Govern the AI your org already uses.
Inventory every agent and copilot operating in your tools — including the ones you didn't know about — see what each one touched, catch unsafe behavior before your customer does, and keep an audit-ready record the whole time.
What you are trying to do.
- →Find every agent and copilot already running in your tools — including the AI nobody onboarded.
- →Know what each one touched: which data, on whose behalf, through which OAuth grant.
- →Catch unsafe behavior — data an agent shouldn't reach, a retry into the wrong account, a model swap that changed how it acts — before a customer does.
- →Produce an exportable activity record reviewers and auditors actually accept.
- →Give security and governance a path to triage AI without slowing engineering down.
What hurts today.
AI arrived without going through you
A teammate installed a Workspace add-on. Marketing wired up an agent with access to production data. A coding assistant is opening pull requests. None of it crossed engineering's desk, and none of it is in your inventory.
You can't answer 'what did it do?'
When security asks what an AI integration actually touched, the honest answer is a shrug. The grant exists in an admin console somewhere; the behavior is invisible.
Unsafe behavior surfaces as a complaint
The first signal that an agent issued the wrong refund, leaked the wrong record, or regressed after a model update is a customer ticket — long after it could have been caught.
Audit season is a scramble
Reviewers want evidence of how AI operates across the org. You assemble it by hand, from screenshots and console exports, every single cycle.
What Trefur gives you.
Unmanaged-AI discovery
Trefur surfaces the agents, copilots, and third-party AI integrations running in your tools that engineering never onboarded — who granted access, to what data, and how widely. Triage each finding: revoke the grant, mark it expected, or contact the owner.
Agent & copilot inventory
One inventory of every agent and copilot operating across Google Workspace, Microsoft 365, Slack, GitHub, your CRM, and your own runtimes — what they ran, where, and on whose behalf.
Unsafe-behavior detection
Every run is a trace. When an agent reaches for data it shouldn't, retries into the wrong account, or behaves differently after a model swap, it shows up in the trace and in your alerts — not in a complaint.
Audit-ready activity record
A continuous, exportable record of what every AI did, when, and on whose behalf. The evidence reviewers, auditors, and your governance team ask for — assembled continuously, not the week before the audit.
Compliance-framework evidence
Positioned for the frameworks you report against — ISO 42001 and SOC 2 — by giving you a defensible trail of how AI operates across the org.
Stays inside your perimeter
The self-hostable collector keeps sensitive content in your network and redacts what leaves. Governance without shipping your prompts to a third party.
From blind spot to inventory.
- Day 1
Connect Google Workspace and Microsoft 365 by OAuth. Within hours, the unmanaged-AI rollup surfaces three AI integrations touching production data that were never in the IT inventory.
- Day 2
Security triages each finding: one grant revoked, one marked expected, one routed to its owner. The agents you do run register automatically as their telemetry arrives.
- Week 2
An alert fires — a support agent's retry rate spiked after a model update. The trace is attached. The deploy is paused before any customer notices.
- Quarter-end
The audit-evidence export is one click: a continuous record of every agent and copilot, what it touched, and on whose behalf. No screenshot scramble.
How discovery works.
The connectors do the legwork — Trefur reads each platform's own admin and audit surfaces, classifies AI activity, and stitches it into the same trace view as the agents you ship.
See what your org is running.
Start free, connect a workspace, and watch the inventory fill in. The first findings usually land the same day.