πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
MED

Sensitive documents uploaded to an unsanctioned AI tool

Shadow-AI SaaS usage

CASB flags employees pasting internal docs into an unapproved AI writing SaaS.

Full brief β–Ύ

CASB detected uploads from ~30 employees to an AI document-summarizer SaaS not on the approved list. Some uploads match internal document classifications, including a few tagged "Confidential". The vendor's terms allow training on submitted data.

index=casb app="ai-summarizer.example" action=upload | lookup dlp_class filename | where classification IN ("Internal","Confidential") | stats count by user, classification
index=casb app="ai-summarizer.example" action=upload | lookup dlp_class filename | where classification IN ("Internal","Confidential") | stats count by user, classification
Signal feed3 events
2026-07-17T13:00:00Zcasbuser=sales-14 Β· app=ai-summarizer.example
ts2026-07-17T13:00:00Z
sourcecasb
usersales-14
appai-summarizer.example
actionupload
classificationConfidential
filenameQ3-pipeline.xlsx
2026-07-17T13:20:00Zcasbuser=hr-3 Β· app=ai-summarizer.example
ts2026-07-17T13:20:00Z
sourcecasb
userhr-3
appai-summarizer.example
actionupload
classificationInternal
filenameorg-plan.docx
2026-07-16T00:00:00Zvendor-tosuser= Β· app=ai-summarizer.example
ts2026-07-16T00:00:00Z
sourcevendor-tos
user
appai-summarizer.example
action
classification
filename
β–Έ syncing case…
SOC β€” Sensitive documents uploaded to an unsanctioned AI tool Β· PlayCISO