Drop your web-filter or DNS report, your OAuth app list and your software-spend
export. The page matches them against the AIP AI service signatures and produces a
review queue — candidates for a human to confirm — then exports
tool-inventory.csv in the exact shape the baseline kit expects.
CSV or TSV. Three input formats are recognised, and the format is detected from
the column headers — a domain / DNS / proxy / web-filter report, an
OAuth app list (Google Workspace App access control, or Microsoft Entra enterprise
applications), or a software-spend export. Drop several at once, in any order. Drop
a previous baseline.json alongside them to run drift detection. See
README-ai-exposure-scan.md for where each export lives in your admin console.
Compared against the baseline.json you loaded. A tool that gained
permissions is the highest-value alert on this page: the app you approved is not the app you now
have.
These services are flagged minor_safety in the signature list: companion chatbots,
voice cloning and synthetic video of real people. A contact here is a matter for the designated
safeguarding lead as well as for the AI policy owner. Confirm the finding first — a single
request may be an advert or an embedded widget — but confirm it today.
Risk ratings are the signature list's default reading of the service, not a judgement about your school. They follow the kit's rules: high — identifiable student data with no agreement, special-category or assessment data, terms that permit training, or student-facing with no documented review; medium — student work product under an agreement but no DPIA, staff-facing with access to student information, or embedded AI activated without review; low — no student data.
Hostnames and app names that look like AI services but match no signature. Nothing is discarded silently: everything AI-shaped is here, and the count of rows that matched nothing and looked like nothing is reported below it. Confirm one of these and it joins the exported inventory.
Method 2 of the kit — AI switched on inside a product you already licence
— is usually the largest single source of unmanaged exposure, and no domain report or OAuth
list will ever find it, because the traffic goes to a domain you already trust. Walk this list by
hand in your admin consoles. Anything you tick is exported as an Embedded row.
tool-inventory.csv carries the exact eighteen columns of
scoring/tool-inventory.csv and can be dropped straight onto the baseline dashboard.
baseline.json is the small state file: keep it, and drop it back in next term to get
drift detection. Both are aggregate only — no person, no username, no address, and no count
between 1 and 4.