Shadow AI & Agent Discovery System
Passive discovery of unsanctioned AI usage across the enterprise stack. Records only the unique usage needed for governance—no raw payloads stored. Extracts operational context to a clean governance state.
Works with every shadow ai discovery
See Shadow AI Discovery in action
Watch Gödel discover unauthorized AWS Bedrock Agents, self-hosted models on Kubernetes, and unsanctioned model endpoints—reducing raw signals to clean, actionable governance states without storing sensitive prompts.
Passive Discovery Connectors
Seamlessly ingest passive metadata across Cloud AI Platforms (AWS, Azure, GCP), Gateways (LiteLLM, Cloudflare), Network Proxies (Zscaler, Palo Alto), and VPC flow logs without storing raw prompts or payloads.

AI Registry & Sanctions Governance
Manage organization-wide sanction decisions across discovered AI providers, foundation models, and local inference runtimes with deterministic enforcement rules.

The Sanctions and Governance Model.
Once Shadow AI or an unknown agent is discovered, Atlas applies its global sanctions model to govern usage effectively.
Provider Sanctions
Apply to a specific API, cloud platform, or local runtime.
Model Sanctions
Global across all providers. For example, sanctioning Llama-3 applies whether it is hosted on AWS, Azure, or locally.
State: Undecided
Newly discovered, unknown AI providers and models are placed in the Authorization Queue for review.
State: Unsanctioned
Generates a violation when usage is detected. Built-in providers headquartered in high-risk regions can default to unsanctioned.
Six ways data walks out.
Six verdicts before it does.
Real traces from the enforcement path. Every action is attributed to its user and agent identity, checked against the data it actually touches, and decided in under 5 ms — locally, before the payload leaves the process.
Unapproved AWS Bedrock Agents
UNDECIDEDAWS Bedrock Connector → bedrock:ListAgents
Engineers spin up unapproved AWS Bedrock Agents. Atlas discovers the new agents via scheduled API sync and places them in the Authorization Queue for review.
Self-Hosted Model on Kubernetes
UNDECIDEDK8s Discovery → Self-Hosted HuggingFace
An agentless K8s cluster scan detects a pod running an unknown local model. Operators review the findings and can sanction it for internal testing.
Shadow API Usage on Corporate Device
UNSANCTIONEDPalo Alto Networks → api.anthropic.com
Developers use personal API keys to query Claude directly. HTTPS logs flag the outbound traffic, which is marked Unsanctioned as it violates enterprise agreements.
Detected in milliseconds,
on the endpoint.
Detection runs in milliseconds across cloud APIs, gateways, network telemetry, and local infrastructure. Atlas extracts only operational context to govern usage — zero raw chat payloads or streams are stored.
Cloud AI Platforms
Direct API telemetry across managed cloud AI infrastructure
| Connector | Type |
|---|---|
| Cloud API | |
| Cloud API | |
| Cloud API |
AI Gateways & Proxies
Traffic inspection through corporate AI routers and reverse proxies
| Connector | Type |
|---|---|
| Gateway | |
| Router | |
| Reverse Proxy |
Internet Access & Security
Egress monitoring across Secure Web Gateways and live DNS
| Connector | Type |
|---|---|
| SWG / NSS | |
| Zero Trust | |
| Live DNS | |
| Firewall | |
| CASB |
Infrastructure Discovery
VPC packet flow logs, cluster scanners and native host daemons
| Connector | Type |
|---|---|
AWS / Azure / GCP VPC Flow Logs | VPC Flow |
| K8s Daemon | |
| Host Daemon |
Connectors span multiple vectors to ensure a complete mesh of discovery.
The 4 core controls,
working on this outcome.
Discovery isn't an isolated scanner. Every phase feeds continuous posture into our policy and sanctions engine.
Ingestion
Connectors ingest raw source metadata from DNS queries, network flows, cloud APIs, and proxy logs across your infrastructure.
Normalization
Raw streams are buffered in-process and normalized into standard observations. Buffers are transient and emptied on restart to protect privacy.
Detection
The Axum API analyzes normalized observations to identify specific AI Providers, Foundation Models, and Agent Frameworks in use.
Governance State
Observations are reduced to a unique (provider, model) finding and linked to the host device and user, ready for policy enforcement.
End-to-End Discovery Pipeline
A strict four-step reduction process: raw source metadata is buffered in-process, normalized into standard observations, mapped to 162+ foundation models, and attributed to the host user.
Explore other use cases
Put a gate in front of every shadow ai discovery.
Local-first enforcement, deployed in minutes. Your agents keep shipping — the unsafe actions don't.