Starting point

Before you protect AI use, you need to know what is actually there

An organisation needs a useful first picture before it writes policies or adds controls: which AI services are identifiable, which teams use them, who owns them and where the evidence is still incomplete.

Current DUBSAR status

The journey is still in private testing

This page describes DUBSAR's intended entry product. The Flash Audit can only report information available through sources the organisation explicitly authorises; it is not a hidden scan of every device, browser or conversation.

Starting point

A map built from authorised sources

The Flash Audit is designed to query identity, collaboration and security sources chosen by the organisation. It separates identified services and accounts from uncertain signals and areas that remain outside scope.

That boundary matters. A service that is not visible through an authorised source does not become visible simply because a report has been generated.

  • AI services, accounts and routes that the connected source can evidence
  • Known owners, teams and purposes where the source provides them
  • Unknown, duplicated or policy-sensitive use that needs review
  • Coverage limits and missing evidence stated alongside the result

Starting point

The report is a starting point, not a blocking mechanism

A discovery report can show that several AI services are in use without a clear owner, or that a sensitive workflow deserves closer attention. It cannot stop that workflow unless the relevant traffic is later routed through a real DUBSAR control point.

The practical next step is to choose one AI call, assistant or workflow, define its owner and policy, then connect it to the Gateway for a controlled pilot.

Starting point

A realistic first step into governance

The Flash Audit does not replace interviews, business analysis or existing security work. It reduces the initial blind spot and gives technical, legal and operational teams a shared evidence base for deciding what should happen next.

Some discoveries may only need an owner and an inventory entry. Others may justify routing rules, data minimisation or human approval before a sensitive action.

Frequently asked questions

What to know before going further.

Does the Flash Audit see every prompt and AI tool in an organisation?

No. It only describes information available from authorised sources. Prompts, business content and unconnected use remain outside scope unless a specific integration has been approved.

Can the Flash Audit already block an action?

No. Blocking or holding an action becomes possible only when the selected flow actually passes through the Gateway and an applicable policy has been configured.