AI governance security checks across 5 apps
AI assistants, agents and model access inside the tenant — what they can read, who can publish them, and how autonomously they act.
Why it matters
AI assistants and agents inherit the permissions of whoever installed them and act without a human in the loop. Knowing which agents exist, what they can read and who is allowed to publish them is now part of the audit scope, not a future concern.
Browse by app
Highest-severity checks
The 8 most severe AI governance checks across all 5 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Bedrock Action Group Computer Use / Bash — Amazon Bedrock severity: critical
- Copilot Agent No Authentication — Microsoft 365 severity: critical
- AI Gateway Logging Disabled — Cloudflare severity: high
- AI Gateway No Authentication — Cloudflare severity: high
- AI Gateway No Rate Limiting — Cloudflare severity: high
- Bedrock Action Group Code Interpreter — Amazon Bedrock severity: high
- Bedrock Agent High Risk Unblocked — Amazon Bedrock severity: high
- Cloudflare AI Gateway Agent High Risk Unblocked — Cloudflare severity: high
Where to start
Connect Cloudflare first — it carries the most AI governance checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.