Shadow AI is not evenly distributed. Each department gravitates to its own tool types, feeds them its own data, and leaves its own signature in the logs. All examples generic-safe, drawn from patterns audits surface repeatedly.
See your own department map freeFor each: the tool types that appear, the data at stake, and the shape of the log evidence that gives it away.
The audit's category table is this page applied to your network: each category total maps to the department that owns the conversation. The annotated report tour shows where to read it.
Some of the most consequential examples belong to no single department.
Invited once by one person, then auto-joining recurring invites across teams. Every department's confidential calls, one tool, one unclear consent state.
Leadership's own unsanctioned tools set culture harder than any policy memo. Executive per-user rows deserve the same review, delivered with more tact.
The CRM, the design suite and the video platform all shipped AI features after procurement approved them. Every department "uses AI" through door three without choosing to. The taxonomy lives on what is shadow AI.
These anatomies become your network's facts in three steps.
Export a month of DNS, proxy or firewall logs with the user or device column. The walkthrough shows where that column lives per source.
Each category with a real total gets the matching department head invited to the review. This page is the seating chart.
Where your patterns differ from the anatomy, that is your finding: engineering-shaped usage in finance means something worth asking about.
The audit reads hostnames and identities, never prompt content. Uploads are discarded after each run and reports are deletable before the 90-day expiry.
The sample report's category table and per-user rows are this page rendered as evidence, on sample data.
The same finding lands differently per department. Openers that keep the meeting collaborative:
"Which of these tools would you keep if we paid for proper licenses?" Consolidation framed as an upgrade, not a confiscation.
"Which of these are load-bearing in the pipeline?" Respecting the CI integration's existence buys honesty about everything else.
"Here is the training verdict on the tool the team uses for sensitive text." Terms, not blame, and the migration proposal in the same breath.
"The transcription bot heard 40 customer calls last month. Whose consent covers that?" A concrete number turns an abstract worry into an agenda item.
By tool count, usually marketing; by depth of use, engineering; by sensitivity per finding, HR. Your audit's category table gives your actual ranking.
They are generic-safe composites of patterns that recur across audits. No real organization is described, and the report you run contains only your own data.
Meeting transcription bots, because they attend rather than get used, and embedded AI features inside sanctioned SaaS, because nobody thinks of them as tools.
Run the audit with an identity column in the export. Department prefixes in usernames or per-team subnets turn the per-user table into a department map.
Yes, that is the point of category-level policy: image tools in marketing and code assistants in engineering deserve separate verdicts. See sanctioned vs unsanctioned.
Verify coverage before celebrating: that department may work off-network or through an unlogged path. An empty cluster with confirmed coverage is genuinely good news.
One export with identities shows which of these anatomies is yours. The free preview draws the category map today.
Run the free audit