The board will ask, if it has not already. The difference between a difficult meeting and a routine one is whether you answer with adjectives or with an inventory that has a date on it. This page is the playbook for the second kind of meeting.
"Are we exposed?" decomposes into four questions a report answers with numbers. Present these, and the conversation becomes governance instead of reassurance.
Metric: tools found, total and per category. The first baseline usually lands 2 to 4 times above anyone's guess, which is why you run it before the board asks, not after.
Metric: high-risk count, training-exposure count and the abusive-purpose tile. Zero abusive tools, with evidence, is a slide worth showing; non-zero is a same-day action you report as handled.
Metric: sanctioned share. The percentage of observed AI usage flowing through tools you contracted and listed. This is the number that trends, and trends are what boards actually govern by.
Metric: the deltas. New tools since last quarter, blocked tools showing attempts only, verdicts that changed. Four consecutive reports make this a one-glance story.
Deck discipline: these four metrics, one slide, every quarter, same format. The annotated report tour maps each metric to the section it comes from.
You have vendors pitching agents, extensions and platforms for this. The log audit is the move that costs nothing to start and strengthens every later purchase.
The board's question is about the present and the past. Only log evidence answers retroactively; every deployed sensor starts from zero on install day.
A $99 report scoped by facts beats a platform bought on fear. When you do buy depth later, the audit's findings write the requirements. The methods comparison is the vendor-meeting cheat sheet.
Dated window, stated method, repeatable on demand: the same properties your auditors want are the ones that make the board trust the trend line.
And it is easy to defend internally: hostnames and identities only, no prompt content, uploads discarded after each run, reports deletable. The works council conversation is short.
| Week | Move | What you can now say |
|---|---|---|
| 1 | Free preview on 30 days of DNS or proxy logs, then the full report. | "We have a dated inventory. Here are the four numbers." |
| 2 | Abusive flags blocked; triage meeting sorts the rest into sanction, control, block. | "Immediate risks are closed. The plan for the rest is minuted." |
| 3 | Top tools move toward enterprise tiers; sanctioned list drafted with a request path. | "Legitimate demand is getting a legitimate outlet." |
| 4 | Remaining blocks placed with published reasons; next audit scheduled. | "The loop is standing. Next quarter you see the trend." |
Weeks 2 through 4 are the sequence argued on detect before you block. The 30-day shape holds from 100 to several thousand seats.
The CISO's real job with the report is distribution. Each audience gets a different slice.
The four-metric slide plus one sentence of interpretation. Attach nothing; offer the PDF to whoever asks. Confidence comes from the format repeating every quarter.
The tool table with training verdicts and sovereignty flags. They will turn it into DPIA priorities and contract asks; the GDPR page shows their read.
The CSV and the block list with cited reasons. Their loop is configuration and the verification re-run; the per-platform guides carry the mechanics.
Their category rows and their team's usage, framed as consolidation offers rather than accusations. This is where sanctioned-share growth is actually won.
Three pages: the tiles page for the board, the inventory page for IT, the evidence page for compliance. Sample data, real format.
Three objections CISOs hear when proposing the cadence, with responses that have worked.
Keep it; it governs sanctioned SaaS well. The audit sweeps the long tail your catalog has not classified and supplies dated training verdicts for vendor reviews. They compose, and the audit is the cheap half.
Hostname-level evidence reads which tools were reached, never what anyone typed. Publish that scope, use findings for coaching and consolidation, and the trust cost stays near zero.
Free preview to scope, $99 per report, packs at $60 to $66, plans for monthly cadence. The whole year of evidence costs less than one vendor lunch-and-learn; see pricing.
The four-metric slide from your first full report: tools found, high-risk count, sanctioned share, and the actions already taken. Lead with the abusive-tools answer.
One log export from whatever you already run, uploaded to the free preview. Totals in minutes, full report the same afternoon if warranted.
Quarterly, same window, same slide format. Consistency is what turns numbers into a governance narrative.
Cyber questionnaires increasingly ask about AI usage controls. "Quarterly log-based audit, reports on file" answers the row, with PDFs as attachments.
First reports always look bad; that is why they exist. The board story is not the baseline, it is the slope you show next quarter.
One person, twenty minutes per quarter for the mechanics. MSPs also deliver it as a service if you outsource operations; see the MSP page.
The next board pack can contain a dated inventory instead of adjectives. It starts with one log export this week.
Run the free audit