ADAM PULSE Knowledge Base
AI Governance · Inventory · Shadow AI · CSF Identify

How to build an enterprise AI inventory

Short answer

An enterprise AI inventory is a living list: approved, restricted, or blocked, with a named owner, the data classes allowed, whether the system can act, which identity it uses, and a review date. It is not a CMDB project and it is not a certificate. NIST CSF 2.0 Identify is the grouping language — voluntary, not a filing. Microsoft’s agent-adoption guidance tells you to inventory agents and tool integrations, including cross-tenant and guest paths, and to record effective permissions end-to-end.

You cannot least-privilege a tool you have not found. Discovery is overlapping methods, not one scan. How to run those methods is What is Shadow AI and how do you find it? This page is the list those methods fill. It sits under AI agent security for business (safeguard 2).

Empty list, unknown estate

The Shadow AI Risk Assessment will not scan anything. In about four minutes it tells you which inventory questions you cannot yet answer. Then pull OAuth grants and interview two departments. Do not wait for a platform purchase.

Run the assessment →

What to put on each row

Minimum fields. Add more if you will actually keep them current.
FieldWhy it exists
Name and vendorThe product people actually use, not the holding company.
KindChatbot, embedded feature, coding assistant, or agent. Do not collapse them.
StatusApproved, restricted (data class or department), or blocked.
OwnerA named person. Empty owner = candidate to disable.
Account typeCompany SSO versus personal account of the same product. They are different rows.
Data classes allowedMapped to the classification you already use. No parallel AI taxonomy.
Can it act?Send, write, pay, delete — yes/no each. A chatbot that cannot act is not an agent.
IdentityHuman user, shared login (should be none), or agent principal (Entra Agent ID or equivalent).
Tools / scopesOAuth grants, MCP tools, Graph permissions, browser-extension IDs.
Review date / last usedAn undated list is a wish list. Dormant agents expand the attack surface.

Keep the list where the acceptable-use policy can point at it. Do not embed the whole inventory in the policy PDF.

How rows get onto the list

Seven methods, summarized here so this page can stand alone. Each misses a different slice; the Shadow AI article is the how-to.

  1. DNS, proxy, firewall — consumer chatbot domains and API endpoints. Misses personal phones and AI inside software you already allow.
  2. CASB or equivalent — unsanctioned SaaS, same unmanaged-device hole.
  3. OAuth grant review — meeting bots and inbox summarizers that never hit a blocked domain.
  4. Browser extensions — anything that can read the page.
  5. Expenses and cards — ChatGPT Plus, Claude Pro, notetaker seats on a department card.
  6. APIs, MCP, local agents — keys in vaults, MCP configs, Intune-visible local agents. Microsoft Shadow AI (Frontier) is one feed for the last of those on managed Windows.
  7. Department interviews — the tool that never touches your DNS.

First honest report is intake, not a gotcha. Punishment on first disclosure ends disclosure. Intake sequence is in the Shadow AI article.

Classify before you control

Microsoft’s agent-adoption language classifies agents by purpose, criticality and autonomy. At minimum, tag every row:

Dormant is a decision, not a status you ignore

Microsoft’s Cloud Adoption Framework says that without lifecycle controls, organizations accumulate unused agents that expand the attack surface (alongside shadow AI proliferation and budget overruns). Operational rule:

Cadence that a small team can keep

  1. Weekly: new OAuth grants and new DNS destinations that look like AI.
  2. Monthly: owner attestations on anything that can act.
  3. Quarterly: full pass against expenses, extensions, and two department interviews.
  4. On incident: add the tool to approved / restricted / blocked the same week, per the AI incident response plan.

This is not a US legal duty invented here. It is how you know what you approved. If you handle CUI, existing contract rules still follow that data into the tool. Completing an inventory does not make you CMMC Level 2 certified or FedRAMP authorized.

Frequently asked questions

Is an AI inventory a CMMC or FedRAMP certificate?

No. An inventory is a control artifact. Completing one does not make the organization CMMC Level 2 certified or FedRAMP authorized. NIST CSF 2.0 Identify is voluntary grouping language, not a filing.

What fields does the inventory need?

At minimum: name, owner, status (approved / restricted / blocked), data classes allowed, whether it can act (send / write / pay / delete), identity (human SSO vs agent principal), tools or OAuth scopes, last-used or review date. An undated list is a wish list.

Is Microsoft’s Shadow AI page the inventory?

No. It is one feed for unsanctioned local agents on Intune-managed Windows, Frontier preview and license-gated. It does not replace DNS, OAuth, expenses, MCP configs, or department interviews.

Should chatbots and agents share one row?

No. Classify by job: chatbot, embedded feature, coding assistant, agent. An agent that can act needs identity, allowlist and a kill switch on the same row. Collapsing them hides the write path.

What do we do with dormant agents?

Microsoft’s Cloud Adoption Framework names unused agents as an operational risk that expands the attack surface. If nobody will claim the owner field, disable the identity, revoke tokens, and mark the row blocked or retired with a date.

Where do we start if the list is empty?

Run the Shadow AI Assessment to see which questions you cannot answer, then pull OAuth grants and interview two departments. Do not wait for a CMDB project.

Does the acceptable-use policy embed the whole inventory?

No. Point the policy at a living list you can update without rewriting the PDF. That is the pattern in How to create a corporate AI acceptable use policy.

Is this a US legal duty?

This article does not invent one. Inventory is how you know what you approved. Contract and CUI rules you already have still follow the data into the tool. EU AI Act duties apply in the Union market, not automatically to every US employer.

References

  1. NIST CSWP 29 — CSF 2.0 (26 February 2024)— Identify. Voluntary framework, not a certification scheme.
  2. Microsoft Learn — Least privilege for AI agents— inventory agents and tool integrations; record effective permissions.
  3. Microsoft Learn — Manage AI agents across your organization— unused agents expanding the attack surface.
  4. Microsoft Learn — Shadow AI in the Microsoft 365 admin center— one feed, not a complete inventory.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and communications services, SDVOSB. An AI inventory is often a network-and-identity list wearing a new name. This is not a CMMC or FedRAMP certificate. Support: (888) 989-4872 · support@adampulse.us