🎁 Free onboarding credit for Sydney SMBs (new customers).
Internacious β€’ Shadow AI Audit
Microsoft 365 & AI governance β€’ Sydney

Your staff are already using AI. The question is which tools, and with whose files.

Nobody announces this. A staff member uses AI now. It works, and it quietly becomes part of how your company operates. This is an audit of what is actually in use, what access those tools hold, and what it would take to make the useful ones safe rather than forbidden.

Fixed scope and a fixed price, agreed before we start
Remote, against your tenant, no staff interviews unless you want them
A defensible position going forward, not a list of offenders

The self-check is answered from your own tenant. Nothing is submitted to us unless you ask for the written interpretation.

What the audit does
β€”Inventory of AI tools in actual use, from sign-in and consent records
β€”Every third-party consent grant reviewed, with its scopes explained in plain English
β€”An assessment of what has plausibly left the tenant β€” and what cannot be determined
β€”A sanctioned alternative your staff will use instead, chosen against the work they do
Fixed price, fixed scope. Remote, against your tenant. Scope agreed on a short call before any work starts.

Five minutes, your own tenant

Go and look at one thing

  1. 1Open the Entra admin centre and go to Enterprise applications.
  2. 2Filter to applications added in the last twelve months.
  3. 3Find any your IT provider did not deploy, and open its permissions.

Each one is there because a staff member clicked Accept on a consent screen. Some of those grants carry standing read access to that person's mail and files. They do not expire when the password changes, and in most firms nobody removes them when the person leaves.

Three different problems

Tools holding a key

A consent grant is a standing token, not a session. The tool keeps reading mail and files until someone revokes it, and revocation is nobody's job.

Material pasted, not connected

The larger volume of your business information leaves by copy and paste into a browser tab, with no record of it inside your tenant at all.

Nothing to attest to

Client security questionnaires now ask which AI tools touch their data. A firm that cannot answer in writing might be answering anyway, but badly.

What the audit does

Fixed scope, fixed price. Remote, against your tenant. No staff interviews unless you want them β€” the point is not to catch anyone.

What is covered

Inventory of AI tools in actual use, from sign-in and consent records
Every third-party consent grant reviewed, with its scopes explained in plain English
An assessment of what has plausibly left the tenant β€” and what cannot be determined
A sanctioned alternative your staff will use instead, chosen against the work they do
Consent policy and conditional access set so the next one needs approval
A one-page acceptable-use statement staff will actually read

What you receive

β€”A register of tools and grants as at the audit date
β€”A prioritised list of what to revoke, what to sanction, and what to leave
β€”The acceptable-use statement, ready to issue
β€”A written answer to the AI section of a client security questionnaire

What this cannot tell you

Material typed or pasted into a browser leaves no trace inside your tenant. We can tell you which tools hold access, which were signed into with work accounts, and what the pattern suggests. We cannot reconstruct every document that has ever been pasted into a chatbot.

The useful output is not a list of offenders. It is a defensible position going forward, and an honest statement of where you are.

Price
Fixed price
Delivery
Remote, against your tenant
Staff
No interviews unless you want them

Fixed scope and a fixed price, both agreed on a short call before any work starts. Tenants above roughly 100 seats, or with more than one tenant in play, are scoped separately.

What happens after

Enforcement only holds if someone watches it. Ongoing monitoring of new consent grants and sign-ins, with a monthly exception report. It is not a condition of the audit, and the register is yours regardless.

If you have also licensed Microsoft 365 Copilot, the adjacent question is what it can now surface from inside your own tenant. That is a separate piece of work: the Copilot Exposure Assessment.

Book the audit

Fixed price, fixed scope, delivered remotely against your tenant. Send the details below and we will confirm scope and the price on a short call before any work starts.

We’ll email you within 2 business hours to confirm scope and next steps.

Start with the self-check

Six questions about your own tenant. You get a rating and a plain explanation of what it means, on the spot, without handing over an email address.

Or call (02) 8313 0464 and talk it through first.