
Shadow AI Review
For firms that suspect staff are pasting client work into public AI tools but can't say which tools, how often, or what data.
A focused review of which AI tools staff are actually using, what client work is going into them, and where that leaves the firm exposed. Covers public chat assistants, browser extensions, and the AI features baked into apps the team already runs, plus anything quietly connected to Microsoft 365 or Google Workspace.
- Duration
- 7 to 10 business days
- Engagement
- Review
Output
What you walk away with
A defined output, on paper or in your tenant. Yours to use whether the work continues with us or not.
AI usage inventory
A plain-language map of the AI tools in use across the firm, including free assistants, browser extensions, and AI features inside apps the team already runs.
Exposure findings
Where sensitive client work is reaching tools the firm does not control, ranked by how much risk each one carries.
Containment plan
A prioritized set of actions that reins in the riskiest usage first, with the tools safe to allow separated from the ones to block.
How It Works
How the work runs.
A short, defined sequence. Nothing in your tenant or domain changes until the scope and access are confirmed.
Discovery
We identify the AI tools in use through sign-in data, connected apps, the browser footprint, and a short conversation with the team.
Exposure check
We trace where client, financial, or legal work is going into tools the firm does not control.
Risk ranking
We separate usage that is reasonable to allow from usage that needs limits or an outright block.
Findings handoff
You get the full inventory, the exposure picture, and a clear order of work to bring AI use back under control.
Best Fit
Sound familiar?
Staff have adopted AI tools faster than anyone can track
Client, legal, or financial work may be going into free public assistants
Browser extensions and AI add-ons have access nobody has reviewed
A policy is needed but the real usage picture is missing
Frequently asked questions.
Who is Shadow AI Discovery and Risk Review for?
Shadow AI Discovery and Risk Review is built for professional services firms, microsoft 365 or google workspace teams, owners worried about client data in public ai tools.
How does this engagement start?
Every engagement starts with a short first call to confirm the situation, the decision owner, the access required, and whether this is the right engagement for what you actually need.
What happens after the first call?
Teclara confirms the scope, the access, and the timing. If the engagement is a fit, we agree on the work and start. If a different engagement fits better, we say so.
Ready to start?
Book the first call. We will confirm the situation, the access required, and the right way to move forward, with no obligation past that conversation.
