An IT lead sees an AI application in a device report, a connection to an AI service in a network report and a declared use in the organisation's AI register. These may be unrelated. Start with a smaller question: what did each source observe, for whom and when? A missing record cannot establish that no AI use occurred.
Four questions that need different evidence
What activity was reported? Record the exact device or network signal, asset or path, period and collection scope. The report does not establish business purpose.
Was the use approved? Check the approval record and its scope with the business owner. A register entry can name a declared use, owner and approval reference. It cannot discover undeclared use or prove that current activity fits the approval.
What access was granted? A device or network signal does not list an identity's permissions. Check the relevant access or consent record under the organisation's authority; until then, access is unknown.
Was a restriction applied and verified? Policy configuration, deployment and observed effect need separate evidence. A discovery report proves none of them. Verify the intended scope and result through an authorised process before calling a restriction enforced.
Compare the sources before combining them
| Source | What it can contribute | What it cannot settle alone |
|---|---|---|
| Managed-device observation | A reported application or agent signal on devices covered by that source during its observation period. | Activity on other devices, what was entered into a tool, business approval, access grants or enforcement. |
| Network observation | Connections or usage measures for traffic that passed through the configured collection path and matched a service catalogue. | Traffic outside that path, prompt contents, sensitive disclosure, approval or a person's purpose. |
| Human-maintained AI register | Declared systems and uses, accountable owners, intended purpose and recorded review or approval information. | Undeclared use, current device or network activity, or whether a restriction is operating. |
Microsoft's Global Secure Access shadow AI discovery and Application Usage Analytics show catalogue matches and usage measures in traffic the service sees. Transactions and bytes do not reveal prompt text or prove sensitive disclosure. A path outside collection stays outside the conclusion.
Microsoft's Shadow AI page in the Microsoft 365 admin center is a Frontier public preview. On 28 September 2026, its prerequisites included preview opt-in, Defender for Endpoint, Microsoft 365 E5, Intune-managed Windows devices and an eligible role. Global Secure Access adds some metadata. Check current prerequisites and supported agents before relying on its coverage. These Microsoft examples do not establish a GovernSafe integration.
The Australian National AI Centre's AI systems register guidance covers systems, use cases and accountable people, including embedded AI. A register is guidance for declared use, not automatic discovery or a legal mandate.
A worksheet for one evidence record
Copy one record per source. Join records only when evidence supports the link.
| Field | Record |
|---|---|
| Source or report | Name, report ID or retained reference: ___ |
| Authorised organisation or client scope | Organisation or one client and the permitted review purpose: ___ |
| Covered assets or users | Named group, devices, identities or path; exclusions: ___ |
| Observation period | Start and end, with timezone; or a point-in-time snapshot: ___ |
| Collection date and time | When this record was obtained, with timezone: ___ |
| Stated lag or unavailable freshness | Source's stated delay and last update, or unavailable: ___ |
| Observation | The exact reported signal, with no extra inference: ___ |
| Unknowns and exclusions | Use the status terms below and state the unanswered question: ___ |
| Accountable reviewer | Role or named owner authorised for this review: ___ |
| Next verification | One permitted check, its owner and the decision it will inform: ___ |
Use distinct statuses: not observed in this source and period for no matching signal within collected scope; not collected when no report was obtained; outside scope for an uncovered person, device, path or period; unknown when evidence cannot answer the question. None means there was no AI use organisation-wide.
Worked example: three fictional records
All records below are fictional. Example Organisation has 120 people. Its seven-day review covers Managed Group A, one office network path and a human register. These are illustrative numbers, not GovernSafe or customer results.
Record D1: managed-device observation
| Field | Synthetic entry |
|---|---|
| Source or report | Device observation D1. |
| Authorised organisation or client scope | Example Organisation internal review; Managed Group A only. |
| Covered assets or users | 40 managed laptops in Group A; other devices outside scope. This is not a people count. |
| Observation period | 21 September 2026, 00:00 to 27 September 2026, 23:59 AEST. |
| Collection date and time | 28 September 2026, 09:00 AEST. |
| Stated lag or unavailable freshness | Unavailable; no ingestion delay or last-scan guarantee stated. |
| Observation | An AI application was reported on one in-scope laptop. |
| Unknowns and exclusions | Other in-scope device states, purpose, content and approval unknown; other devices outside scope. |
| Accountable reviewer | Endpoint reviewer for this internal review. |
| Next verification | Confirm device identity, scan time and signal; ask the business owner about approval within permitted scope. |
Record N1: network observation
| Field | Synthetic entry |
|---|---|
| Source or report | Network report N1. |
| Authorised organisation or client scope | Example Organisation internal review; office egress path A only. |
| Covered assets or users | Traffic on path A; distinct user/device count unknown; other paths outside scope. |
| Observation period | 21 September 2026, 00:00 to 27 September 2026, 23:59 AEST. |
| Collection date and time | 28 September 2026, 09:20 AEST. |
| Stated lag or unavailable freshness | Unavailable; no ingestion delay stated. |
| Observation | A connection to a catalogued AI service was recorded on path A. |
| Unknowns and exclusions | Prompt, disclosure, identity and approval unknown; other paths outside scope; activity there unknown. |
| Accountable reviewer | Network reviewer for this internal review. |
| Next verification | Confirm path coverage, period and permitted identity attribution; seek business context. |
Record R1: human-maintained register
| Field | Synthetic entry |
|---|---|
| Source or report | AI register snapshot R1. |
| Authorised organisation or client scope | Example Organisation declared-use register; no automatic discovery. |
| Covered assets or users | One declared use; undeclared uses outside the declared-use register's scope; their existence and activity unknown. |
| Observation period | Point-in-time snapshot, 28 September 2026; no seven-day activity log. |
| Collection date and time | 28 September 2026, 10:00 AEST. |
| Stated lag or unavailable freshness | Entry update date unknown; no automated freshness claim. |
| Observation | One declared use has an owner and a recorded approval reference. |
| Unknowns and exclusions | Approval scope/currentness, activity and enforcement unknown; undeclared uses outside the declared-use register's scope; their existence and activity unknown. |
| Accountable reviewer | Business owner for the declared use. |
| Next verification | Confirm approval reference, scope and open questions with the owner. |
Nothing links D1, N1 and R1 to one person or tool. Forty laptops in a 120-person organisation do not establish a percentage of staff using AI.
Investigate the open question
Confirm the triggering report's asset or path, period, collection time and lag. Separate observation from reviewer inference. Before using another source, check authority and whether asset, identity and period match. Ask the business owner about purpose and approval; check access and policy state in their own records. Name each follow-up owner and leave gaps open until evidence arrives.
For an empty collected report, record not observed in this source and period and its exclusions. If there is no report, write not collected.
If you review this for an MSP client
Agree each client's authorised scope, source access, reviewer and decision owner. Keep separate worksheets and outcomes per client. Client A's device observation cannot fill Client B's network gap, and their counts cannot be combined into a coverage claim. For an unavailable source, record not collected or outside scope and name the client's next check. This method grants no new data access or control-change authority.
Where GovernSafe fits
GovernSafe's public About page states: "See observed AI use on devices running the GovernSafe client. Broader agent ownership and approval workflows are on the roadmap." This worksheet is an educational method. The Microsoft examples do not establish GovernSafe coverage, approval decisions or enforcement.
Source notes
Sources checked on 28 September 2026. Recheck documentation before making a coverage decision. The records above are synthetic.
- Microsoft, Global Secure Access shadow AI discovery, updated 11 June 2026; network application discovery.
- Microsoft, Application Usage Analytics, updated 19 March 2026; usage measures.
- Microsoft, traffic forwarding profiles; collection path limits.
- Microsoft, Shadow AI in Microsoft 365 admin center, updated 25 August 2026; Frontier public preview.
- National AI Centre, AI systems register; register guidance and templates.
- GovernSafe About; current public capability wording.

