Four AI problems
sit in one asset class.
The seat someone expensed, the API key burning tokens, the GPU fleet running a sweep and the agent calling your systems are four different governance problems. CerteroX covers all four, because it already covers SaaS, cloud, assets and identity.
Answered on one platform. One data model across ITAM, SAM, SaaS, Cloud and AI.
Shadow AI · adoption risk
IllustrativeAI tools detected across the organisation
Classified from application feature tags
- AI tools detected seats, keys, grants and agents
- 34
- Reviewed and managed
- 9
- Blocked
- 3
- Unreviewed no owner, no risk assessment
- 22
- Highest adoption tool share of organisation signed in
- 41%
- OAuth grants with drive access risk score ≥ 70
- 6
Adoption risk model
three tiers, by share of organisation
The problem
Three departments are each looking at a third of the problem.
Finance sees one AI invoice. Engineering sees a GPU cluster. Security sees an unsanctioned model with access to customer data. Nobody sees all three, and the spend compounds monthly.
+393%
growth in AI-native application spend at large enterprises
Whatever your AI budget is this year, plan on the number moving under you before the year is out.
- 01 ten users, then a thousand
Adoption is a risk curve.
Ten people trialling an assistant is an experiment. A thousand people using it daily is a dependency, a data-flow and a renewal you will be negotiating from behind. The same tool, two entirely different decisions.
Shadow AI Dashboard with three-tier adoption risk model AI Management
- 02 the list is stale on arrival
A hardcoded list of AI tools is out of date the week it ships.
The bigger problem is the tool you already own. It ships an AI feature in a point release, under a name your blocklist has been treating as safe for years.
Shadow AI detection from application feature tags, not a static list AI Management
- 03 the grant nobody reviews
Someone clicked Allow, and a note-taker now reads the whole drive.
OAuth grants outlive the enthusiasm that created them. Scope is broad, review is never, and the grant survives the account that authorised it.
OAuth grant risk scoring on sensitivity, scope, consent and dormancy SaaS Management
- 04 a GPU is a cloud instance
The training cluster is ordinary waste wearing an interesting hat.
Idle executors, oversized instances, a previous generation left running, spot-eligible workloads paying on demand. Nothing about it is special except how much it costs per hour.
The full 26-check recommendation engine applied to ML executors AI Management
- Governing AI means knowing which tools, which grants, which GPUs and which agents you are holding right now. Any of the four can be changed today.
Three of the five disciplines.
Each runs standalone and shares one asset model, so the parts of this that span products need no integration work.
- Primary CerteroX AI Management Models, experiments, GPU fleets, agents and the MCP layer, governed as one asset class. Product page
- Also applies CerteroX SaaS Management AI seats, OAuth grants and the workflow engine that revokes them. Product page
- Also applies CerteroX Cloud Management The cost model and policy engine underneath the compute. Product page
Five steps, from detection to an audited agent.
AI governance fails at the third step, because most tools can tell you something is happening and not one thing you can do about it.
-
Detect what is actually in use
Four signals across seats, grants, compute and agents, resolved into one picture.
- Shadow AI detection from application feature tags, not a static list AI Management
- AI tool adoption ranked by share of organisation using it AI Management
- OAuth grant discovery for consented third-party applications SaaS Management
- Executor visibility — the compute actually running each workload AI Management
- ML task, run and runset tracking with console logs and milestones AI Management
-
Assess the exposure
Risk is data plus scope plus reach, and all three are measurable.
- Risk assessment on data sensitivity, GDPR, HIPAA and SOC 2 exposure AI Management
- OAuth grant risk scoring on sensitivity, scope, consent and dormancy SaaS Management
- Shadow AI Dashboard with three-tier adoption risk model AI Management
- Model registry with versioning, and dataset versioning with lineage AI Management
-
Decide, then enforce the decision
Managed, blocked or ignored, with automation that carries the decision out on detection.
- Shadow AI status workflow: managed, blocked or ignored AI Management
- Workflow automation to alert, block or revoke on detection AI Management
- One-click grant revocation, also available as a workflow action SaaS Management
- AI seat reclamation through the SaaS licence engine AI Management
-
Cost it like everything else
AI spend is four line items in three systems. Here it is one portfolio with budgets.
- Dedicated ML/AI cost pools with their own budgets AI Management
- Per-application AI budgets with warning and critical thresholds AI Management
- GPU and training-instance rightsizing and generation upgrade AI Management
- Short-living executor detection for spot and preemptible migration AI Management
- Cross-region and cross-cloud migration opportunities for training workloads AI Management
-
Evidence every call
When an agent has credentials to your systems, the audit trail is the control.
- Scoped, per-organisation MCP tokens with full tool-call auditing AI Management
- Every AI agent tool call audited and quota-tracked AI Management
- Full audit trail across AI seat provisioning and revocation AI Management
- Audit log covering every provisioning and deprovisioning step SaaS Management
Ask to see any one of these running in the product itself, on the screen where it happens.
What good looks like.
An AI portfolio with an owner, a status and a budget against every line of it.
- 01
The detection set grows without you.
Classification comes from application feature tags in the catalogue, so a tool that adds AI features next quarter appears next quarter, with no list to maintain.
- 02
Every tool has a status.
Managed, blocked or ignored. Ignored is a legitimate answer, provided somebody chose it, and the workflow enforces whichever one they chose.
- 03
Grants are reviewed like accounts.
A 0–100 risk score built from data sensitivity, scope, consent and dormancy, with one-click revocation that is also available as an automated workflow action.
- 04
The GPU bill gets the same twenty-six checks.
ML executors are cloud instances, so rightsizing, generation upgrade, abandonment detection and spot migration apply automatically. AI cost optimisation runs on the same engine as the rest of your cloud.
- 05
The agents are audited.
Scoped MCP tokens per organisation, every tool call logged and quota-tracked. You can answer what an AI agent asked your systems for, and when.
Questions worth asking us.
Not the one you came with? Ask it directly and we will answer it in writing.
How do you detect AI tools you have never heard of?
Classification is driven by application feature tags in the catalogue, so a new tool inherits the classification of what it does. The browser extension supplies the domains, the identity provider supplies the sign-ins, and the connectors supply the authoritative user lists for anything already sanctioned.
We want to encourage AI use, not police it. Does this get in the way?
The dashboard ranks adoption, which is as useful for sponsorship as for restriction. The tool 41% of your organisation already uses is a negotiation opportunity. Status is managed, blocked or ignored: three answers, of which two are yes.
What exactly is the MCP piece?
Every CerteroX product exposes a Model Context Protocol server, so your AI agents can query the asset inventory, the cloud bill and the licence position directly. Tokens are scoped per organisation and every tool call is audited and quota-tracked, which means the agent has a permission model and a log like any other identity.
Does this handle AI spend inside tools we already pay for?
That is the case the hardcoded lists miss entirely. Because classification is by feature, an existing application that ships an AI capability is reclassified in the catalogue and appears in the Shadow AI view with its adoption share, even though nothing new was ever purchased.
Where does the GPU and training cost data come from?
The same collectors as the rest of your cloud footprint, across AWS, Azure, Google Cloud, Nebius, Kubernetes and Databricks. Above that sits the experiment layer: ML task, run and runset tracking, custom metrics, and Spark instrumentation via the Delight agent collector.
You already have AI
in production. See how it surfaces.
Shadow AI ranked by adoption share, OAuth grants with data access, agent tool calls on the audit trail and GPU spend against an owner: four governance problems, one populated AI position. Tell us which assistants worry you most.
A policy written against a real inventory is a policy people follow.