10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Start free

See Every AI Tool Touching Your Org — Sanctioned or Shadow

The 8200.dev Team8 min read

Somewhere in your organization right now, an employee is using an AI tool you have never heard of. Maybe it is a personal DeepSeek API key pasted into a side project. Maybe it is Perplexity connected to a work Google account. Maybe it is something considerably more capable: an autonomous agent platform holding standing OAuth access to Notion, Gmail, and GitHub, doing multi-step work on that employee's behalf — and on your data.

Until today, 8200.dev surfaced all of this — but in pieces, scattered across the general findings feed. Today we are shipping AI Governance: a unified dashboard section that answers one question in one place — what AI is running in your org, and is it governed?

What actually changed

Here is the honest framing, because honest framing is the product: AI Governance is an aggregation layer, not a new scanner. Every detection it shows existed in the engine before today. What is new is that they now tell one coherent story instead of appearing as isolated findings, plus a set of new per-member depth rules described below. Nothing about this release collects new data, adds a scope, or touches anything it could not already see. If you have connected sources, the page is already populated.

The dashboard organizes what the platform knows into six areas:

1. Shadow AI discovered through OAuth grants. Some AI vendors cannot be governed at all — not because you have not bought the right tier, but because no organizational admin surface exists. DeepSeek offers a personal API-key console and nothing else: no SSO, no audit logs, no member management. Moonshot's Kimi is the same — and independent research (Harmonic Security, January 2026) found enterprise Kimi usage volume actually exceeds DeepSeek's, making it the larger real-world shadow-AI channel of the two. Grok's API is inference-only. Perplexity's enterprise administration is UI-only. For these vendors, the only governance lever that exists anywhere is detection: 8200.dev fingerprints their OAuth grants in the workspaces you connect and tells you which employees wired them in.

2. Agentic platforms on elevated watch — the Manus story. Manus deserves its own paragraph, because it is a different class of risk. Manus is an agentic orchestration platform: it does not just answer questions, it executes multi-step autonomous tasks, and to do that it holds delegated OAuth connections into the tools your organization runs on — Notion, Gmail, GitHub, Google Workspace. A Manus grant in your OAuth inventory is not "an app an employee tried once"; it is a standing, autonomous actor with real reach, and if the platform is ever breached, over-permissioned, or misdirected, that grant is a direct lateral-movement path into your workspace.

The company's history is worth knowing when you weigh that risk. Manus launched in 2025 out of a Chinese startup (Butterfly Effect) and, as was widely reported at the time, relocated its headquarters to Singapore amid US regulatory scrutiny of its American-led funding round. In 2026 it was briefly acquired by Meta — a deal that was unwound in June 2026, leaving Manus operating independently with a large and fast-growing enterprise customer base. None of that history makes Manus malicious. All of it makes Manus a vendor whose access to your organization deserves deliberate governance — and here is the catch: Manus exposes no public admin API. No connector-grant audit, no member list, no activity log an outside platform could read (its e-discovery interface is gated to enterprise customers through customer success). What Manus does with its access is not independently auditable today. That is why 8200.dev classifies it as an *agentic connector* on elevated watch: the OAuth-grant signature detection we ship is, as far as we know, the only independent coverage that exists — and we say exactly that in the finding, rather than implying more.

3. Vendor AI-training posture. Does each platform you connect train AI models on your data by default? As we documented in our research across 17 SaaS platforms, not one exposes this as an API-queryable setting — the posture lives in contracts, regional defaults, and plan tiers. The AI Governance view surfaces the researched, dated posture for every platform you have connected, so the answer sits next to your live findings instead of in a vendor PDF nobody opens. (The Atlassian data-contribution deadline is a live example of why this belongs on a dashboard.)

4. Governed AI vendors — the five real connectors. Where a vendor does expose an admin API, 8200.dev connects to it properly. Five AI vendors have first-class connectors today: Mistral AI, OpenAI, ChatGPT Enterprise, Anthropic, and Cursor — part of the platform's 23 connectors overall. These read (read-only, always) the governance surface each vendor actually offers: API keys and their last use, members and roles, seats and per-seat activity, spend limits, audit-log configuration, daily usage.

5. Per-member elevation depth — new in this release. The one genuinely new rule logic shipping with the dashboard: flagging a *specific member* whose API access outlived their role. On Mistral, OpenAI, and Anthropic, the connector already reads members, roles, and key ownership — so the platform now flags an active org-wide API key owned by a member whose current role is no longer a privileged tier. That mismatch almost always means someone was demoted or role-scoped after minting the key: the seat was tightened, the credential was not, and no seat review will ever show it. On Cursor, the same idea runs over the server-side audit log: a plain member seat performing admin-level actions (membership, roles, billing, keys) without the owner role.

And where the data does not genuinely exist, the rule does not exist either. ChatGPT Enterprise's compliance-log surface has no member or key inventory to derive an elevation mismatch from — so instead of inventing a rule that could never fire, the dashboard surfaces the honest signal it does have: whether your compliance-log export is enabled and producing evidence at all (OpenAI retains those logs for only 30 days; every silent day is audit evidence permanently lost). Cursor's audit stream depends on your plan tier — when it is unavailable, the rule stays quiet instead of guessing.

6. GitHub Copilot governance. Copilot policy and seat hygiene — public-code matching, departed members holding seats, seats nobody uses — rounds out the picture, because for most engineering organizations Copilot is the highest-volume AI tool of all.

What this is not — on purpose

8200.dev's AI Governance is point-in-time posture, read from vendor admin APIs and OAuth-grant metadata, read-only by default. It does not intercept network traffic. It does not proxy, log, or inspect prompts. It never reads message or file content. The dashboard states this on the page itself, because a governance product that is vague about its own access has no business scoring yours.

We think that boundary matters more in AI governance than anywhere else. The market is filling with tools that answer "what AI is running here?" by putting themselves in the traffic path — an approach with real capabilities and real costs (a new inline dependency, a new data concentration point, a new thing to trust). Our answer is deliberately different: govern what can be read from the surfaces vendors officially expose, be exhaustive about those surfaces, and be explicit about what no one can see. When a vendor offers no surface at all — DeepSeek, Kimi, Grok, Perplexity, Manus — we say "detection is the only lever that exists," and we ship the detection.

Why this matters right now

The regulatory direction of travel is not subtle. The EU AI Act phases in obligations through 2026–2027, and deployer-side accountability — the idea that the organization *using* AI answers for it, not just the vendor that built it — keeps hardening in courts and state rules, as we covered in our analysis of AI agent liability. Frameworks and auditors increasingly expect you to demonstrate you know what AI touches your data and that access is reviewed. The AI Governance view supports exactly that kind of audit-trail documentation: findings feed the same compliance console as everything else and map to access-control and vendor-management control areas in frameworks such as SOC 2 and ISO/IEC 42001. To be precise about what that sentence means: it is a factual control-area mapping that can support your evidence gathering — it is not a certification, and connecting 8200.dev does not make anyone "EU AI Act compliant." Anyone who tells you a dashboard can do that is selling something else.

Where to see it

The section lives in the app at AI Governance, next to your findings. It is available on every plan, including free — because the "what AI is running here?" question is the beginning of the conversation, not an upsell gate. The features page shows how it fits the rest of the platform, and the AI agent governance use-case covers the broader agent story — detection, access mapping, and enforcement.

If you have never connected anything: the free tier takes a few minutes, needs no sales call, and starts with read-only scopes you can revoke at any moment. Your first AI Governance view — including whatever shadow AI is already wired into your workspace — is one connect away. Start free.

ShareX / TwitterLinkedIn

Related articles