Skip to content

AI Management

AI is now a line item.
Treat it like one.

Track the models, the experiments, the GPUs and the seats — from a hyperparameter sweep on a training cluster to the ChatGPT subscription someone expensed. One asset class, governed like every other.

One asset class

Four layers governed

  • Agents

    MCP

    Every tool call audited, scoped and quota-tracked.

    Model Context Protocol server

  • Models & experiments

    ML

    Runs, runsets, artifacts and dataset lineage.

    Model registry

  • Training compute

    GPU

    Executors rightsized, migrated and switched off.

    26-check recommendation engine

  • Seats & API keys

    SEAT

    Subscriptions found, ranked and reclaimed.

    SaaS licence engine

The data model and the policy engine are the ones already running the other four asset classes.

layers governed — agents, models, compute, seats
4 layers governed — agents, models, compute, seats
CerteroX products exposing an MCP server
5 CerteroX products exposing an MCP server
cost checks applied to GPU fleets
26 cost checks applied to GPU fleets
adoption risk tiers in the Shadow AI board
3 adoption risk tiers in the Shadow AI board
The problem

Finance sees one AI invoice. Engineering sees a GPU cluster. Security sees an unsanctioned LLM with access to customer data.

Nobody sees all three, and the spend is compounding monthly.

Finance Invoice · monthly
AI services 1 line item
  • Vendor Not itemised on the invoice
  • Team Not itemised on the invoice
  • Model Not itemised on the invoice
  • Seats Not itemised on the invoice

Four fields not itemised

Blind to: which team, which model, and who is actually on it.

Engineering Executors · live

10 running · 5 idle · 17 stopped

Blind to: the invoice, the seat count, the contract renewal date.

Security OAuth grants
Unrecognised LLM app risk 88
drive.readonly mail.read offline_access

Consented by 41 users · never reviewed

Meeting summariser add-on risk 57
calendar.read profile

Blind to: who pays for it and whether it is even a company tool.

CerteroX sees all three.

Inside the product

Shadow AI, ranked by how much of the organisation is already on it.

Ten people on a chat assistant is a policy conversation. A thousand is an incident waiting to be written up. The board tiers every detected tool by share of organisation, scores the grant it holds, and gives you one place to decide.

AI Management / Shadow AI

Illustrative interface · sample data

Adoption risk, ranked

Tier 1 — Broad adoption over 25% of the organisation

Tier 2 — Emerging 5% to 25%

Tier 3 — Isolated under 5%

ChatGPT

OpenAI · detected via browser + oauth

Managed
74

OAuth grant risk score

Scored 0–100 on data sensitivity, scope breadth, consent pattern and dormancy.

Data sensitivity
82
Scope breadth
61
Consent pattern
78
Dormancy
24

Granted scopes

drive.file email offline_access
  • Enterprise tenant detected
  • SSO enforced for 61% of users
  • 148 seats unused for 30+ days

Workflow

On new user → assign to AI budget pool, require SSO

Grant history

  1. 14 Feb First seen
  2. 06 Jun Grant reviewed
  3. 01 Sep Next review

Shadow AI status

Three signals
Browser extension, identity provider and vendor connector, converging on one application record.
Status workflow
Managed, blocked or ignored. The same workflow the SaaS catalogue uses, so nothing sits undecided.
Risk score
OAuth grants scored 0–100 on data sensitivity, scope breadth, consent pattern and dormancy.
The four pillars

The four pillars, pointed at AI.

The same four questions we ask of a laptop, an Oracle database and an S3 bucket, now asked of models, experiments, GPUs and seats, with the same engines answering them.

01 Visibility

Which AI is already here?

Every AI tool in use is found and put on a record.

  • Browser extension
  • Identity provider
  • Vendor connector

Browser, identity provider and vendor connector

  • Shadow AI detection from application feature tags, not a static list
  • AI tool adoption ranked by share of organisation using it
  • Model registry with versioning, and dataset versioning with lineage
Show the other 5
  • ML task, run and runset tracking with console logs and milestones
  • Executor visibility — the compute actually running each workload
  • Custom metrics with target values and goal tendency
  • Leaderboards ranking runs and models by metric
  • Spark instrumentation via the Delight agent collector

8 named capabilities

02 Optimization

What is it costing us?

ML executors land in cost pools with budgets on them.

  • GPU fleet
  • AI seats
  • Model APIs

GPU fleet, AI seats and model APIs in one cost pool

  • The full 26-check recommendation engine applied to ML executors
  • GPU and training-instance rightsizing and generation upgrade
  • AI seat reclamation through the SaaS licence engine
Show the other 4
  • Short-living executor detection for spot and preemptible migration
  • Dedicated ML/AI cost pools with their own budgets
  • Hyperparameter tuning via reusable runset templates
  • Cross-region and cross-cloud migration opportunities for training workloads

7 named capabilities

03 Management

Who runs it, and how?

Runsets provision their own cloud runners and track every run on them.

Illustrative model registry rows
churn-propensity v7 Production
doc-embed-base v3 Staging
ticket-router v11 Archived

Model registry · illustrative sample

  • Model Context Protocol server exposing the platform to AI agents
  • Scoped, per-organisation MCP tokens with full tool-call auditing
  • Runset orchestration that provisions cloud runners on demand
Show the other 4
  • Experiment tracking with artifacts, tags, stages and milestones
  • Leaderboard templates for repeatable model comparison
  • In-product conversational assistant over your own cost and asset data
  • External MCP plugin support for calling out to other servers

7 named capabilities

04 Governance

Is it allowed to do that?

Approve, restrict and evidence AI use before it becomes an incident.

0 Revoke above 85 100

Risk threshold on the grant score

  • Shadow AI status workflow: managed, blocked or ignored
  • OAuth grant risk scoring for AI tools with data access
  • Risk assessment on data sensitivity, GDPR, HIPAA and SOC 2 exposure
Show the other 4
  • Per-application AI budgets with warning and critical thresholds
  • Every AI agent tool call audited and quota-tracked
  • Workflow automation to alert, block or revoke on detection
  • Full audit trail across AI seat provisioning and revocation

7 named capabilities

Where this diverges

Three things no competitor page leads with.

AI governance is mostly sold as a dashboard bolted onto a SaaS catalogue. These are the parts that only work if the platform underneath already governs everything else.

01

AI spend arrives in four different budgets

The seat, the API key, the GPU fleet and the agent all land in different budgets under different owners, and each goes wrong in its own way. CerteroX governs all of them, because it already governs SaaS, cloud, assets and identity. One governance position covers the lot.

Four forms · three engines

  • SaaS Management
  • Cloud Management
  • AI Management

02

Your platform is an MCP server

Every CerteroX product exposes a Model Context Protocol server with scoped tokens and per-call auditing. Your AI agents can query your technology assets, the cloud bill and the licence position directly — and you can see exactly what they asked for.

mcp · tool-call audit Illustrative · sample log
Time Agent Tool call Token scope Result
17:02:11 finops-copilot certerox.cloud.expenses.query pool:ml-research ok 142ms
17:02:14 finops-copilot certerox.sam.licence.position publisher:oracle ok 88ms
17:02:19 sec-triage certerox.saas.grants.list risk>=70 ok 201ms
17:02:22 sec-triage certerox.saas.grants.revoke grant:8c1f denied quota
17:02:26 asset-desk certerox.itam.devices.search site:eu-west ok 63ms
$

Recommendations · ML executors

6 of 26 shown

  • Instances stopped but not deallocated
  • Instance rightsizing
  • Instance generation upgrade
  • Short-living instances — spot candidates
  • Abandoned images and obsolete snapshots
  • Cross-region migration opportunity

Each check carries its own thresholds, pool exclusions and account skips. Nothing was rewritten for GPUs.

03

The GPU bill gets the same 26 checks as everything else

ML executors are cloud instances. So abandoned-resource detection, rightsizing, generation upgrade and spot migration all apply to them automatically. AI cost optimization is not a separate product because it does not need to be.

All twenty-six, in Cloud Management
Integrations

Connected across every layer of the stack.

Model providers, the ML platform, the compute underneath it and the protocol your agents speak.

The AI layer reaches further than this list, because the platform underneath it is already connected to your identity provider, your cloud bill and every SaaS application you own. Those connections carry the AI layer with them.

How the platform connects

Model providers

  • OpenAI
  • Anthropic

ML platforms & frameworks

  • Databricks
  • MLflow
  • PyTorch
  • TensorFlow
  • Apache Spark
  • Kubeflow

Compute & clouds

  • Kubernetes
  • AWS
  • Microsoft Azure
  • Google Cloud
  • Nebius

Agent protocol

  • Model Context Protocol

Plus every connector the rest of the platform carries. See the full list.

Questions

AI Management, answered plainly.

Six questions we are asked in every AI Management conversation. If yours is not one of them, the answer is a short call rather than a form.

What actually counts as an “AI tool” here?

Classification comes from the application feature tags in the catalogue. When a newly catalogued application carries AI capabilities, it joins the Shadow AI view without anyone editing a rule, which matters because the detection set changes every month.

Do we need an agent on the training cluster?

No. ML executors are discovered through the same cloud connectors that already read your billing and resource inventory, so the compute layer needs no additional footprint. Spark workloads can additionally be instrumented with the Delight agent collector if you want run-level detail.

Can we see shadow AI without blocking anything?

Yes. Detection and enforcement are separate. Every detected tool sits in a status workflow (managed, blocked or ignored) and stays in whichever state you choose. Workflow automation to alert, block or revoke is opt-in, per application.

Our own AI agents want to query this data. Is that supported?

Every CerteroX product exposes a Model Context Protocol server. Tokens are scoped per organisation, every tool call is audited and quota-tracked, and external MCP plugins let the platform call out to your other servers. Nothing bespoke has to be built first.

Is AI cost optimization a separate product?

No, and it should not be. An ML executor is a cloud instance, so the recommendation engine already knows what to do with one. All 26 checks run against the GPU fleet. AI seats are reclaimed through the SaaS licence engine for the same reason.

Do we have to buy the other four products first?

No. Every CerteroX product runs standalone on one shared asset model. AI Management is richest alongside SaaS Management and Cloud Management, because seats and GPUs are governed by those engines, but adding them later adds no integration work.

Start with shadow AI

AI you never budgeted for
is already running.

The demo opens on the shadow AI board: the assistants already in use, the seats nobody has opened in a month, the model APIs billing quietly and what a training fleet actually costs.

No gated PDF, just a populated environment, a technical person on the call and an honest answer.