Skip to main content

Discovery & Shadow AI

Automatically map your AI footprint — cloud agents, source code, MCP servers, collaboration apps, and direct browser-based AI usage — before you can govern it.

Where to find it in the app​

Dashboard → Administration → AI Estate → DISCOVERY.

The DISCOVERY stage of the AI Estate page has three sub-tabs:

Sub-tabWhat's here
Attack Surface MonitorsCloud, code, and network discovery channels. The Discovered Assets view inside this tab is the asset inventory — filter by status (PENDING_APPROVAL, APPROVED, BLOCKED, ACTIVE, etc.), category, or risk level.
Browser AIShadow AI detection — direct browser-based ChatGPT / Claude / Perplexity usage caught by the Rivaro browser extension.
Tool IntegrationsMCP servers discovered in your environment — bridges to the MCP configuration UI in Tool Integrations.

Click any discovered asset to open its detail panel with findings, source channels, and the approve / deny / promote actions. See Asset Management for the full approval workflow.

Overview​

Discovery runs continuously across your infrastructure, finding AI assets you may not know exist. Every discovered asset enters an approval workflow before it can be used by governed agents. Shadow AI detection catches direct AI usage (ChatGPT, Claude, etc.) happening outside your proxy.

Discovery works through channels — configured integrations with your infrastructure. Each channel type uses a different collection method and targets a different part of your environment.

Discovery channels​

Configure discovery channels under Administration → AI Estate → DISCOVERY → Attack Surface Monitors → Channels. Rivaro supports the following channel types:

Channel TypeDisplay NameModeWhat it finds
CLOUD_AI_SERVICESCloud AccountsScheduledAWS, GCP, and Azure accounts — Bedrock Agents, AgentCore, SageMaker, Vertex AI, Azure ML endpoints, models, and AI-specific risks
COLLABORATION_PLATFORMCollaboration AppsScheduledSlack, Teams, Google Workspace — unauthorized AI bots, plugins, and integrations
SOURCE_CODECode RepositoriesScheduledGitHub, GitLab, Bitbucket — AI dependencies, hardcoded API keys, agent code
NETWORK_ENDPOINTNetwork ScanAgent callbackRunning MCP servers, AI agent runtimes, and AI/MCP API endpoints on internal networks — requires a deployed network scanner agent
AGENT_DATAScanner AgentAgent callbackPre-collected findings from a deployed scanner agent
OPENCLAW_CONFIGOpenClaw ConfigAgent pushAgents, models, channels, and tools imported from local OpenClaw configuration
MANUAL_ENTRYManual EntryManualAdmin-created assets — auto-approved on creation

Channel configuration​

Each channel has these common fields:

FieldDescription
nameDisplay name for this channel
channelTypeOne of the types above
activeWhether the channel runs on its schedule
pollingIntervalSecondsHow often to run (scheduled channels)
configurationChannel-specific settings (non-sensitive)
lastRunAtTimestamp of most recent scan
lastRunStatusSUCCESS, FAILED, or RUNNING
lastRunAssetCountAssets found in last run
lastRunRiskCountRisk findings in last run
note

Sensitive credentials (API keys, tokens, secrets) are stored separately in an encrypted credential store — never in the channel configuration JSON.

Network scanner agent​

For NETWORK_ENDPOINT channels, the channel configuration page lets you generate a downloadable Python agent. The agent is bound to a per-channel detection key, scans your internal network, and posts results back to Rivaro. Deploy it anywhere with network access to your internal AI infrastructure.

What Gets Discovered​

Each discovered asset is classified by type and category:

CategoryExamples
AI_SERVICEOpenAI, Anthropic, Vertex AI endpoints in use
AI_AGENTBedrock Agents, AgentCore agents, LangChain/CrewAI/AutoGen runtimes
AI_MODELDeployed models, fine-tuned versions, model registries
MCP_SERVERDiscovered MCP servers (gateway and tool endpoints)
DATA_STORAGEVector databases, embedding stores, training data repositories
ML_PIPELINETraining pipelines, fine-tuning jobs, MLflow experiments
SOURCE_CODERepositories with AI dependencies or hardcoded keys
IDENTITY_ACCESSService accounts and roles with AI service permissions
COLLABORATION_BOTAI bots and plugins in collaboration apps

Asset risk findings​

Each discovered asset can have associated findings — specific security or compliance issues detected during scanning:

Finding fieldDescription
detectionTypee.g. CREDENTIAL_EXPOSURE, MISCONFIGURATION, INFRASTRUCTURE_MCP_PUBLIC_ENDPOINT
severityCRITICAL, HIGH, MEDIUM, LOW
statusACTIVE, RESOLVED, IGNORED
descriptionHuman-readable description of the finding
detectedContentWhat was found (masked in UI)
statusOPEN → IN_PROGRESS → RESOLVED

Asset Approval Workflow​

Rivaro defaults to zero-trust / default-deny: every new asset starts as PENDING_APPROVAL. No agent can use an unapproved asset.

Approval lifecycle​

StatusMeaning
PENDING_APPROVALDiscovered, awaiting security team review
APPROVEDReviewed and explicitly approved for use
BLOCKEDReviewed and denied — agents cannot access
ACTIVEApproved and currently in use by governed agents
PROMOTEDGraduated to a governed entity (agent, data source, model)
REMOVEDAsset no longer detected in environment
ARCHIVEDDeprecated, kept for audit history

The approval request includes a riskScore (0–100) calculated from the asset's findings. Reviewers can add notes before approving or denying.

Promoting an asset​

Approved assets can be promoted — graduated into a fully governed entity with an AppContext, detection key, and full enforcement. This is how shadow infrastructure becomes official, monitored infrastructure.

Promoted entity typeWhat it becomes
AGENTA registered agent identity with trust score tracking
DATA_SOURCEA governed data source with access controls
MODELAn approved model with allowed-model list enforcement
INTEGRATIONA governed integration with policy enforcement
SERVICEAn approved AI service endpoint

Multi-Source Correlation​

The same asset may be discovered by multiple channels. Rivaro deduplicates using an externalId fingerprint — the same fingerprint from two channels links to one asset, with confidence increasing with each additional source.

Observation typeConfidenceHow it's detected
DISCOVEREDSUSPECTED → INFERREDFound by a scanner/channel scan
RUNTIME_USAGECONFIRMEDSeen in live agent traffic through the proxy
CODE_REFERENCEINFERREDFound in source code as an import or API call
IAM_POLICYINFERREDService account has permission to access it

Shadow AI Detection​

Shadow AI is direct use of AI services (ChatGPT, Claude, Perplexity, etc.) that bypasses your proxy — typically via a browser. The Rivaro Shadow AI browser extension monitors this activity and applies your policies in real time.

How it works​

  1. Install the Chrome extension and configure it with your organization's detection key (managed under Administration → API Credentials).
  2. The extension monitors supported AI domains: chatgpt.com, claude.ai, bard.google.com, bing.com/chat, poe.com, perplexity.ai, and more.
  3. When a user types a prompt and submits it, the extension captures the content and sends it to Rivaro's detection engine.
  4. Rivaro runs the same detection pipeline as the proxy — PII, PHI, credentials, prompt injection, etc.
  5. The response action is applied directly in the browser.

Browser AI activity is visible at Administration → AI Estate → DISCOVERY → Browser AI.

Shadow AI policy actions​

ActionWhat the user sees
BLOCKModal appears, submission is prevented
REDACTModal shows sanitized version; user can copy and resubmit
LOGSubmission proceeds, violation is logged in the dashboard
ALLOWNo action, submission proceeds normally

Shadow AI analytics​

The Browser AI sub-tab tracks:

  • Session trends — daily session counts and week-over-week change
  • Violations by severity — CRITICAL / HIGH / MEDIUM / LOW breakdown
  • Compliance rate — percentage of sessions with no violations
  • Risk users — top users by risk score and violation count
  • Cost exposure — estimated API cost of shadow usage, productivity hours
  • Compliance by framework — HIPAA, GDPR, and other framework-level metrics

Zero Trust inventory​

Shadow AI detection surfaces an unverified asset inventory including:

  • Agent runtimes — LangChain, AutoGen, CrewAI instances running without governance
  • MCP servers — unauthenticated or public MCP endpoints
  • AI bots — Slack/Teams bots with excessive AI access
  • Public endpoints — ML infrastructure exposed to the internet

Next steps​