Back to all releases

v1.30.0

Platform

// September 24, 2026

A detected AI tool now opens onto the people running it

Shadow AI told you an unsanctioned tool was in the building. It now tells you who has it. Opening a row on the Harnesses, Assistants, or Local Models tab expands the tool into the enrolled users it was detected for, each with their devices, signals, versions, and first and last sightings, and each linking through to their identity page. Linked alias emails fold to one person, so a colleague with three addresses is one row rather than three. This is the identity page's Shadow AI table turned around: instead of starting from a person and seeing their tools, you start from a tool and see its people, which is the direction an access decision usually runs.

Features

  • Shadow AI tools expand onto their users #6735 - A new access.listAIDetectionUsers read takes a detection target and returns the tool's inventory row plus one row per enrolled user it was found for, with device count, signals, versions, and first and last seen. Linked alias emails fold to the canonical identity through the same fold the inventory's user count already uses. The Harnesses, Assistants, and Local Models tabs each gain a nested route showing that list, every user links to their identity page, and access decisions move to the row's context menu and a button on the tool page. A target with no detections in the organization reads as not found. Available to organization admins, the same audience as the Shadow AI inventory itself. (Author: @subomi)
Sagar Batchu
Sagar Batchu
View on GitHub