AI Governance

Govern AI the way
you govern everything else

Every AI agent and Azure AI deployment adds identity risk and configuration risk to your estate. Bring both into the same risk-driven platform you already use for the rest of your Microsoft cloud.

START FOR FREEREQUEST DEMO

14-day free trial · 2 min setup · No credit card required

TENET — AI Governance
Agent identities
Support Copilot
Copilot Studio · Tenant-wide
High
Operations Agent
Copilot Studio · No sponsor
Medium
AI resource posture
text-embed-ada
No content filter policy
High
gpt4-prod-eu
Local auth enabled
Medium
Identity risk

Know who owns every AI agent

AI agents created through Copilot Studio and Azure AI Foundry are non-human identities with real permissions and real data access. Left ungoverned, they accumulate the same way over-privileged service accounts always have: quietly, and without a clear owner.

AI Agent Identities — Tenant Inventory3 IDENTITIES
2
Sources
Tracked
Ownership
Scoped
Access
Support Copilot
Copilot Studio · Tenant-wide
High
Finance Analyst
Azure AI Foundry · Scoped
Low
Operations Agent
Copilot Studio · No sponsor
Medium
Agent Identity Risk Signals
No assigned owner
Surface agent identities without an accountable owner.
No human sponsor
Identify agents that do not have a named human sponsor.
Broad tenant-wide grants
Flag access granted across the tenant instead of a narrow scope.
Sensitive permissions
Bring attention to agent identities that can reach sensitive permissions or data.
What TENET surfaces

Governance gaps around every agent

Risk is tied to identity ownership and access: who is accountable, what the identity can reach, and whether access is broader than it needs to be.

Configuration risk

Close the configuration gaps behind the model

An AI agent is only as secure as the Azure AI resource it runs on. Public endpoints, key-based authentication, and unmanaged encryption keys all widen the attack surface, independent of what the agent itself is doing.

Security Controls Audit2 RISKS
gpt4-prod-eu
Local Auth Disabled
Key-based auth is disabled. Entra ID managed identities only.
Network ACL: Deny default
Public network access requires explicit IP allowlisting.
text-embed-ada
Local Auth Enabled
API key auth is active. Keys can be exfiltrated without Entra visibility.
Network ACL: Allow default
Endpoint is reachable from any IP. Restrict to trusted CIDRs.
Content Filter Policy Audit
gpt4-prod-euConfigured
Microsoft.DefaultV2
gpt35-turbo-batchConfigured
CustomPolicy-Batch
text-embed-adaNo Policy
No policy configured
What TENET audits

Configuration-level guardrails, checked continuously

See which deployments have content filter policies configured, track blocked requests, and identify unprotected deployments that may return unfiltered outputs in production.

Quota pressure

Flag deployments running close to their token or request quota, since capacity pressure is itself a posture risk.

Encryption and key management

Audit encryption-at-rest and whether keys are customer-managed or Microsoft-managed.

Clear scope

Governance of identity and configuration, not conversations

TENET's AI governance applies identity governance and security posture management to AI agents and Azure AI resources, the same way organisations already govern human identities and cloud infrastructure. It does not monitor an agent's conversation output or runtime behaviour.

Business Benefits

Benefits of governing AI in TENET

Reduce AI-native attack surface
Close configuration gaps and identity gaps before they are exploited, instead of discovering them after an incident.
Close the ownership gap
Eliminate ownerless, unsponsored agent identities accumulating unmanaged access across the tenant.
One view of AI risk
See agent identity risk and AI configuration risk in the same risk-driven platform as the rest of your Azure and Microsoft 365 estate.
Build trust in AI adoption
Give leadership and customers a defensible answer to how AI agents and AI services are governed.

FAQs

What does "AI governance" mean in TENET?
It covers two things: identity governance for AI agents created through Copilot Studio and Azure AI Foundry (ownership, sponsorship, permission reach, and access scope), and security posture management for the underlying Azure AI resources (network exposure, authentication, content filter policy, quota pressure, and encryption). Together, these are the identity and configuration risks that come with adopting AI on Microsoft cloud.
Does TENET monitor what my AI agents say or do?
No. TENET governs the identity and access of AI agents and the configuration of the Azure AI resources they run on. It does not monitor conversation output, prompts, or runtime behaviour.
How is this different from AI for IT Ops?
AI for IT Ops is about using AI internally, inside TENET, to help your team detect, investigate, and resolve risk faster. AI Governance is the opposite direction: governing the AI agents and Azure AI services your organisation has deployed, so they don’t become an ungoverned risk surface themselves.
What counts as an AI agent identity?
Any agent identity registered in your tenant through Copilot Studio or Azure AI Foundry. TENET inventories these the same way it inventories human and other non-human identities, tracking ownership, sponsorship, and what permissions and data each one can reach.
What Azure AI services does the posture side cover?
Azure OpenAI, Cognitive Services, Azure AI Search, Azure Bot Service, and other Azure AI resources connected to your tenant, audited for network exposure, authentication configuration, content filter policy, quota pressure, and encryption and key management.

Bring AI agents and AI services into your governance programme.

See ownership, access, and configuration risk across every AI agent and Azure AI resource in one place.

FREE ASSESSMENTREQUEST DEMO

No credit card required. Connects to Azure and M365 in minutes.