See who's building skills in AI, and surface shadow AI.
Two sources feed one picture: the provider APIs know what happens inside the tenant, and the scan reads the machines, which is where people actually build things. What comes out is an inventory, a set of names, and the AI nobody registered.
Skills, MCPs and the shadow AI on the machines
An agent on each machine reads what is actually there: skills, MCP servers, prompts and rules. No survey, because the people building the most interesting things are rarely the ones filling in forms.
- Index every skill, MCP server, prompt and rule on the machine
- Attribute each finding to a person and a team
- Surface the AI nobody registered alongside the AI that was approved
- Run as a one-off audit, or continuously
Activity from Claude and ChatGPT
Pulls the full activity stream out of Claude Enterprise and ChatGPT Enterprise rather than the summary each console shows, and normalises it into one event model.
- Claude Enterprise activity
- ChatGPT Enterprise activity
- Gemini, in build
- One event model, so a shared project means the same thing whichever provider it came from
- Everything kept, not only what was raised
One list of every skill and MCP
The scan and the connections merge into a single living inventory of every skill, MCP server and capability your organisation has, with an owner and a version against each.
- Everything that exists, categorised and searchable
- Ownership and version on each entry
- Duplicate detection: the same problem solved separately on nineteen desks
- Orphaned work, the kind that leaves when somebody does
MCP inventory
Every MCP connection found across every machine, deduplicated by identity, with a risk level, the clients it was found in, and how many people are running it. Grouped answers what the company has; by person answers who has it.
Skill inventory
Every skill found, rolled up by what it does rather than what it was called — skills never share a name, and the same job gets solved under nine of them. The variant count is the duplication nobody had a number for.
The numbers leadership decides on
What is being used, by which teams, at what cost, and by whom. Including the report that answers the only question that matters at board level: is any of this working.
- Usage by capability, team and person, over time
- Champions: who builds, and whose work other people copied
- What was installed once and never opened again
- Token spend attributed to the work that caused it