top of page

How to Discover Every AI Tool Your Employees Are Using in Under an Hour

Most organizations estimating their AI footprint do so by surveying employees or reviewing recent procurement requests. Neither method produces a reliable answer. Surveys depend on memory and self-disclosure; procurement records reflect only the AI tools the finance team has approved. The actual population of AI in use almost always exceeds both numbers, often by a factor of five to ten.

This article describes a focused 60-minute exercise to produce a defensible inventory of AI usage across your environment. The method draws on four data sources that, taken together, capture the overwhelming majority of real AI activity. It assumes administrator access to your identity provider, your mail and calendar workspace, and your finance system.

Step 1: Export the OAuth grant inventory from your workspace

The single most productive data source is your workspace's OAuth grant list. Most AI assistants and AI-enhanced productivity tools authenticate via "Sign in with Google" or the equivalent Microsoft Entra flow, leaving a persistent token bound to a corporate identity.

In Google Workspace, navigate to Admin Console → Security → Access and data control → API controls → Manage Third-Party App Access. Export the full list. In Microsoft 365, query the Microsoft Graph API for enterprise applications and delegated permissions, or use the Entra portal's Enterprise Applications view. Filter for grants issued in the past 24 months and flag any whose vendor name, scopes, or category suggest AI capability.

Step 2: Search mail metadata for signup and notification traffic

Even where AI tools were adopted outside the identity provider, signup confirmations and product notification emails almost always reach a corporate mailbox. Use your mail platform's eDiscovery or content search to find subject-line patterns such as "Welcome to," "Verify your email," "Your trial has started," and "Invoice for" — restricted to a list of known AI provider domains. Public domain lists for popular AI vendors are easy to assemble. The resulting matches reveal AI accounts that exist under your domain even when OAuth was never involved.

Step 3: Reconcile against your expense and procurement systems

Pull credit-card and expense-report transactions for AI vendor names over the past 12 months. This includes paid plans, prosumer tiers, and individual subscriptions that may have been reimbursed. Cross-reference any matches with the OAuth and mail evidence to establish which accounts are paid, which are free, and which have already been deprovisioned.

Step 4: Audit embedded AI features in approved SaaS

The fastest-growing AI footprint in 2026 is not standalone tools but features enabled inside SaaS applications already in your stack. For each of your top 20 most-used SaaS apps, log into the admin console and review the feature settings related to AI summarization, copilot assistants, generative writing aids, and meeting transcription. Document which features are enabled, the data they process, and whether prompts are retained or used for model improvement under the vendor's current terms. A companion guide on SaaS-side AI training covers this dimension in depth.

Step 5: Consolidate, classify, and assign owners

Merge the four data sources into a single spreadsheet. For each AI surface — standalone tool, OAuth integration, or embedded feature — record the discovery source, the corporate identity associated with it, the data classes involved, and a preliminary risk rating against your existing data-handling policy. Authoritative references such as the NIST AI Risk Management Framework and the OWASP Top 10 for LLM Applications can inform consistent risk categorization; broader SaaS governance principles in the Cloud Security Alliance's SaaS Governance research apply equally to AI integrations.

A faster, continuous alternative

The manual exercise above is valuable as a one-time baseline. It is not sustainable as a continuous program — the inventory becomes stale within weeks as new tools are adopted and new features are enabled. Waldo Security's SaaS Discovery performs the same correlation across mail signals, OAuth grants, and identity data continuously and agentlessly, including the embedded AI features inside the SaaS apps you already license. Organizations adopting it typically find that their internal AI estimates were short by 60 to 80 percent. See also the broader Shadow AI discovery walkthrough for additional context.

To see the live picture of AI usage across your environment, request a demonstration. The initial report is typically available within 24 hours of connecting your identity provider.

Comments


bottom of page