1. Zen IT Technologies
  2. AI Platform Governance

AI arrived through sign-ups, not procurement.

By the time most companies decide to govern AI, they are already paying for it, depending on it, and sending company data through it. The tools arrived through individual accounts, expensed cards, and free tiers, then quietly became part of the operating environment.

We put AI platforms under the same discipline as everything else we run: identity and provisioning, usage policy, spend that matches observed usage, and documented boundaries around what the tools can reach.

Let's talk

The problem

Nobody decided any of this, which is exactly the problem.

Every other platform in the estate went through a decision. Someone chose it, someone configured it, someone can say who has access and what it can see. AI tooling skipped all of that, and it did so while becoming genuinely useful, which is why nobody wanted to stop it.

The gaps are consistent, and they surface at the same three moments: an audit, a customer security questionnaire, or a budget review.

  • Accounts nobody owns.

    Sign-ups on personal addresses that offboarding never touches, because they were never in the identity platform to begin with.

  • Access that outlives employment.

    No single sign-on and no provisioning, so leaving the company and losing access are separate events that may be months apart.

  • Undefined data boundaries.

    Nobody has established what the tools can reach, what is retained, or where output lands.

  • Seats bought by tier, not by use.

    Spend grows with the vendor's packaging rather than with observed usage.

  • Connectors granted more than they need.

    Integrations and API scopes approved once, broadly, and never reviewed since.

What we do

  1. Identity
  2. AI platforms
  3. Usage policy
  4. Data-egress boundaries
  5. Reporting
  • Rollout under corporate control

    Single sign-on and provisioning through the identity platform you already run, so an AI account is created and removed by the same process as every other account. Workspace and permission design, model and retention defaults enforced centrally rather than left to individual users, and a usage policy short enough that people follow it.

  • Spend and seat governance

    We read usage on AI platforms from platform telemetry and billing exports rather than headcount, so tier and seat decisions reflect who is actually active. Recurring reporting gives management and finance a clear view without needing to interpret technical data.

  • Integration and data-egress review

    We review what each connector and API scope can actually reach and where the output goes. Over-broad grants are corrected, misconfigurations fixed, and the resulting boundary written down, so the answer exists before somebody asks for it.

  • Policy and questionnaire readiness

    The AI section of a customer security questionnaire is now standard, and it asks what your controls are rather than whether you have any. We produce the evidence behind the answers: who has access, through what, what retention settings apply, and how often the controls are reviewed.

  • SaaS License and Spend Management

    The same discipline applies across the rest of the SaaS estate, not only the AI tools: license inventory, utilization analysis, and consolidation of overlapping tooling. Annual subscriptions are reconciled against observed usage and current headcount rather than last year's number, so renewal becomes a planned decision rather than an invoice that arrives.

Technical notes

Six questions to ask about an AI platform

The same platform controls as everything else, asked in the right order.

More on this topic

How it runs

  1. Assessment.

    What is in use, who is paying, who has access, and what the tools can reach. Usually the first complete list the company has had.

  2. Rollout.

    Accounts moved under the identity platform, defaults set centrally, policy written and communicated.

  3. Governance.

    Access reviews, connector scope reviews, and retention settings maintained as the platforms change, which they do faster than anything else on the estate.

  4. Reporting.

    Usage and spend reported on a cadence, so the next tier decision is made against evidence.

Available as a project →

Proof

  • AI platform spend brought under management reporting.

    Technology company

    Usage analyzed from platform exports across every seat, tiers matched to observed usage rather than defaults, and a recurring optimization report established that management and finance now rely on.

  • An AI platform deployed under corporate identity.

    B2B SaaS company

    Developer AI tooling brought under single sign-on and provisioning through the identity platform, model defaults enforced centrally, and the governance settings documented for the team that owns them.

  • An AI integration's data access diagnosed and corrected.

    Technology company

    An AI connector failing against a data platform was traced to misconfigured authorization scopes; the grant corrected, access narrowed to what the integration actually needs, and the boundary documented.

Client examples are anonymized by design. References are provided privately, on request, and with the client's consent.

Who this is for

Companies where management now has to answer for AI tooling that nobody formally chose. What is missing is not the tooling; it is the administration around it.

To be clear about what this is not: we govern the platforms. We are not an AI strategy consultancy, and if what you want is a model selection exercise or a capability bake-off, that is a different engagement and we will say so.

Frequently asked questions

  • Do we really need an Enterprise plan, or can a Team subscription do the job?

    You do not always need an Enterprise plan to have a secure environment. The right tier depends on the security, compliance, identity, and governance requirements of the business.

    For many companies, a Team or Business plan provides the better balance. These plans are typically quota-based rather than billed directly against API usage, which can make them considerably more economical for everyday use. Many also support single sign-on and integration with your identity provider, allowing access to remain centrally controlled.

    Enterprise becomes more relevant when there are specific requirements around regulated or highly controlled environments, such as HIPAA, advanced compliance controls, detailed auditability, retention requirements, or more sophisticated provisioning and lifecycle management.

  • Can lower tiers still be secured and governed?

    The main limitation of the lower tiers is usually around advanced provisioning and governance rather than basic security. For example, they may not provide the same level of SCIM-based provisioning or granular administrative controls.

    Security also does not need to live entirely inside the application. We can use the identity platform together with MDM or endpoint-management tools to enforce policies, restrict applications, configure agents, and put additional guardrails around how AI tools can be used.

    For many organizations, that combination provides a secure and well-managed environment without paying for Enterprise features they do not actually need.

  • What does AI tooling actually send to the provider?

    It depends on the tier and the settings, which is exactly why it needs to be established rather than assumed. With cloud-hosted AI tools, prompts and any attachments you submit are sent to the provider for processing. Whether they are retained, whether they are used for training, and what a connector can additionally reach depend on the product, contract, and tenant settings; those need to be verified rather than inferred from the plan name.

  • How do we control which models people use?

    Where the platform supports it, centrally, through the platform's own administration, once accounts are under corporate identity rather than personal sign-ups. Model availability, retention and workspace defaults are enforced settings rather than instructions, which matters because an instruction is only followed by people who read it.

  • How do we know whether we're on the right tier?

    Platform exports and billing detail show who is actually active and how heavily they use the platform, which is usually a different picture from the one the seat count implies.

  • Can you govern developer AI tooling without slowing the developers down?

    Yes, and it is the case we care most about getting right. Governance that gets in the way is governance that gets routed around, so the controls belong at the account level, in model defaults, and in connector scopes, not between an engineer and their editor.

  • Do you also manage AI tooling?

    Yes. AI Tooling Administration covers deployment and governance of AI developer and productivity tooling, including license management, usage reporting, and data-egress review.