What discovery actually finds
Egress and identity telemetry reveal three populations: individuals using consumer assistants for work content, engineering teams calling model APIs directly with corporate credentials, and third-party SaaS features that forward customer data to a model provider under a subprocessor agreement nobody reviewed.
The third population is usually the largest data-protection exposure and the least visible, because the traffic goes to a vendor already on the allow list.

Classify the content, not just the destination
Destination-based policy produces a binary decision with no business context. Classifying submitted content — source code, customer records, financial data, health data — makes it possible to allow the majority of usage while stopping the specific categories that create regulatory liability.
- Per-request classification of submitted content where inspection is lawful and configured
- Identity and business-unit attribution for every session
- Subprocessor mapping for SaaS features that forward data to model providers
Provide a sanctioned path before enforcing
Every enforcement program that lacks an approved alternative produces circumvention through personal devices, which removes visibility entirely. A sanctioned gateway with logging, retention control and data-residency guarantees converts shadow usage into governed usage.
Enforcement then targets a narrow, defensible set: unsanctioned destinations for classified data categories, with a self-service exception path and a published review time.
- Sanctioned gateway with logging, retention and residency controls
- Enforcement scoped to classified data categories, not to tools in general
- Exception requests answered within a published service level
