Triaging discoveries
Each row in the Shadow AI queue is something observed in your estate. Work through them top-down — AI matches are listed first.
What the AI label means:
- AI (catalogue match) — the app matched our AI-tool catalogue by domain or name. The most confident signal.
- Defender: AI — your Microsoft Defender report tagged it as "Generative AI"; we surface that even if our catalogue doesn't list it.
- AI? — suggested by the AI classifier (if you've enabled the Shadow AI classification feature). Hover for the rationale.
- not AI / — — classified as not AI, or not yet assessed.
Triage actions (per row):
- Link to a vendor — connects the find to a vendor record so it enters your vendor lifecycle. If a vendor with that name already exists we link to it; otherwise we create one (status Prospect) with a note that it came from discovery. The queue flags "vendor exists — will link" when a match is detected.
- Sanction — mark it as a known, accepted tool.
- Ignore — dismiss it (e.g. a false positive or out-of-scope app).
- Reopen — return a triaged item to New.
Classify unmatched with AI: if the Shadow AI classification feature is enabled (Settings → AI features), a button lets the AI assess catalogue misses and suggest whether each is AI. It only annotates the row — it never creates a vendor or changes a status. You still triage.
Re-importing or re-syncing a source refreshes what's been seen (last-seen, counts) and never overwrites your triage decisions.