# For IT: find the AI on your fleet, decide once.

> Shadow AI control for IT, in ColossalX, means finding the AI tools people use, including local models, through gateway traffic, 13 collector types and a browser sensor rolled out by browser policy; turning one decision into a standing rule and a blocklist; and giving staff governed AI chat from the same login.

Find AI tools on laptops and in traffic, including local models, turn one decision into a standing rule, and give staff governed AI.

Canonical page: https://colossalx.tech/solutions/it · Last reviewed: 6 Oct 2026

*Illustration:* Shadow AI · one decision: browser sensor to unapproved chat tool, "Found on laptops in the finance team". Checks: Approved provider failed, Risk assessment on file failed, Standing rule set passed. Verdict: monitored, Monitor first, then block.

## The question you are asked

Which AI tools are on our laptops, and who approved them?

## What IT is asked, and what answers it.

- **The threat:** People use AI tools nobody approved, some as local models on laptops. **The control:** A browser sensor, rolled out by browser policy, finds them, local models included. [Shadow AI](https://colossalx.tech/platform/shadow-ai)
- **The threat:** Blocking one AI tool sends people to their personal accounts instead. **The control:** ColossalX Assistant gives staff governed AI chat from the same login, with redaction. [ColossalX Assistant](https://colossalx.tech/assistant)
- **The threat:** AI spend grows by model and team, and the bill arrives late. **The control:** Cost by model, provider and conversation, with daily allowances by role. [AI spend](https://colossalx.tech/platform/ai-spend)

*Illustration:* An illustrative Shadow AI list: a public chat assistant and a code assistant went around the gateway although their provider is approved there, a meeting notetaker and an image generator were never assessed, and a research assistant was assessed, each with the users seen. Notes: 1. Approved provider, traffic went around 2. No risk assessment on file 3. Users seen for each app

## Questions the board asks IT about AI.

- **Do we know which AI tools staff use?** Gateway traffic, collectors and a browser sensor find them, matched to what was approved.
- **What does AI cost us, and where?** Spend by model, provider and conversation, with daily allowances by role.
- **Can staff use AI without going around us?** ColossalX Assistant gives them governed AI chat from the same login.

*Illustration:* From a question to a record: Which AI tools are in use? ends in Shadow AI inventory; Who approved this tool? ends in Standing rule, with reason; What does AI cost us? ends in Spend by model; Can staff use AI safely? ends in Governed Assistant chat.

*Figures:* 58% of executives surveyed reported an AI-related security issue or close call in the last 12 months (Okta, AI Agents at Work 2026, 27 May 2026)

## Brief: Shadow AI found, decided once

ColossalX, from Quantexra Labs, is an AI security and governance platform delivered as SaaS. It finds the AI tools people use and turns one decision into a standing rule.

- A browser sensor, rolled out by browser policy.
- One decision becomes a standing rule.
- Governed AI chat for staff, same login.

**Ask any vendor, including us**

- Does your sensor ever read a prompt?
- Where does a block actually take effect?
- What do staff use once you block?

**Limit:** Blocks take effect where ColossalX can enforce them, and say where.

## What ColossalX does not do

- A block takes effect only where ColossalX can enforce it; elsewhere it is labelled recorded intent.
- The browser sensor does not read prompts; it was tested never to.
- Sign-in uses SAML SSO or Microsoft and Google accounts; generic OIDC providers are not supported.

*Illustration:* Standing rule · where it holds: standing rule to unapproved chat tool, "Block the unapproved chat tool". Checks: Enforcement point here failed, Decision recorded passed. Verdict: monitored, Labelled recorded intent.

## Questions

### How do we find which AI tools employees use?

Start with signals you already have. ColossalX discovers shadow AI from gateway traffic with no configuration, takes push ingestion from 13 collector types such as network, OAuth, DNS and SaaS, and adds a browser sensor for laptops. It then matches what it finds to the AI you already approved and assessed, so the gaps show.

### How is the browser sensor rolled out?

Through the browser policy you already manage, such as Google Admin or Intune. The sensor authenticates with a device key and never holds a person's session. It finds AI tools on laptops, including local models, and it was tested never to read a prompt.

### Can we block an AI tool everywhere?

Not everywhere, and ColossalX says so. One decision becomes a standing rule and a blocklist; the default is to monitor, never to allow. Where ColossalX can enforce the block, it does; where it cannot, the rule is labelled recorded intent, so nobody mistakes a wish for a control.

### How do SSO and group-to-role mapping work?

People sign in with SAML SSO and just-in-time provisioning, or with Microsoft and Google accounts, and Entra directory sync keeps them current. Directory groups map to roles, custom roles reach down to the page, MFA can be required by role, and scoped API keys always expire.

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
