# AI Governance

Discover every AI tool in use, see exactly what AI costs per user and per model, and put token requests and access approvals into one governed workflow.

## Govern AI before it governs your budget

Your employees already use AI. The question is whether you can see it. Harmony discovers every AI tool in your organization, shows you exactly what it costs, and turns access and token requests into governed workflows instead of Slack messages.

## How AI Governance helps your teams

Shadow AI discovery: surface every AI tool in use across the organization, including locally installed apps and tools accessed through SSO. Find the second ChatGPT instance before your CFO does.

AI spend visibility: see what each AI tool costs, broken down by user, team, and model. Track token consumption over time and spot heavy users before the invoice arrives.

Token and upgrade request management: replace manual approvals and hallway asks with a clear request workflow. Employees request token limit upgrades or new AI tools from the service catalog, approvers get full context, and every decision is logged.

AI access control: grant and revoke access to AI tools through your identity provider groups. Know exactly who approved access to which application, and keep permissions granular down to individual agents and features.

## From unmanaged sprawl to governed adoption

### Full inventory

One live inventory of every sanctioned and unsanctioned AI tool, kept current automatically instead of through periodic audits.

### Cost clarity

Per-user and per-model cost breakdowns with configurable spend thresholds and proactive alerts when usage trends out of budget.

### Governed requests

Access requests, token upgrades, and new tool approvals flow through one auditable process with clear ownership.

### Policy alignment

Keep AI usage aligned with your internal policies and data governance requirements, with detailed logs of who is using what.

## Built for the way AI actually enters your organization

- Continuous discovery: AI applications found across SSO logins, browser usage, and installed software
- Spend and token dashboards: consumption broken down by user, team, tool, and model
- Budget thresholds: alerts and notifications when teams or individuals approach their limits
- Self-service catalog: AI tool access and token upgrade requests, with routed approvals
- Access management: identity provider groups, with a full approval audit trail
- Usage logs and reporting: identify active users, idle licenses, and consolidation opportunities

## Explore pre-built agents for AI governance:

- [Unauthorized Applications Detection](/agents/unauthorized-applications-detection)

- [Discovered Applications Review](/agents/discovered-applications-review)

- [Application Access Request](/agents/application-access-request)

- [Unused Application Discovery](/agents/unused-application-discovery)

- [License Expiration Discovery](/agents/license-expiration-discovery)

- [Inactive Employees](/agents/inactive-employees)

## Connects to your identity and AI stack

- Identity providers: Okta, Microsoft Entra ID, Google Workspace, JumpCloud
- AI providers: ChatGPT, Claude, Gemini, Microsoft Copilot, Cursor
- SaaS management: Zylo, Torii
- Finance & procurement: Mesh Payments, Navan, NetSuite, ZipHQ

## FAQ

### How does Harmony discover AI tools we don't know about?

Harmony correlates identity provider logins, SSO events, and application usage data to surface AI tools in use across the organization, including ones that were never centrally approved.

### Can Harmony show AI costs per user or per team?

Yes. Spend dashboards break down cost and token consumption by user, team, tool, and model, so you can see exactly where your AI budget goes.

### Can we set hard limits on token usage?

Harmony monitors consumption against the thresholds you define and alerts owners and approvers when limits are approached or exceeded. Enforcement happens through your governed request workflow: users request upgrades, and approvers decide with full usage context.

### How do employees request access to a new AI tool or a token upgrade?

Through the same self-service catalog they already use for IT requests. Requests are routed to the right approver, and every decision is logged for audit.

### Does this work with our identity provider?

Yes. Access is managed through your existing identity provider groups, such as Okta or Microsoft Entra ID, so AI access follows the same controls as the rest of your stack.

### How is this different from a SaaS management tool?

AI Governance is part of the same platform that runs your service desk, asset management, and workflows. Discovery feeds directly into request workflows, approvals, and automations instead of ending at a report.