely confidential... I didn't know I needed approval. I just googled a tool that worked.
✓ ⚠️ Shadow AI detected: ChatPDF · Confidential contracts uploaded to unapproved external service · Owner: Michael Torres
Emma Fischer
Claims
AI
Hi Emma — I'm mapping AI tools used in Claims. What AI systems does your team currently use in claims processing?
E
We have a fraud detection model, an AI for damage assessment from photos, and we auto-generate claims letters.
AI
The fraud detection model — has it been tested for bias across customer demographics like age or ethnicity?
E
We had one audit last year but I'm not sure the results were actioned. It's been flagged a few times.
✓ Use case extracted: Fraud Detection Model · Critical bias risk flagged · Owner: Emma Fischer
Marco Rossi
Finance
AI
Hi Marco — as CFO, I want to understand what AI tools Finance is using for reporting or forecasting. Can you help?
M
We use GPT-4 to help generate board reports and budget forecasts. I review everything before it goes out.
AI
Are financial figures fed directly into the AI prompt, or does it only work with aggregated/anonymised data?
M
Full P&L data goes in. We haven't thought about whether that's a risk.
✓ Use case extracted: Report Generator · GPT-4o · Restricted financial data · Owner: Marco Rossi
Tom Bradley
Underwriting
AI
Hi Tom — I'm reviewing AI use in Underwriting. What AI systems are in use for risk assessment or pricing?
T
We have a risk assessment model and an LLM that explains pricing decisions to customers.
AI
Does the risk assessment model use any customer demographic data like postcode or occupation that could create protected characteristic proxies?
T
Yes it uses postcode which I know can correlate with ethnicity. It's been flagged by our actuaries.
✓ Use case extracted: Policy Risk Assessor · Critical bias risk (postcode proxy) · Owner: Tom Bradley · EU AI Act gap
Lisa Wang
Risk & Compliance
AI
Hi Lisa — as CRO, you're well placed to help. What AI tools does Risk & Compliance use, and are you aware of any ungoverned AI elsewhere?
L
We use AI for sanctions screening, regulatory monitoring, and risk scoring — all properly governed. But I know some teams are using ChatGPT informally.
AI
Can you name any specific departments or tools you've noticed being used informally?
L
Finance uses some PDF tool I don't recognise, and I heard HR is using an AI for CVs without proper vetting.
✓ Shadow AI leads: ChatPDF (Finance) · CV Screening tool (HR) · Referred for investigation