For IT managers

Find out what AI tools employees use, with what you already own

No new vendor onboarding, no agents, no project code. You own the log console; that is the entire prerequisite. Twenty minutes from export to a per-user inventory, and the first pass is free.

0 installsreads exports your stack already produces
10 sourcesUmbrella to Squid, plus any CSV with headers
Per userwhen your export carries the identity column
Freepreview with real totals before any spend
The operator's timeline

Twenty minutes, honestly accounted

The practical end-to-end, from a console you know to a report you can forward.

MIN 0-8

Export 30 days from your DNS filter, proxy or firewall. Allowed traffic, identity column in. This is the longest step, and the per-vendor guides pin the exact fields.

MIN 8-10

Register with an email, drag the file onto the upload panel. The parser announces format and line count before running.

MIN 10-13

Matching runs against 20,399 classified AI domains. The upload itself is discarded. Free preview shows all totals plus the top tools named.

MIN 13-20

Read the tiles, count the masked rows, screenshot for the ops channel. Decide whether the full $99 report is warranted; most first runs answer that themselves.

Your console's five minutes: Umbrella, Zscaler, Palo Alto, FortiGate, SonicWall and five more, each with the export shape and sample lines.

What you get back

The report, read like an operator

Less "risk narrative", more "what do I do at the console". The sections in the order you will actually use them.

The tool table, sorted twice

Once by risk for the block candidates, once by users for the procurement conversation. Both sorts come from the same CSV that ships with the full report.

The per-user table

Who reached what, with hit counts. Service accounts touching AI hosts are the sleeper finding: that is an integration someone built without a ticket.

The block-ready list

Abusive and block-verdict domains, exact hostnames including api. and cdn. hosts, ready to paste into a custom category or blocklist.

Scope you can state in one line if anyone asks: hostnames, identities and timestamps only, no prompt content, upload discarded after the run, report deletable.

Career math

Why this is the highest-leverage twenty minutes this quarter

Three situations where having the inventory already run changes your week.

When leadership asks

"What AI do we use?" lands on IT first, always. Answering same-day with a dated PDF, instead of promising a project, is how operators get remembered at budget time.

When something leaks

The moment a paste-into-chatbot incident surfaces, the first question is scope. A standing inventory turns a panicked week into a targeted afternoon.

When the renewal lands

Vendor consolidation talks go differently when you know four teams already pay for overlapping AI tools out of expense budgets nobody compared.

The eventual escalation path also starts here: the same report that serves you feeds the CISO's board slide. The CISO page shows where your twenty minutes end up.

No-new-vendor math

What "no onboarding" actually saves

Compare the paths to your first real AI inventory.

PathTime to first dataProcurement involvementWhat it covers on day one
Log auditToday, ~20 minutesNone for the preview; $99 fits most card limitsFull history of the logged network, retroactively
Endpoint agent rolloutWeeks to monthsFull cycle, security review, pilot groupManaged devices only, from install day
CASB / SSE moduleA quarter, optimisticallyPlatform negotiationBrokered traffic, catalog-known apps
SurveyTwo weeks of chasingNoneWhat people admit remembering

The longer comparison, including when the heavier options genuinely win, is on the detection methods page.

See what a finished audit looks like

Three pages of sample data, including the per-user table and the block-ready tool list. If it looks useful, your own version is twenty minutes away.

Open the sample PDF
After the first run

The operator's loop, quarterly

Configure from the CSV

Block-verdict hostnames into your filter's custom category, sanctioned tools toward SSO. An hour of console work with the list open.

Re-run to verify

Same window next month or quarter. Blocked tools should show attempts only; if allowed hits persist, you found a bypass path for free.

Report up in four numbers

Tools found, high-risk, sanctioned share, delta. Whoever you report to, that line fits their format. Costs stay flat: pricing.

FAQ

IT manager questions

Do I need approval to run the free preview?

That is your call and your org's policy. Many operators treat it like any other log analysis: existing data, existing access, read-only output. The one-line scope statement above usually settles it.

Which export should I start with?

Whichever console you can reach fastest. DNS filter logs are usually the one-click option; the walkthrough has the per-source cheat sheet.

What if my logs have no usernames?

You still get the full tool inventory with per-IP attribution. DHCP reservations make the IP table readable enough for most decisions.

Will this generate work I do not have time for?

It generates a short block list and a shorter procurement list. Both replace diffuse worry with an hour of defined console work.

How big can my export be?

Free: 5,000 lines or 2 MB. Full report: 2,000,000 lines or 25 MB, larger on request via contact.

What does the paid report add over the preview?

Every tool named instead of a fifth, the per-user table, the sanctioned split and the CSV. The free audit page has the exact split.

You are one export away from knowing

The console is already open in another tab. Twenty minutes from now, the guessing is over.

Run the free audit