Tool Gate · How it works

How the Shadow AI Discovery & Risk-Triage Kit gate works

How the Shadow AI Discovery & Risk-Triage Kit grades 4 AI tools on sanction status, data sensitivity, account type, and training exposure: a regulated-data-on-personal-account gate forces the whole inventory UNGOVERNED — which is how 2 of 4 tools pull into governance and the set reads UNGOVERNED.

How the gate works

This tool grades your AI-tool inventory - sanction status, data sensitivity, account type, training exposure. It reads 4 tools and rolls them into one verdict — the worst, never the average — and then a gate that can only make it worse.

The 4 tools

ToolVerdict
ChatGPT (free, personal logins)fix firstPULL INTO GOVERNANCEUnsanctioned · Regulated data · Personal account · Trains on your data
Otter.ai meeting notesPULL INTO GOVERNANCEUnsanctioned · Personal data · Personal account · Trains on your data
Notion AI (team workspace)REVIEWSanctioned · Personal data · SSO / managed · Training unclear
Approved coding copilot (SSO)SANCTIONEDSanctioned · Low data · SSO / managed · Controlled training

The verdict bands

GOVERNED
every tool sanctioned, on SSO, exposure handled
TIGHTEN
no pulls, but a tool needs sanction, account, or training work
UNGOVERNED
any tool pulls into governance, or regulated data sits on a personal account
Regulated-data-on-personal-account · worsen-only

A tool touching regulated data through a personal, non-SSO account trips UNGOVERNED on its own, even if every other tool in the inventory is clean.

In the worked sample it reads UNGOVERNED2 of 4 tools pull into governance - ChatGPT and Otter.ai both run personal or regulated data through personal, unsanctioned logins. ChatGPT alone - regulated data on a personal account - would force UNGOVERNED even if it were the only issue in the inventory. The one thing to fix first: Bring ChatGPT (free, personal logins) into governance first - it's both unsanctioned and the tool tripping the regulated-data gate..

Common questions

Can every tool look survivable on the How the Shadow AI Discovery gate works and the company still read UNGOVERNED?

Yes. The roll-up takes the worst of 4 tools — never the average — then a worsen-only gate, the Regulated-data-on-personal-account gate, escalates when trouble clusters. In the worked sample it reads UNGOVERNED because 2 of 4 tools pull into governance - ChatGPT and Otter.ai both run personal or regulated data through personal, unsanctioned logins. ChatGPT alone - regulated data on a personal account - would force UNGOVERNED even if it were the only issue in the inventory.

What is a worsen-only gate?

A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-set of survivable lines, because a single disqualifying gap shouldn't hide behind an average of the healthy ones. The tool also names the one thing to fix first — here, "Bring ChatGPT (free, personal logins) into governance first - it's both unsanctioned and the tool tripping the regulated-data gate.".

Grades the tools, never people. A discovery aid - not monitoring, a scan, or an audit. Runs offline in the .xlsx.

Embed this diagram

Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.

Interactive — renders the live diagram

<iframe src="https://redhub.ai/visuals/tool/shadow-ai-discovery-risk-triage-kit.html" title="How the Shadow AI Discovery & Risk-Triage Kit gate works — RedHub AI" width="760" height="1764" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/shadow-ai-discovery-risk-triage-kit">How the Shadow AI Discovery & Risk-Triage Kit gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>

Image + link — a static picture for any blog

<a href="https://redhub.ai/visuals/tool/shadow-ai-discovery-risk-triage-kit"><img src="https://redhub.ai/visuals/tool/shadow-ai-discovery-risk-triage-kit-share.png" alt="Diagram of the Shadow AI Discovery & Risk-Triage Kit: four AI tools rolled up worst-not-average, a regulated-data-on-personal-account gate, and the inventory reading UNGOVERNED." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>

Download the image: dark · light

This is how Shadow AI Discovery & Risk-Triage Kit works. More diagrams in the Visual Field Guide.