# Shadow AI — Discover and Revoke Unapproved AI Access | Cyflow

> Find every AI app and agent holding an OAuth grant in Microsoft 365 or Google Workspace, score each one on data access and publisher trust, and revoke what fails review.

Canonical URL: https://cyflow.ai/shadow-ai/
Last updated: 2026-07-30T00:00:00.000Z

---
![](/background-theme.webp)

Shadow AI

# Shadow AI is consent nobody reviewed

Nobody filed a request. Somebody clicked Accept on a trial, and an AI vendor has held delegated access to tenant mail and files ever since. Cyflow inventories every grant, scores what it can actually reach, and revokes the ones that fail review.

[Schedule a Demo](/schedule-demo/)[AI Readiness Assessment](/ai-readiness/)

Applications — Shadow AI

![Applications table columns showing OAuth access, organization scope, AI exposure and trust rating](/screenshots/home/capability-shadow-ai.webp)

Three doors

## Shadow AI arrives three ways

Only one of them passes an admin. This page owns that one — the OAuth grants that give an AI vendor standing access to the tenant. The two browser surfaces need different controls and have their own page: [browser AI security](/browser-ai-security/).

### Connected apps and agents

An AI vendor asks once, somebody accepts, and the grant persists. Delegated scope carries that person's reach; organization-wide scope carries everyone's. Neither expires on its own.

### Extensions in the browser

An AI extension installs from a store in two clicks and can read the page in front of the user. No consent screen touches the tenant, so nothing appears in an admin audit.

### Assistants opened in a tab

A work address signs into a consumer AI tool and sensitive text goes straight into it. There is no grant and no install to find — only the content on its way out.

Discover, score, revoke

## Every grant, scored on what it can reach

The applications inventory is the register of who holds delegated access to the tenant. It is the list an attacker would want and the list nobody maintains.

01

### Discover

Cyflow enumerates every OAuth application and agent holding a grant in the tenant — including the ones a single user consented to rather than an admin — and records the scopes each one carries.

02

### Score

Each grant carries three readings: AI exposure, how much data its scopes actually reach, and how far the publisher can be trusted. That is what turns four hundred rows into the ten worth a decision.

03

### Revoke or keep

Revoke from the row it appears on, or mark it reviewed so it stops competing for attention. Grants that appear afterwards are raised by an agent rather than found in next year's audit.

Keep reading

## The rest of the surface

-   [Browser AI securityThe other two shadow-AI surfaces: extensions that install, and assistants used in a tab.Read more](/browser-ai-security/)
-   [AI ExposureConnected apps are one of six paths into the same data. This is the whole map.Read more](/ai-exposure/)
-   [AI GovernanceWhat keeps the register current once the first clean-up is done.Read more](/ai-governance/)

How the grants work

## What shadow AI is, and what revoking it does.

Is shadow AI just shadow IT with a new name?

Shadow IT is any unsanctioned tool. Shadow AI is the subset that reads your data to produce output, which is why it is scored separately: an AI app holding mail scope is a different risk from a project tracker holding the same scope.

How does an AI app get access without an admin approving it?

Microsoft 365 and Google Workspace can both let people consent to applications themselves, depending on tenant policy. One person accepting a prompt is enough for the vendor to reach whatever that person can reach, and an organization-wide consent extends it to everyone it covers.

Does revoking a grant break something for the user?

It ends that application's access to tenant data. The person keeps their own account with the vendor; the app simply stops being able to read mail, files or calendar through the grant. The scopes and the owner sit on the row, so the decision is made with both in view.

Does this cover Google Workspace?

Yes. OAuth application discovery, scoring and revocation run on Google Workspace through domain-wide delegation, alongside Drive, Shared Drives, Gmail and the directory.

What about AI tools that never ask for a grant?

Those are browser-side, and the browser extension covers them rather than the applications inventory — extension authorization for the ones that install, and paste and upload controls for the ones used in a tab.

Read the register

## Find out who already has access

Book a demo and we will walk the applications inventory — the grants, the scores behind them, and what revoking one actually does.

[Schedule a Demo](/schedule-demo/)[AI Readiness Assessment](/ai-readiness/)
