G.A.I.N. use case

Turn unknown AI use into controls your team can explain.

Review recorded activity from connected AI workflows, start with observation, and configure local policy actions when your team is ready. G.A.I.N. event records exclude prompt and file bodies.

Book a 20-minute call

A common visibility gap

Security has an AI policy, but nobody can show whether it runs at the moment a paste happens.

G.A.I.N. connects policy to supported AI workflows on the device. Teams can see the tool and category involved, then choose the right response without forcing a blanket ban on AI.

Policy response

Warn

AI usage rule

Intended verified-path outcome: the user receives a local warning before submitting a configured data type.

How it works

A policy needs a real control behind it.

01

Start with a seven-day snapshot

Run observation first so policy choices use recorded events from connected workflows while documenting uncovered paths.

02

Choose rules by real risk

Apply different actions for client data, credentials, financial information, and custom business terms.

03

Show the evidence

Use metadata-only events and reports to explain what was recorded, then use workflow receipts to show which outcomes were verified.

Policy actions

Choose the response that fits the risk.

Log only

Understand before enforcing

Record metadata-only activity for a category without interrupting the person using the tool.

Warn

Make the decision visible

On a supported path, prompt a person to stop and review a risky paste before submission.

Block

Set a hard boundary

On a verified block path, stop configured high-risk categories before submission.

Evidence without prompt collection

A useful record of control, not a surveillance archive.

Managers can review the recorded tool label, department, category, reported action, and time without a prompt archive. A workflow receipt is still required for an enforcement conclusion.

Tool
Claude
Department
Finance
Action
Warn
G.A.I.N. event record
Prompt body excluded
G.A.I.N. dashboard showing policy evidence and AI activity

Where this applies

  • Supported browser AI tools and configured coding workflows.
  • An observation-first rollout with log-only, warning, redaction, and block policies.
  • Department and supported-tool policy scopes with metadata-only evidence.

What it does not claim to do

  • It does not claim to discover every AI site on every unmanaged browser or device.
  • Coverage depends on the extension or agent being installed, enrolled, healthy, correctly wired, and verified for the workflow.
  • It does not replace AI vendor governance, access controls, or employee training.

Questions

Before you put a policy into production.

What is shadow AI?

Shadow AI is AI use that is outside the controls or visibility your organisation expects. The practical problem is not that people use AI, but that data can leave through a workflow no one can explain.

Can G.A.I.N. start in observation mode?

Yes. Start with log-only policies to understand normal work, then turn on warnings, redaction, or blocking only where the evidence supports it.

What is shown to managers?

Metadata such as the recorded tool label, policy category, reported action, department, and time. The dashboard excludes prompt and file bodies; the event record alone does not prove the provider-side outcome.

Read the guide to detecting secrets in AI prompts

See the policy on your real workflow.

In 20 minutes, we can map the AI tools your team uses and show the policy actions that fit them.

Book a 20-minute call