Skip to main content
ShadowAI Defense GitHub

Runbooks

Response runbooks

Graduated response procedures invoked when detections fire. Each includes phases (immediate / short-term / long-term), RACI, decision tree, comms templates, and metrics to capture.

  1. RB-001

    Medium

    Repeated consumer LLM use by individual employee

    Sentinel rule DET-MS-SEN-001 (or platform equivalent) fires for an individual user with > 5 connections to consumer LLM domains in 24 hours, OR DLP records repeated paste-to-AI events over a 7-day window.

  2. RB-002

    High

    Sensitive data egress to AI service confirmed (DLP positive)

    Purview DLP (DET-MS-PV-001) or Falcon Data Protection (DET-CS-FALCON-002) detects confirmed sensitive content egress to a consumer AI service, with an override or attempted bypass.

  3. RB-003

    High

    Mass adoption of unsanctioned AI tool (> 50 users)

    DET-MS-SEN-003 (or platform equivalent) fires for an unsanctioned AI service exceeding the program's user-count threshold. Also triggered by DET-MS-MCAS-001 / -MANUAL-001 surfacing a new viral app.

  4. RB-004

    High

    Unauthorized AI browser extension or OAuth grant

    DET-MS-MDE-001 detects a high-risk AI browser extension on a managed endpoint, OR DET-MS-MCAS-002 detects an OAuth grant to an AI app over Microsoft Entra ID with sensitive permissions.

  5. RB-005

    High

    AI use detected in restricted department (Legal, HR, Finance)

    Detection of AI service access from users in restricted departments (Legal, HR, Finance) via DET-MS-SEN-001 enriched with department data, DET-MS-MCAS-002 user-scope filtering, or DET-NET-001 correlated with identity source.

  6. RB-006

    High

    Repeat offender — second or subsequent violation

    Same user triggers shadow AI detection after a prior warning has been documented. Identified when SOC analyst enriches a new alert and finds a prior case in the AI Governance Risk Register for the same user within 90 days.

  7. RB-007

    Medium

    AI-generated content identified in external communications

    Manual report or DLP detection of AI-generated content in outbound emails, reports, or client deliverables. Triggered by DET-MS-PV-001 content-inspection policies flagging AI-characteristic patterns, or DET-MS-SEN-005 detecting unusual volumes of content with AI markers.

  8. RB-008

    High

    Third-party vendor using AI without disclosure

    Discovery that a third-party vendor or service provider has introduced AI capabilities into their service without contractual authorization or disclosure. Detected via DET-MS-MCAS-001 surfacing new AI-related API calls from a vendor's application, or DET-MS-SEN-003 identifying unexpected AI service connections originating from vendor-managed infrastructure.