Find every AI service in 24 hours
CASB stops at the browser. DNS sees everything.
A complete inventory of AI services, agent endpoints and MCP servers from the resolution layer. No agents, no proxies.
| Timestamp | Action | Site | Query Name | Source IP | Reason |
|---|---|---|---|---|---|
| 2026-09-15 11:20:05 | accept | corp-office | chatgpt.com | 10.1.14.66 | allow list |
| 2026-09-15 11:20:09 | accept | corp-office | claude.ai | 10.1.14.66 | allow list |
| 2026-09-15 11:21:44 | greywall | corp-office | app.summarizeit-pro.io | 10.1.22.3 | first seen, held 24h |
| 2026-09-15 11:22:10 | greywall | corp-office | api.elevenlabs.io | 10.1.7.90 | first seen, held 24h |
| 2026-09-15 11:23:51 | block | corp-office | free-gpt-unlimited.xyz | 10.1.30.12 | block list |
AI adoption happened before AI policy
Employees connect to assistants, transcription tools, image generators and code helpers that IT never reviewed. Scripts and agents call model APIs directly, outside any browser. A CASB sees the SaaS logins it knows about. The resolver sees every service, from every device, the first time it is used.
Browser-only visibility
API calls from scripts, notebooks and agents never touch a browser plugin or a SaaS login page.
New services weekly
The tool that launched on Tuesday is in use by Thursday. Category lists lag; first-seen does not.
No evidence for the policy
An AI acceptable use policy needs a list of what is actually in use before it can approve or restrict anything.
Inventory first, then decide
Assign the resolver
Office networks through a static site; managed laptops through a DoH virtual site. No software on the device.
Read the inventory
Traffic Logs list every destination by site with query counts and first-seen dates. AI services stand out by name. Filter on Greywall Event: New Query and export the list.
Approve, restrict, hold
Allow the approved assistants by name. Block the ones policy prohibits. Set Enforce so new AI services wait for review.
Discovery controls
Destination inventory
Every hostname resolved, by site, with query counts and first-seen dates. Filter, sort and export.
First-seen review
A service no one has used before is held. The queue shows who, how often and since when.
Every device, no client
Static sites for networks, DoH virtual sites for laptops and roaming runtimes. Managed devices take the DoH profile through MDM.
Exportable evidence
CSV or JSON of every AI destination by site and month, for the acceptable use policy and the auditor.
SIEM forwarding
Syslog, CEF and webhooks. Alert on a new AI service the day it appears.
Per-team policies
Engineering may reach model APIs that finance may not. One policy per team, one inventory each.
What nobody approved
First-seen AI services on the corporate policy: the query count, the first timestamp and the establishment rank. Approve the assistant the design team adopted; block the voice cloning beta.
Questions teams ask
Does this see AI usage inside approved SaaS apps?
No. Securd sees resolution to AI services and APIs. Features inside an approved application that call a model on the vendor side do not resolve from your network.
Can we allow some AI services and block others?
Yes. Allow by name, block by name or category, and hold everything first-seen. Policies are per team or per network.
What about personal devices?
Devices that do not use your resolver or the DoH profile are not governed. Managed devices are.
See your AI inventory by tomorrow
One resolver change on the office network and the list fills overnight.