Discovery correlates browser, SaaS, network, and desktop signals to surface every AI tool in use — sanctioned or not — attributed to users and business units. Most organizations see their first complete inventory within the first day of deployment, and it stays current because it is generated from live usage rather than surveys.
Discovered tools match against the 1,400+ entry catalog, arriving with a risk score, data-handling posture, and training-use policy already attached. Tools the catalog has never seen are flagged as unknowns and prioritized for review instead of disappearing into a backlog.
Discovery feeds enforcement directly: sanction a tool, restrict it to specific groups, or retire it — and because every finding carries user attribution, migration is a conversation with the right people rather than an org-wide announcement nobody reads.
Discovery works on tool-level signals — which AI applications are in use, by whom, how often — with content inspection happening only at the policy boundary. It is an inventory of tools, not surveillance of people.
Typically within 24 hours of deployment; the 72-hour pilot exists precisely because the first inventory is usually the moment the problem becomes concrete.
Discovery is surface-based, so brand-new tools appear as unknowns immediately and are matched into the catalog as it updates — they don't wait for a signature.
Yes — coverage follows managed devices and identities, so personal-device policy stays a policy decision rather than a technical accident.