Sample report · Illustrative data

Sample AI Usage Evidence Pack

This is what SentraGuard hands over at the end of a one-week pilot, shown here after a full quarter. It has 12 pages: inventory, account split, sensitive data, agents, decisions, exceptions, regulator clause maps and a signed export. Sample Institution is fictional, and so is every figure.

Prints one A4 page per sheet. Choose "Save as PDF" in the print dialog to keep a copy.

SentraGuard · AI Usage Evidence Pack

AI Usage Evidence Pack

Sample Institution (fictional)
Dubai, UAE

Reporting period
01 Jul to 30 Sep 2026 (13 weeks)
Scope
2,140 users in 8 business units. Browser, IDE and endpoint surfaces. AI apps, accounts, agents and MCP servers.
Prepared by
SentraGuard, SovereignAI Security Labs (SOAISEC Labs)
Document id
SG-EP-SAMPLE-2026Q3-001
Classification
Confidential, sample
Export id
SG-EXP-2026Q3-000417 (see page 12)
Sample document. All names, figures and events in this document are fictional and for illustration only.

Contents

  1. Executive summary 2
  2. Scope and method 3
  3. AI application inventory 4
  4. Account split 5
  5. Sensitive data events 6
  6. Agents and MCP servers 7
  7. Policy decisions 8
  8. Exceptions and approvals 9
  9. Regulator clause map, UAE 10
  10. Regulator clause map, Saudi Arabia and international 11
  11. Signed export attestation 12
SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 1 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
02

Executive summary

This pack records how staff at Sample Institution (fictional) used AI tools from 01 Jul to 30 Sep 2026. It also records the controls that applied. All figures are sample data.

63AI apps discovered
41apps with personal-account sessions
212prompts with regulated data
9agents and MCP servers, 4 with write access

Findings

  1. AI use is wide and mostly outside approved tools. Staff used 63 AI apps. Only 3 are sanctioned. 42 are unsanctioned, including 2 unlisted LLM endpoints found by behaviour (page 4).
  2. Personal accounts are common. 41 of 63 apps had sessions from personal accounts. Marketing and Human Resources had the highest share (page 5).
  3. Regulated data left through personal and unsanctioned paths. 212 prompts carried regulated data to an unsanctioned app or a personal account. Customer PII (64), source code (42) and Emirates ID (38) led (page 6).
  4. Agents can change systems. 9 agents and MCP servers run on staff endpoints. 4 have write access. 2 had no named owner at discovery (page 7).
  5. Coaching works. SentraGuard logged 20,049 decisions: 18,402 allow, 1,207 coach, 388 redact and 52 block. Weekly coach events peaked at 190 in week 2 and fell to 47 in week 13 (page 8).
Overall risk rating (sample)Elevated
LowModerateElevatedHigh

Controls now stop the most sensitive data classes. Personal-account use and write-capable agents keep the rating above Moderate.

Recommendations

  1. Move personal-account use of ChatGPT, Gemini and Claude to ChatGPT Enterprise and Microsoft 365 Copilot. Set Coach for 30 days, then Block for personal accounts on these apps.
  2. Put the 4 write-capable agents under tool-call policy. Give each one a named owner, an approver and an expiry date.
  3. Turn on Redact for Emirates ID, IBAN and card number on all tolerated apps. Keep Block for regulated data on unsanctioned apps.
SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 2 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
03

Scope and method

Who and what was in scope

  • Users 2,140 protected users in 8 business units.
  • Period 01 Jul to 30 Sep 2026, 13 weeks. Times are Gulf Standard Time (UTC+4).
  • Identity Users and groups come from the institution's SSO. Group membership syncs by SCIM. Every event carries a user, a role and a business unit.
  • Deployment On premise. No data was sent to SOAISEC. App dictionary updates arrived as signed bundles.

Surfaces

  • Browser Plugin for Chrome and Edge, pushed by Intune to all 2,140 users.
  • IDE Extensions for VS Code and Cursor in Technology.
  • Endpoint Agent on Windows, macOS and Linux in Technology, Treasury and Retail Banking. It sees desktop AI apps, CLI coding agents, local models and MCP servers.

Business units

Business unitUsersSurfaces
Retail Banking620Browser
Corporate Banking310Browser
Treasury95Browser, endpoint
Operations385Browser
Technology290Browser, IDE, endpoint
Risk and Compliance160Browser
Human Resources90Browser
Marketing190Browser
Total2,140

Pilot week and timeline

Day 0Plugin and endpoint agent pushed by Intune. First shadow AI inventory the same day: apps, personal accounts, agents and MCP servers.
Day 1 to 2Apps classed sanctioned, tolerated or unsanctioned. Sensitive-data map and corporate vs personal split.
Day 3 to 4Coach and Redact live for Emirates ID, IBAN, card number and secrets.
Day 5 to 6Block live for unsanctioned apps. Exceptions set with approver and expiry.
Day 7Full governance. All four actions live. First Evidence Pack and executive readout.
Weeks 2 to 13Steady-state governance at full scope: 2,140 users in 8 business units.

Method

SentraGuard matches traffic against its app dictionary. It flags unknown LLM endpoints by behaviour. It compares the signed-in account with the SSO identity to split corporate and personal use. It inspects three lanes: prompt, paste and upload. Each inspected event gets one decision: Allow, Coach, Redact or Block.

Out of scope. Mobile devices. A one-week pilot pack uses the same structure for one business unit.

SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 3 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
04

AI application inventory

63 AI apps were used in the period. This page lists the 15 with the highest risk or use. The CSV export lists all 63.

Sanctioned 3Tolerated 18Unsanctioned 42New apps inherit the Unsanctioned class until reviewed.
AppClassUsersSessionsPersonal accountData-policy note
Microsoft 365 CopilotSanctioned1,3802,9400%Enterprise agreement. Reviewed by Procurement and DPO.
ChatGPT (consumer)Unsanctioned6121,870100%Consumer terms. Not reviewed.
ChatGPT EnterpriseSanctioned2401,2100%Enterprise workspace. Reviewed.
GitHub CopilotSanctioned1461,1206%Business plan. Personal GitHub accounts seen.
GeminiTolerated38896071%Mixed accounts. Data location not confirmed.
GrammarlyTolerated32278064%Browser extension. Vendor review pending.
ClaudeTolerated20564083%Mostly personal accounts. Vendor review pending.
CursorTolerated3842045%Covered by exception EX-02.
PerplexityTolerated17641092%Covered by exception EX-01.
Notion AITolerated11830558%Workspace AI add-on. Vendor review pending.
Canva AITolerated9721077%Covered by exception EX-03.
DeepSeekUnsanctioned64190100%Consumer terms. Data location outside the UAE.
Otter.aiUnsanctioned4196100%Meeting audio upload. Exception EX-04 for one series.
Unlisted LLM endpoint AUnsanctioned958n/aDetected by behaviour. Unknown operator.
Unlisted LLM endpoint BUnsanctioned422n/aDetected by behaviour. Self-hosted proxy.
Top 10 apps by sessions Sanctioned Tolerated Unsanctioned
01,0002,0003,000Microsoft 365 Copilot2,940ChatGPT (consumer)1,870ChatGPT Enterprise1,210GitHub Copilot1,120Gemini960Grammarly780Claude640Cursor420Perplexity410Notion AI305

Figure 1. Sessions per app, 01 Jul to 30 Sep 2026. Sample data.

SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 4 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
05

Account split: corporate and personal

41 of 63 AI apps had at least one session from a personal account.

A personal-account session is one where the account signed in to the AI app does not match the user's SSO identity. Data sent this way sits outside the institution's contracts, retention rules and audit trail.

63AI apps discovered
41with personal-account sessions
22corporate accounts only
Share of AI sessions on personal accounts, by business unit Below 40% 40% or more
0%25%50%75%100%Retail Banking (620)38%Corporate Banking (310)29%Treasury (95)22%Operations (385)41%Technology (290)34%Risk and Compliance (160)12%Human Resources (90)47%Marketing (190)58%

Figure 2. Users per unit in brackets. Sample data.

What the split shows

  • Marketing, 58% Staff use personal accounts for design and copy tools. Canva AI and ChatGPT lead.
  • Human Resources, 47% Staff use personal accounts for meeting notes and letters. This includes candidate data.
  • Risk and Compliance, 12% Most use goes through Microsoft 365 Copilot.
  • Largest gap in volume Retail Banking and Operations have the most users with personal-account sessions.
SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 5 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
06

Sensitive data events

212 prompts carried regulated data to an unsanctioned app or a personal account.

SentraGuard inspects three lanes: typed prompts, pastes from the clipboard, and file uploads. Each event below also appears in the policy decision log with its timestamp, user and action.

Events by data class and lane Prompt Paste Upload
010203040506070Emirates ID38IBAN31Card number (PAN)17Customer PII64Source code42API keys and secrets20

Figure 3. Prompts with regulated data, 01 Jul to 30 Sep 2026. Sample data.

Data classPromptPasteUploadTotal
Emirates ID14121238
IBAN1215431
Card number (PAN)79117
Customer PII30201464
Source code2019342
API keys and secrets146020
Total978134212
Action takenEvents
Allow (pilot days 0 to 2)24
Coach55
Redact99
Block34
Total212

24 events were allowed and logged on pilot days 0 to 2, before Coach, Redact and Block went live. From day 5, regulated data to unsanctioned apps was blocked.

Counting rule. One prompt counts once, under its most sensitive data class. Redact and block counts on page 8 cover all apps, including sanctioned ones, so they are higher.

SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 6 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
07

Agents and MCP servers

9 agents and MCP servers were found. 4 have write access.

The endpoint agent and IDE extensions list each agent, the tools and MCP servers it can call, and the data those tools reach. Agent tool calls get the same four actions as prompts: Allow, Coach, Redact and Block.

9agents and MCP servers
4with write access
2had no named owner at discovery
Agent or serverOwner groupRuntimeTools or MCP reachableData reachablePermissionFinding
Claude Code (CLI agent)Technology, Payments squadmacOS endpointShell, file edit, git; GitHub MCP serverPayments source reposWriteUses a personal API key. Move to a corporate key.
Cursor agent modeTechnology, Mobile squadIDE (Cursor)Terminal, file editMobile app source codeWriteCovered by EX-02. Secrets redacted.
MCP server: JiraTechnology, PMOmacOS endpointCreate and update issuesInternal ticketsWriteNo named owner at discovery. Owner now assigned.
MCP server: email (IMAP/SMTP)Retail Banking, ServiceWindows endpointRead mail, send mailCustomer service mailboxWriteCan send mail outside the domain. EX-06 under review.
MCP server: filesystemOperations, AnalyticsLinux endpointRead filesShared drive with customer exportsReadReaches files with customer PII. Scope reduced.
MCP server: PostgresRisk and ComplianceLinux endpointSQL queryCredit risk reporting replicaReadRead-only account. Covered by EX-05.
Custom Python agentCorporate Banking, InnovationLinux VMWeb search, internal product APIProduct documentsReadNo named owner at discovery. Owner now assigned.
Ollama (local model)Treasury, Quant teammacOS endpointNoneLocal files loaded by userReadLocal model not in the asset register. Added.
LM Studio (local model)MarketingmacOS endpointNoneLocal files loaded by userReadLocal model not in the asset register. Added.

Actions taken in the period

  • Owners Every agent now has a named owner group.
  • Write tools Tool calls that write or send now run under Coach. Calls that send regulated data outside the domain are blocked.
  • Register Both local models were added to the asset register.
SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 7 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
08

Policy decisions

SentraGuard logged 20,049 policy decisions in the period.

18,402Allow: observe and log
1,207Coach: banner with the approved path
388Redact: identifier removed, prompt continues
52Block: stopped and logged
Decisions per week, 13 weeks Allow Coach Redact Block
04008001,2001,600W1W2W3W4W5W6W7W8W9W10W11W12W13Allow per week (observe and log)050100150200250W1W2W3W4W5W6W7W8W9W10W11W12W13CoachRedactBlockCoach, Redact and Block per week (all live from pilot day 7)

Figure 4. Two scales: Allow on the top panel, the other actions below. Sample data.

Coach to sanctioned path

Coach shows a banner that points the user to the approved app. Coach events peaked at 190 in week 2, the first full week with Coach live. They fell to 47 in week 13, a fall of 75%. Allow volume stayed level over the same weeks. This shows that users moved to sanctioned apps and did not stop using AI.

Redact and Block

Redact removed the identifier and let the prompt continue. Most redactions were IBAN and Emirates ID in tolerated apps. Block stopped 52 events. All 52 were regulated data sent to unsanctioned apps or through write-capable agent tools.

Each decision in the log has a timestamp, user, role, business unit, app, account type, lane, data class and action. The log streams to the institution's SIEM (Microsoft Sentinel in this sample).

SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 8 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
09

Exceptions and approvals register

6 exceptions were in force at the end of the period.

An exception lets a named group use an app or tool outside its default class. Each exception has a scope, a reason, an approver and an expiry date. SentraGuard applies the exception by user group and returns to the default policy on expiry.

IdRequester groupApp or toolScopeReasonApprover roleExpiryStatus
EX-01Treasury research (6 users)PerplexityPublic market research only. Redact stays on for all regulated data.Research tool with no sanctioned equivalent.Head of Market Risk31 Dec 2026Active
EX-02Technology, Mobile squad (38 users)CursorSource code in the squad workspace. Secrets redacted.Pilot of AI coding tools before a licence decision.CISO31 Oct 2026Active
EX-03Marketing (24 users)Canva AICorporate accounts only. No customer data.Brand design work.Head of Marketing and DPO30 Nov 2026Active
EX-04Human Resources (1 meeting series)Otter.aiOne external panel series. Recordings deleted after 30 days.Panel member requires transcripts.DPO15 Oct 2026Active
EX-05Risk and Compliance, AnalyticsMCP server: PostgresRead-only account on the reporting replica.Analyst queries on risk data.Head of Data Governance31 Dec 2026Active
EX-06Retail Banking, ServiceMCP server: emailSend limited to the institution's domain.Draft replies for the service queue.CISO31 Oct 2026Under review

Register controls

  • Expiry No exception runs longer than 6 months. Owners get a reminder 14 days before expiry.
  • Review EX-06 is under review because the tool can send mail. It stays limited to the institution's domain until the CISO decides.
  • Evidence Every decision made under an exception carries the exception id in the decision log.
SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 9 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
10

Regulator clause map: UAE

This map links UAE regulatory expectations to the evidence in this pack.

Regulator or lawExpectation (general)Evidence itemPage
CBUAEOutsourcing and third-party controlsAI app inventory with class and data-policy status4
CBUAEConsumer data protectionSensitive data events; redact and block decisions6, 8
CBUAEIncident reportingTimestamped decision log; signed export8, 12
UAE Information Assurance RegulationAsset inventoryAI app inventory; agents and MCP servers4, 7
UAE Information Assurance RegulationData classificationEvents by data class and lane6
UAE Information Assurance RegulationMonitoring and loggingDecision log and weekly trend; SIEM feed8
UAE PDPL (Federal Decree-Law 45 of 2021)Lawful processing of personal dataPersonal data events; account split5, 6
UAE PDPL (Federal Decree-Law 45 of 2021)Processor obligationsInventory data-policy notes; exceptions register4, 9
UAE PDPL (Federal Decree-Law 45 of 2021)Cross-border transfersApps with data outside the UAE4
DIFC Data Protection Law 2020Processor obligations and transfersInventory; exceptions with approver and expiry4, 9
ADGM Data Protection Regulations 2021Lawful processing, processors, transfersInventory; sensitive data events; exceptions4, 6, 9

How to read this map. The map shows where this pack holds evidence that supports a control area. It uses general terms, not clause numbers. It is not legal advice or a compliance opinion. The institution's compliance team decides which rules apply.

SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 10 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
11

Regulator clause map: Saudi Arabia and international

This map is for institutions that also operate in Saudi Arabia, and for international standards.

Saudi Arabia

Regulator or lawExpectation (general)Evidence itemPage
SAMA Cyber Security FrameworkData leakage protectionSensitive data events; redact and block decisions6, 8
SAMA Cyber Security FrameworkLogging and monitoringDecision log; signed export8, 12
SAMA Cyber Security FrameworkThird-party securityAI app inventory; exceptions register4, 9
NCA Essential Cybersecurity ControlsAsset managementAI app inventory; agents and MCP servers4, 7
NCA Essential Cybersecurity ControlsEvent loggingDecision log and SIEM feed8
NCA Essential Cybersecurity ControlsExternal and cloud servicesInventory; corporate and personal account split4, 5
Saudi PDPLProcessor controlsInventory data-policy notes; exceptions4, 9
Saudi PDPLTransfer restrictionsApps with data outside the country; data events4, 6
Saudi PDPLBreach notificationTimestamped events; signed export6, 8, 12
SDAIA AI Ethics PrinciplesAccountability, privacy, transparencyAgent owners; data events; inventory4, 6, 7

International

StandardExpectation (general)Evidence itemPage
ISO/IEC 42001AI management system: inventory, roles, monitoringInventory; agents; exceptions; decision log4, 7, 8, 9
NIST AI RMF: MapKnow the AI systems in useInventory; agents and MCP servers4, 7
NIST AI RMF: MeasureMeasure use and riskAccount split; data events; decisions5, 6, 8
NIST AI RMF: ManageAct on riskPolicy decisions; exceptions8, 9
NIST AI RMF: GovernRoles, approvals, recordsExceptions register; signed export9, 12

How to read this map. The map shows where this pack holds evidence that supports a control area. It uses general terms, not clause numbers. It is not legal advice or a compliance opinion. The institution's compliance team decides which rules apply.

SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 11 of 12
AI Usage Evidence PackSample Institution (fictional) · 01 Jul to 30 Sep 2026
12

Signed export attestation

SentraGuard signed this export at creation. Anyone can check that the file has not changed.

Export id
SG-EXP-2026Q3-000417
Document id
SG-EP-SAMPLE-2026Q3-001
Created
2026-10-01T06:00:00+04:00 (Gulf Standard Time)
Period covered
01 Jul to 30 Sep 2026
Contents
AI app inventory, user and role attribution, policy decision log, exceptions and approvals, regulator clause map. Formats: PDF, CSV, SIEM feed.
SHA-256 of export file
3f9a0c7e51b24d8a96e0f13c7b5a29d4e8c160f7a3b95d2e4c07f81a6d3b9e25c
Signing key fingerprint
SHA256:7Q2mX9vK4pR1tLw8eN3sB6yH0cJ5dF2gA9uZ4oV7iM1

The hash and fingerprint above are fictional. They show the format only.

How to verify

  1. Get the export file and its signature file from the institution's SentraGuard console or SIEM archive.
  2. Compute the SHA-256 hash of the export file with a standard tool, for example sha256sum on Linux or certutil -hashfile on Windows.
  3. Compare the result with the hash above. One changed byte gives a different hash.
  4. Check the signature file against the public signing key. Confirm that the key fingerprint matches the one above.
  5. Record the result, the date and the name of the reviewer in the audit file.

Methodology note

Data comes from the SentraGuard browser plugin, IDE extensions and endpoint agent, as described on page 3. Users and roles come from SSO and SCIM at the time of each event. Apps are matched against the SentraGuard app dictionary. Unknown LLM endpoints are flagged by behaviour. Counts on page 6 count each prompt once. Counts on page 8 count each decision once. Figures are not rounded. Times are Gulf Standard Time.

Prepared bySentraGuard export service
Reviewed by (institution)
Date
Sample document. All names, figures and events in this document are fictional and for illustration only.
SG-EP-SAMPLE-2026Q3-001Confidential, samplePage 12 of 12