🎁 Free onboarding credit for Sydney SMBs (new customers).
Internacious β€’ Shadow AI Audit
Microsoft 365 & AI governance β€’ Sydney

Your staff are already using AI. The question is which tools, and with whose files.

Nobody announces this. A staff member uses AI now. It works, and it quietly becomes part of how your company operates. This is an audit of what is actually in use, what access those tools hold, and what it would take to make the useful ones safe rather than forbidden.

Fixed scope, fixed price, two weeks
Remote, against your tenant, no staff interviews unless you want them
A defensible position going forward, not a list of offenders

The self-check is answered from your own tenant. Nothing is submitted to us unless you ask for the written interpretation.

What the audit does
β€”Inventory of AI tools in actual use, from sign-in and consent records
β€”Every third-party consent grant reviewed, with its scopes explained in plain English
β€”An assessment of what has plausibly left the tenant β€” and what cannot be determined
β€”A sanctioned alternative your staff will use instead, chosen against the work they do
$4,500 fixed Β· Two weeks Β· Around two hours in total of your time. Remote, against your tenant.

Five minutes, your own tenant

Go and look at one thing

  1. 1Open the Entra admin centre and go to Enterprise applications.
  2. 2Filter to applications added in the last twelve months.
  3. 3Find any your IT provider did not deploy, and open its permissions.

Each one is there because a staff member clicked Accept on a consent screen. Some of those grants carry standing read access to that person's mail and files. They do not expire when the password changes, and in most firms nobody removes them when the person leaves.

Three different problems

Tools holding a key

A consent grant is a standing token, not a session. The tool keeps reading mail and files until someone revokes it, and revocation is nobody's job.

Material pasted, not connected

The larger volume of your business information leaves by copy and paste into a browser tab, with no record of it inside your tenant at all.

Nothing to attest to

Client security questionnaires now ask which AI tools touch their data. A firm that cannot answer in writing might be answering anyway, but badly.

What the audit does

Two weeks, fixed scope, fixed price. Remote, against your tenant. No staff interviews unless you want them β€” the point is not to catch anyone.

What is covered

Inventory of AI tools in actual use, from sign-in and consent records
Every third-party consent grant reviewed, with its scopes explained in plain English
An assessment of what has plausibly left the tenant β€” and what cannot be determined
A sanctioned alternative your staff will use instead, chosen against the work they do
Consent policy and conditional access set so the next one needs approval
A one-page acceptable-use statement staff will actually read

What you receive

β€”A register of tools and grants as at the audit date
β€”A prioritised list of what to revoke, what to sanction, and what to leave
β€”The acceptable-use statement, ready to issue
β€”A written answer to the AI section of a client security questionnaire

What this cannot tell you

Material typed or pasted into a browser leaves no trace inside your tenant. We can tell you which tools hold access, which were signed into with work accounts, and what the pattern suggests. We cannot reconstruct every document that has ever been pasted into a chatbot.

The useful output is not a list of offenders. It is a defensible position going forward, and an honest statement of where you are.

Price
$4,500 fixed
Duration
Two weeks
Your time
Around two hours in total

Indicative pricing. Scope and final price are confirmed on a short call before any work starts β€” tenants above roughly 100 seats, or with more than one tenant in play, are quoted separately.

What happens after

Enforcement only holds if someone watches it. Ongoing monitoring of new consent grants and sign-ins, with a monthly exception report. It is not a condition of the audit, and the register is yours regardless.

If you have also licensed Microsoft 365 Copilot, the adjacent question is what it can now surface from inside your own tenant. That is a separate piece of work: the Copilot Exposure Assessment.

Book the audit

$4,500 fixed Β· Two weeks Β· Around two hours in total of your time. Send the details below and we will confirm scope and the final price on a short call before any work starts.

We’ll email you within 2 business hours to confirm scope and next steps.

Start with the self-check

Six questions about your own tenant. You get a rating and a plain explanation of what it means, on the spot, without handing over an email address.

Or call (02) 8313 0464 and talk it through first.