AI Risk · Detect & respond
Discover the shadow AI that already has access to your company's data.
Your team connects AI tools to Microsoft 365 and Google Workspace with one click and broad permissions. Axyom enumerates those OAuth grants, classifies them against a catalog of AI apps and flags which ones ask for more access than they need.
The inventory lights up when you connect Microsoft 365 or Google Workspace.
What it is
The AI apps nobody has reviewed.
They are the AI tools someone at the company has connected to the corporate systems without security knowing. The permission is granted without downloading or installing anything: a one-click OAuth grant hands over access to email, calendar or files, and neither side ever looks again.
Someone in operations authorizes a meeting assistant to take notes and grants it the whole calendar. Someone in sales connects an assistant to the mailbox to draft replies faster. Neither authorization goes through security, because the OAuth flow is designed so it does not have to.
That permission stays alive when the tool is no longer used and when the person leaves the company. Almost nobody looks at it until an incident arrives or a large customer's security questionnaire does, and then you have to answer which AI tools process company data, with which permissions and since when.
5
read permissions in Microsoft 365
9
read permissions in Google Workspace
4
actions assignable per finding
6
counters that prove each pass
- What it is
- An inventory of the AI apps with live permissions over your email and your files, classified against a catalog and prioritized by the access they ask for. Every row arrives with its finding and its action.
- Who it is for
- Companies of 10 to 250 employees with Microsoft 365 or Google Workspace and AI use without a written policy. If your team connects new tools every month, here you see which ones hold permission over your data.
- Where it's included
- In the Base plan, and it stays on in Pro and Max. The Free plan does not include an AI app inventory, because it needs the Microsoft 365 or Google Workspace integration.
- What we need
- Administrator consent on Microsoft 365, or a Super Admin in Google Workspace. All the permissions we ask for are read-only and none of them opens the contents of mailboxes or files.
- Cadence
- Each pass leaves its date and the number of items reviewed. You can request a review from the portal with the integration active; check the available schedule in your account.
What each pass inventories
Everything an AI app can reach.
One row per connected app, with the exact permission you granted it and the finding it has generated.
- Delegated grants
- Which app holds a permission granted by a user of your Microsoft tenant, and with what scope.
- Application permissions
- The permissions an app holds over the whole tenant without depending on any user.
- Tokens per user
- In Google Workspace, the directory is walked user by user, reading the granted tokens.
- Scope over email
- Which apps can read or write in the mailboxes, with the exact permission they were granted.
- Scope over files
- Which apps reach Drive or SharePoint, and whether the permission is read or write.
- Calendar and meetings
- The meeting assistants that receive the whole calendar to take notes.
- Catalog classification
- What the catalog says about each app: sanctioned, unapproved, excessive permissions or high risk.
- Uncataloged apps
- Apps that ask for sensitive permissions and give themselves away as AI by name or publisher; they await human review.
- Data residency
- What the catalog states about where each app processes data, with its provenance and its confidence.
Every classification arrives with its confidence written into the finding. A match by application identifier is firm; one by publisher domain counts as a hint.
Sample inventory · Fictitious apps and data
- High
- Meeting assistant · Google Workspace · calendar.events, drive.file · review scope
- High
- Document assistant · Microsoft 365 · Files.ReadWrite.All · review granted permission
- Medium
- Email assistant · Google Workspace · gmail.readonly · review approval
- Pending
- Uncataloged assistant · Microsoft 365 · human classification pending
- Reviewed
- Development assistant · use and permissions reviewed by the company
Trust
Which permissions we ask for and what we do not touch.
A module that asks for access to your email in order to tell you who has access to your email deserves the full list up front.
Permissions
Five in Microsoft, nine in Google
In Microsoft 365 we ask for five read-only permissions: applications, directory, audit logs, risky users and policies. In Google Workspace there are nine: openid and email, five for reading the directory, one for identity policies and the one that lists the tokens granted by each user.
Inventory
What we inventory with those permissions
The first pass enumerates the delegated grants and the application permissions in Microsoft, and in Google walks the directory user by user reading the granted tokens. From there comes the list of apps, with their scope over email, calendar and files.
Scope
What we do not touch
Axyom reads who has granted what to whom, and none of the permissions we ask for opens the contents of mailboxes or files. Nor do we revoke grants or block apps. The change is carried out by your administrator in the Microsoft or Google console, with the evidence the portal leaves.
The list you are already being asked for
A large customer's security questionnaire usually asks which AI tools have access to company data, with which permissions and since when. The inventory provides that list and the counters of each pass say when it was reviewed. It is the starting point for documenting AI use and deciding its policy.
What each pass leaves behind
Three pieces you can show a customer.
The inventory
One row per connected app, with its real name, the originating provider, the permissions granted and their count, the severity and the reason for detection. Opening the row takes you to the finding's detail.
Action and owner
“Review the grant” is the default action for unapproved apps and excessive permissions, and “Recommend blocking” for high-risk ones. The remaining actions are “Approve with conditions of use” and “Notify users”. The default owner is your IT team.
The counters
Each pass leaves grants reviewed, apps reviewed, application permissions reviewed, users reviewed, users failed and findings issued. They serve as proof for an auditor or a customer who asks about the last review.
Where it fits in the platform
The basis of the AI systems register.
The AI app inventory goes into the file with the rest of the posture, so the finding of a live grant reads alongside that same person's leaked credential and alongside the framework control that captures it. Axyom Agent answers questions about it in the portal and in Slack, and the decision to approve an app with conditions of use is recorded with its owner.
Continuous Compliance
The inventory feeds the AI systems register and the answer to the supplier questionnaire.
Learn moreThreat Intelligence
A leaked credential of someone with live grants opens everything those apps reach.
Learn moreAxyom Agent
Ask it which AI apps have access to your files and it answers in the portal or in Slack.
Learn moreLimits
What AI Risk does not do.
Check the scope before turning on the module and coordinate with your team the actions that fall to them.
It does not revoke or block
The module detects, classifies and prioritizes, and its part ends there. The change is carried out by your administrator in the Microsoft or Google console.
Microsoft 365 and Google Workspace only
The module needs one of those two integrations active to produce data. Other suites are outside the inventory.
It sees the permission granted
It knows which app has been granted access and to what. It does not measure how many documents the app has read or what data it has taken out.
It does not cover AI without an OAuth grant
Someone pasting data into a chat from their browser creates no grant and does not appear here. The module covers AI connected with live permissions.
It does not look inside mailboxes or files
The permissions we ask for read configuration and grants. The contents of email, calendar and files are outside our reach.
It does not replace an AI use policy
The inventory says what is connected and with which permission. Writing the policy and deciding what gets approved is your management's job.
Sized for companies like yours
The per-pass caps are designed for companies of 10 to 250 employees. For tenants far above that size, a custom scope.
Classification confidence varies
A match by application identifier is firm and one by publisher domain is a hint. Every finding says in writing which of the two it is.
Plans
AI Risk comes with the Base plan.
The Free plan covers only the external surface. The AI app inventory lights up when you connect Microsoft 365 or Google Workspace, and stays on in Pro and Max.
Free
To see your real risk before deciding anything.
No cost · No card.
Everything to get looking:
- Continuous scan External surface, 24/7
- Posture and risk map Real-time CyberScore
- Leaked credentials Counted, no detail
Base
For companies that want the whole platform without a security team of their own.
Self-serve · No commitment.
Everything in Free, plus:
- Integrations Microsoft 365, Google Workspace and cloud
- AI risk Apps with permissions over your data
- Prioritized backlog Monthly remediation
- 1 domain Continuously scanned
Pro
For teams that need every sensor active and an expert behind it.
Advisor on escalation · No commitment.
Everything in Base, plus:
- Security advisor On escalation, with SLA
- Threat Intelligence Exposed credentials, under watch
- Recurring pentesting Authenticated, report reviewed by Axyom
- MDR 24/7 Up to 20 managed devices
- Up to 5 domains All continuously scanned
Max
For high exposure or compliance demands.
Dedicated advisor · No commitment.
Everything in Pro, plus:
- Dedicated security advisor A fixed person, monthly session
- Priority response Incidents
- Compliance by framework Downloadable evidence and attestation
- Audit support Customer questionnaires and due diligence
FAQs.
Can you read our email or our files?
The permissions we ask for read configuration and grants: applications, directory, audit logs, policies and the list of tokens granted by each user. None of them opens the contents of mailboxes or files.
Does Axyom revoke a dangerous app's permissions?
At this stage the module is read-only: it detects, classifies and prioritizes. The change is carried out by your administrator in the Microsoft or Google console, with the finding and its evidence in front of them. It is declared that way in the catalog and on the portal screen itself.
What happens with an AI app you do not know?
If it asks for sensitive permissions, is not in the catalog and gives itself away as AI by its name or its publisher, it is marked as pending classification and awaits human review. We would rather have one row too many than wave through an AI nobody has looked at.
And people pasting data into a chat from the browser?
That creates no OAuth grant and does not appear in this inventory. The module covers what is connected to your systems with live permissions, which is what keeps having access when nobody is looking.
Is it useful for a customer's questionnaire and the AI policy?
The inventory provides the connected applications, the permissions granted and the date of the review. It helps prepare the security questionnaire and the AI use policy. Determining the applicable obligations requires reviewing the company's case.
Choose how to start.
On your own
Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.
With our team
Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.