ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

Employee AI access and usage controls

Find employee use of approved and unapproved AI services, then control access, uploads, and sessions.

Use-case context

How this approach relates to the selected use case

Employee AI and data: Directly addresses — Discover employee AI use and control access to approved and unapproved AI services.

Back to use case →
Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsRequirements connected to the selected use case
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
21 shown in this view
Security requirements
5 to review
Strong public support
83 requirement records
Limited public support
14 requirement records
Open research
8 with no supporting claim · 0 incomplete

Evaluation guide

What to verify for this use case

Foundational security requirement

Unapproved AI use discovery

Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.

Questions to test
  1. An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
  2. The test user's AI usage activity can be filtered or exported with AI-specific context.
  3. Approved and unapproved AI destinations or accounts are distinguishable in the evidence record.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

AI-feature discovery in business applications

Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.

Questions to test
  1. A software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.
  2. The inventory shows which users, data classes, integrations, or providers are associated with the AI-enabled software as a service (SaaS) app.
  3. Third-party AI service use is flagged separately from generic software as a service (SaaS) application discovery.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Approved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Questions to test
  1. Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
  2. Prompt, model, or admin activity can be exported or correlated for the selected approved AI platform.
  3. Model or provider usage can be filtered for the scoped workspace, tenant, gateway, or platform.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Controls for unapproved AI use

Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.

Questions to test
  1. A policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.
  2. The control event records policy reason, user, destination, action, and timestamp.
  3. An allowlist or exception path changes the outcome for an approved AI destination.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Additional security requirement

Browser and business-application controls

Apply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.

Questions to test
  1. A session-level policy controls upload, download, copy, paste, sharing, or form submission in a browser or software as a service (SaaS) workflow.
  2. The policy decision includes user, app, session, or identity-aware context.
  3. The event record shows affected action, user, app, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Only requirements explicitly connected to the selected use case are shown. Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorUnmanaged AIBusiness-app AI inventoryApproved AI activityUnapproved AI controlBrowser and app controlsSourcesAction
Core product focusThis approach is central to how these vendors present the product · 14 vendors
AurascapeGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support1Profile →
CyberhavenScaledSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support1Profile →
LayerX SecurityGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Netskope AI SecurityEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support1Profile →
Obsidian AI SecurityGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Palo Alto Networks Prisma AIRSEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Zscaler AI SecurityEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Island Enterprise BrowserScaledSupport found for 5 of 5 requirementsStrong public supportLimited public supportStrong public supportStrong public supportStrong public support2Profile →
WitnessAIGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportLimited public supportStrong public supportStrong public support2Profile →
Proofpoint AI Security / AcuvityEstablishedSupport found for 4 of 5 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportStrong public support2Profile →
Cisco AI DefenseEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support1Profile →
Cloudflare AI Security SuiteEstablishedSupport found for 5 of 5 requirementsStrong public supportLimited public supportStrong public supportStrong public supportLimited public support1Profile →
Grip SecurityGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportLimited public supportLimited public supportStrong public support2Profile →
AIM Security / Cato NetworksScaledSupport found for 4 of 5 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportLimited public support1Profile →
Related coverageThese vendors address the requirements through another core product focus · 7 vendors
RecoGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Lakera / Check PointEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportLimited public supportStrong public supportStrong public support1Profile →
BigID AI Security and GovernanceScaledSupport found for 5 of 5 requirementsStrong public supportLimited public supportStrong public supportStrong public supportLimited public support2Profile →
AktoEmergingSupport found for 4 of 5 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportLimited public support1Profile →
Iterate.ai AgentWatchEmergingSupport found for 4 of 5 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportLimited public support1Profile →
Backslash Agentic AI Endpoint SecurityEmergingSupport found for 3 of 5 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportNo supporting claim found2Profile →
RunlayerGrowth stageSupport found for 3 of 5 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportNo supporting claim found1Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.