Coverage
Endpoints & Devices
The AI use no tenant connector can see
Enterprise connectors show you the AI your company bought. They are structurally blind to the personal ChatGPT account someone opens in a second browser profile. The endpoint is where that becomes visible — and it is the last place a prompt can still be stopped.
What you see
The telemetry we pull
Browser-level AI usage
What people type into AI tools in the browser, seen before it is sent. This is the only vantage point that covers consumer tools reached from a personal account.
Installed AI applications
Desktop AI apps and coding assistants inventoried from Jamf and Intune, including the ones installed without going through software request.
EDR process and network signal
CrowdStrike Falcon and Microsoft Defender telemetry for AI binaries and their outbound connections — the AI slice of detection you already pay for.
Device posture
Whether the machine running an AI tool is managed, encrypted and compliant, which changes the risk of the same action considerably.
Paste and upload events
Large clipboard pastes and file uploads into AI destinations, which is how most real data loss to AI actually happens.
MCP and local tool servers
Local MCP servers and agent runtimes on developer machines, which hold credentials and reach internal systems from outside your server estate.
How it connects
From zero to first signal
- 1
Start with what you already deploy
If you run Jamf, Intune, CrowdStrike or Defender, SAF3AI reads them read-only. That gives you an AI software inventory with nothing new on any endpoint.
- 2
Add the browser extension where you need depth
Pushed through Chrome Enterprise or Intune policy. This is what turns visibility into enforcement — coaching, warning or blocking before a prompt is sent.
- 3
Layer the desktop agent for developers
For engineering fleets running local agents and MCP servers, the desktop agent covers what neither the browser nor the network can see.
- 4
Correlate with everything else
Endpoint findings resolve to the same identities as your Copilot, Gemini and gateway signals, so one person's behaviour is one story across all of them.
Layered by design: MDM and EDR connectors need nothing new installed and give you inventory immediately. The browser extension and desktop agent are optional layers you add only where you need enforcement rather than visibility.
What it catches
Risks specific to this surface
Consumer AI on managed devices
Personal ChatGPT, Claude or Gemini accounts used on corporate machines, which no enterprise-tenant connector can see by construction.
Sensitive paste into AI tools
Customer records, credentials and source code pasted into a chat box. Caught at the moment of paste, where it can still be stopped.
Unapproved AI desktop applications
AI tools installed outside software request, inventoried from MDM and ranked by vendor and data risk.
Local MCP servers holding credentials
Developer machines running tool servers with production access and no monitoring — an unmanaged path into internal systems.
AI on unmanaged or non-compliant devices
The same action from an unencrypted personal laptop is a different risk, and posture is what tells you which one you are looking at.
Off-network activity
Home and travel usage that never crosses the corporate gateway, which only endpoint visibility covers.
See Endpoints & Devices in your own tenant
Connect this surface in a pilot and get a mapped inventory, a scored risk list and the attack paths that actually reach your data.