Score 100/100 · tier CRITICAL · rule version 1.1 · 5 rule(s) fired: high-risk-tools, consumer-posture, violations, agents-passive-only, enrichment-connectors.
Coverage: 8 tools, 3 agents, policy v7, 214 blocked / 89 warned.
| Severity | Finding | Evidence | Remediation |
|---|---|---|---|
| CRITICAL | 2 high-risk AI tools in use | host=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22 | Map to approved-use policy; restrict via policy block/warn + DNR enforcement. |
| HIGH | 5 consumer-tier AI tools without enterprise controls | host=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96 | Assess need; prefer enterprise-tier equivalents or add compensating controls. |
| MED | 1 agent in the registry without identity enrichment | agents=1 | Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment. |
| MED | 1 agent-enrichment connector not active | google-workspace=not-configured | Supply connector keys (owner action O-ENV) and re-run enrichment. |
| MED | 303 enforcement events (214 blocked, 89 warned) | blocked=214 · warned=89 | Review the violations feed; refine policy; run user-awareness on warned hosts. |
8 tools in the coverage window.
| Host | Category | Risk | Posture | Events | Devices |
|---|---|---|---|---|---|
| chat.openai.com | chatgpt | high | consumer | 4210 | 38 |
| claude.ai | claude | high | consumer | 1980 | 22 |
| github.com | copilot | low | enterprise | 15630 | 41 |
| gemini.google.com | gemini | med | hybrid | 870 | 17 |
| midjourney.com | image-gen | med | consumer | 310 | 9 |
| gamma.app | deck-gen | med | consumer | 240 | 12 |
| notebooklm.google.com | research | med | hybrid | 190 | 11 |
| elevenlabs.io | voice-gen | med | consumer | 96 | 4 |