Block unmanaged PII mount
Stop direct access, notify owner, and open a classification request.
Where governance stands today: posture score, open violations, what's awaiting human review, and the audit trail. 3 critical issues are currently blocking 4 agents from production.
Recommended next actions for shadow AI and policy drift. Proxon can contact owners, apply approved alternatives, add approval gates, or block high-risk usage with the evidence captured below.
Stop direct access, notify owner, and open a classification request.
Move users to the approved Sales Research skill bundle and require review before re-enabling.
Disable direct execution and insert the production promotion approval gate.
Send owner notice with inventory registration, retention policy, and vendor review steps.
Score is a weighted sum of five dimensions — each scored independently and refreshed daily. Drill in to any dimension below to see the underlying checks.
Each violation links a specific policy to the asset that's breaking it. Critical issues block production deploys until resolved.
Things waiting for a human to act — agent promotions, model whitelisting, data mounts, exception requests. SLA clock starts on submission.
Models, tools, servers, and data sources detected in your environment but never reviewed or approved. Up 13 over the past 12 weeks. Recommended actions now include owner contact, policy application, scoped restriction, and blocking.
| KIND | NAME | OWNER | DETECTED | CALLS / WK | RISK | REASON | |
|---|---|---|---|---|---|---|---|
| Model | gpt-5-pro-experimental | Diego Vasquez · Sales · West | 2 days ago | 4,200 | HIGH | Un-reviewed model build, no DLP profile | |
| Tool | scrape_competitor_pricing | Hannah Lindqvist · Growth Mktg | 5 days ago | 1,840 | HIGH | Calls external site, no rate-limit policy | |
| Data Source | customers_pii (raw export) | Aisha Adeyemi · FP&A | today | 280 | CRITICAL | PII without classification, mounted directly | |
| Tool | send_sms_internal | Marcus Donnelly · Enterprise Sales | 1 day ago | 920 | MEDIUM | No vendor security review on file | |
| Model | llama-3.1-70b-uncensored | Tomás Castellanos · Platform | 3 days ago | 3,100 | HIGH | Bypasses safety filters, no eval suite | |
| Server | mcp-internal-finance | Aisha Adeyemi · FP&A | 1 week ago | 6,200 | MEDIUM | Self-hosted MCP, not on approved server list | |
| Tool | query_legal_db | Sofia Brennan · Legal Ops | 2 days ago | 480 | MEDIUM | Privileged data access, no approver chain | |
| Prompt | extract-medical-claims-v2 | Kenji Nakamura · Product | today | 140 | MEDIUM | PHI handling without HIPAA review | |
| Tool | deploy_to_prod_unsafe | Tomás Castellanos · Platform | 4 days ago | 24 | CRITICAL | Skips deploy approval gate | |
| Model | claude-sonnet-4.5-experimental | Priya Iyer · Customer Ops | 6 days ago | 8,420 | LOW | Pre-release version, missing in model registry | |
| Data Source | stripe_webhook_raw | Marcus Donnelly · Sales | today | 1,240 | HIGH | Live payment data, no encryption-at-rest tag | |
| Tool | reset_user_password | Sofia Brennan · IT | 1 day ago | 36 | HIGH | Privileged action, no approval workflow | |
| Prompt | synthesize-trade-recs | Diego Vasquez · Sales | 3 days ago | 320 | HIGH | Investment advice, no compliance review | |
| Tool | post_to_external_slack | Hannah Lindqvist · Mktg | 5 days ago | 1,640 | LOW | External comms, no DLP scan | |
| Server | github-mcp-personal-token | Tomás Castellanos · Platform | 2 weeks ago | 2,840 | MEDIUM | Personal access token, expires in 12 days | |
| Model | mistral-large-2 | Kenji Nakamura · Product | 1 week ago | 480 | LOW | Vendor not on approved list | |
| Data Source | support_tickets_export | Priya Iyer · Customer Ops | today | 920 | LOW | Customer data, no retention policy attached |
Append-only log of security-relevant events. Retained 384 days. Exportable to your SIEM.
Auto-generated bundles of controls, logs, and screenshots for external auditors. Continuously updated — no quarter-end scramble.