Brief / AIGIS resources

Why discovering shadow AI agents is only half the governance problem.

Surveys report most enterprises have unknown AI agents in their environments. Discovery tools name them. The sharper question for a governed agent is whether you can prove what it was allowed to do. Salesforce is the AIGIS production proof path.

Executive read

The short version, before the deep dive.

Discovery answers which agents exist; provenance answers what each was allowed to access.

Permission checks belong before model exposure, not after transcript review.

Keep evidence of denied records and stripped fields per agent interaction.

Prove it first on Salesforce; treat ServiceNow and SAP as disclosed co-development scope.

Analysis

What matters

Discovery is necessary but not sufficient

Inventories and control towers can surface agents you did not know were running. That closes the visibility gap but not the proof gap.

Once an agent acts on systems of record, the board question becomes whether you can show the permission decision behind each access.

What permission provenance adds

AIGIS checks the user's permissions before the model sees business context, strips fields the user cannot view, and records the decision as auditor-readable evidence.

Prompt logs answer what the AI said. Permission provenance answers why it was allowed to know it.

A first governed workflow

Start with one Salesforce workflow where different users have different record or field visibility, and show the evidence trail end to end.

Request a scoped governance review at `/demo`.